Governance & Compliance第 98 / 100 题
The residual risk that remains after all controls have been applied should be:
a.Ignored entirely
b.Transferred automatically
c.Eliminated completely
d.Accepted by management
解析
Residual risk is what remains after mitigations are in place, and it cannot usually be reduced to zero. Senior management should formally acknowledge and accept it. This ensures leadership is aware of and owns the remaining exposure.
免费刷完整 100 道题库 — 无需注册。
同考点相关题目
- A calculation of expected yearly loss from a risk, found by multiplying single loss expectancy by annual rate of occurrence, is the:
- Which assessment identifies the critical processes and the impact of their disruption to guide continuity planning?
- Which agreement defines the measurable service levels a provider must meet, such as uptime guarantees?
- Which legal agreement prohibits parties from disclosing confidential information they receive?
- Which framework provides a widely used structure for managing cybersecurity risk through functions like Identify, Protect, Detect, Respond, and Recover?
- Regular training that teaches employees to recognize phishing and follow security policies is called: