An empowered security steering committee has decided to accept a critical risk. Which of the following is the information security manager's BEST course of action?
A.
Notify the chief risk officer (CRO) and internal audit.
B.
Determine the impact to information security objectives.
C.
Remove the specific risk item from the risk register.
D.
Document the risk acceptance and justification.
If an empowered security steering committee has decided to accept a critical risk, the BEST course of action for the information security manager is to document the risk acceptance and justification (Option D).
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Jess20
1 month, 1 week agorichck102
6 months, 2 weeks agoSouvik124
10 months, 4 weeks ago