QuestionQ752

Risk Response and Reporting

An assessment of information-security controls has found controls that are ineffective. Which of the following should be the risk practitioner’s FIRST course of action?

  • A Deploy a compensating control to address the identified deficiencies
  • B Report the ineffective control for inclusion in the next audit report
  • C Determine if the impact is outside the risk appetite
  • D Request a formal acceptance of risk from senior management
Explanation

Risk management requires evaluating the risk against established risk criteria and appetite before selecting a response. Compensating controls, formal risk acceptance, and reporting are possible subsequent actions, depending on whether the resulting exposure exceeds the organization’s risk appetite.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!