QuestionQ650

Risk Assessment

Reviewing the results of which of the following is the BEST way to identify information systems control deficiencies?

  • A Control self-assessment (CSA)
  • B Vulnerability and threat analysis
  • C User acceptance testing (UAT)
  • D Control remediation planning
Explanation

A control self-assessment (CSA) evaluates controls within the relevant business unit or process and surfaces gaps between expected and actual control effectiveness. Those gaps are information-systems control deficiencies.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!