CRISC 문제 11

After a high-profile systems breach at an organization s key vendor, the vendor has implemented additional mitigating controls. The vendor has voluntarily shared the following set of assessments:
After a high-profile systems breach at an organization s key vendor, the vendor has implemented additional mitigating controls. The vendor has voluntarily shared the following set of assessments:
Which of the assessments provides the MOST reliable input to evaluate residual risk in the vendor's control environment?

CRISC 문제 12

조직은 위험에 대응하기 위해 여러 옵션 중에서 선택해야 합니다. 이해 관계자는 동의하지 않고 결정을 연기하기로 결정할 수 없습니다. 다음 중 조직이 채택한 위험 대응책은 무엇입니까?

CRISC 문제 13

IT 운영 팀은 필요한 복원력 수준과 관련하여 애플리케이션 소유자의 결정을 기반으로 재해 복구 제어를 구현합니다. 이 시나리오에서 위험 소유자는 누구입니까?

CRISC 문제 14

Which of the following is the MOST important enabler of effective risk management?

CRISC 문제 15

Which of the following is the BEST indication of an improved risk-aware culture following the implementation of a security awareness training program for all employees?