CRISC 문제 166
An IT risk practitioner has been asked to regularly report on the overall status and effectiveness of the IT risk management program. Which of the following is MOST useful for this purpose?
CRISC 문제 167
What is the PRIMARY reason to periodically review key performance indicators (KPIs)?
CRISC 문제 168
FISMA는 연방 기관이 IT 시스템과 데이터를 보호할 것을 요구합니다. 얼마나 자주 외부 조직에서 규정 준수를 감사해야 합니까?
CRISC 문제 169
You are the risk official in Bluewell Inc. You are supposed to prioritize several risks. A risk has a rating for occurrence, severity, and detection as 4, 5, and 6, respectively. What Risk Priority Number (RPN) you would give to it?
CRISC 문제 170
Management has required information security awareness training to reduce the risk associated with credential compromise. What is the BEST way to assess the effectiveness of the training?


