QuestionQ67

Risk Governance and Management

What is the MOST likely reason a list of control deficiencies found in a recent security assessment would be left out of an IT risk register?

Explanation

An IT risk register is used to record and manage active risks. Once control deficiencies have been remediated, they no longer require risk treatment or ongoing tracking in the register.

Community Discussion

No comments yet. Be the first to start the discussion!