[Governance]
Which of the following should be the risk practitioner's FIRST course of action when an organization plans to adopt a cloud computing strategy?
Answer : D
[Governance]
Which of the following is the GREATEST concern if user acceptance testing (UAT) is not conducted when implementing a new application?
Answer : D
[Governance]
Which of the following is MOST helpful in providing a high-level overview of current IT risk severity*?
Answer : B
[Governance]
Once a risk owner has decided to implement a control to mitigate risk, it is MOST important to develop:
Answer : A
[Governance]
An organization's financial analysis department uses an in-house forecasting application for business projections. Who is responsible for defining access roles to protect the sensitive data within this application?
Answer : D
[Information Technology and Security]
Who should be responsible for implementing and maintaining security controls?
Answer : D
[Governance]
Which of the following is the BEST Key control indicator KCO to monitor the effectiveness of patch management?
Answer : B