QuestionQ484

Risk Response and Reporting

An exception to a security control would MOST likely be justified through risk acceptance when:

  • A the end-user license agreement has expired.
  • B automation cannot be applied to the control.
  • C the control is difficult to enforce in practice.
  • D business benefits exceed the loss exposure.
Explanation

Risk acceptance is justified when the anticipated business benefits outweigh the potential loss exposure and the organization deliberately accepts the residual risk.

Community Discussion

No comments yet. Be the first to start the discussion!