QuestionQ375

Governance

A risk practitioner has noted that risk owners have approved a substantial number of exceptions to the information security policy. Which of the following should be the risk practitioner’s GREATEST concern?

  • A Aggregate risk approaching the tolerance threshold
  • B Vulnerabilities are not being mitigated
  • C Security policies are not being reviewed periodically
  • D Risk owners are focusing more on efficiency
Explanation

Approved policy exceptions represent accepted residual risk. Their cumulative effect can cause aggregate organizational risk to approach or exceed the established risk-tolerance threshold, which is the key governance concern.

Community Discussion

No comments yet. Be the first to start the discussion!