Want to know:
During an audit, an IS auditor notices that the IT department of a medium-sized organization has no separate risk management function, and the organization's operational risk documentation only contains a few broadly described types of IT risk. What is the MOST appropriate recommendation in this situation?A.Create an IT risk management department and establish an IT risk framework with the aid of external risk management experts.B.Use common industry standard aids to divide the existing risk documentation into several individual types of risk which will be easier to handle.C.No recommendation is necessary because the current approach is appropriate for a medium-sized organization.D.Establish regular IT risk management meetings to identify and assess risk and create a mitigation plan as input to the organization's risk management.
Get a detailed, AI-powered explanation for this question and thousands more on StudyFetch.
Get the Answer for FreeHow StudyFetch Helps You Master This Topic
AI-Powered Answers
Get instant, detailed explanations powered by AI that understands your course material.
Deep Understanding
Go beyond surface-level answers with step-by-step breakdowns and examples.
Personalized Learning
Spark.E adapts to your learning style and helps you connect ideas.
Practice & Test
Turn any question into flashcards, quizzes, and practice tests to solidify your knowledge.
Explore More Questions
- An administrator at Ursa Major Solar is configuring a workflow rule. What are two considerations for an administrator in this situation? (Choose 2 options.)
- Quelle est la moyenne de cette distribution 20; 40; 60; 80; 100
- Shawn and Dorian rented bikes from two different rental shops. The prices in dollars, y, of renting bikes from the two different shops for x hours is shown.Shop Shawn used: y = 10 + 3.5xShop Dorian used: y = 6xIf Shawn and Dorian each rented bikes for the same number of hours and each paid the same price, how much did each pay for the rental?