CRISC Certified in Risk and Information Systems Control – Question498

Which of the following should be done FIRST when a new risk scenario has been identified?

A.
Assess the risk awareness program
B. Assess the risk training program
C. Identify the risk owner
D. Estimate the residual risk

Correct Answer: A