A. If the risk owner has accepted the risk
Before considering alternative measures or strategies like compensating controls or insurance, it's essential to confirm that the individual or group responsible for the risk (the risk owner) is aware of and has formally accepted the elevated risk due to the incomplete implementation of the control. This ensures accountability and awareness at the appropriate level within the organization.
Risk is not acceptable, that's why the mitigation suggested, however if the mitigation control can't e implemented fully risk practitioner may look for alternative to bring down the risk within risk appetite, that whys compensating control.
This section is not available anymore. Please use the main Exam Page.CRISC Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
eblue
10 months, 1 week agoCbtL
1 year, 3 months agoKoulyo
1 year, 3 months agojohn_boogieman
1 year, 5 months agoSuchib
1 year, 7 months agoblokey
1 year, 7 months ago