A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner's GREATEST concern? A. Aggregate risk approaching the tolerance threshold B. Vulnerabilities are not being mitigated C. Security policies are not being reviewed periodically D. Risk owners are focusing more on efficiency  Suggested Answer: A This question is in CRISC exam For getting Risk and Information Systems Control Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by ISACA. The website does not contain actual questions and answers from ISACA's Certification Exams. Trademarks, certification & product names are used for reference only and belong to ISACA.
Please login or Register to submit your answer