CISM Certified Information Security Manager – Question0356

A risk management program will be MOST effective when:

A.
risk appetite is sustained for a long period
B. risk assessments are repeated periodically
C. risk assessments are conducted by a third party
D. business units are involved in risk assessments

Correct Answer: D