CRISC Certified in Risk and Information Systems Control – Question676

Which of the following should be the risk practitioner’s PRIMARY focus when determining whether controls are adequate to mitigate risk?

A.
Cost-benefit analysis
B. Sensitivity analysis
C. Level of residual risk
D. Risk appetite

Correct Answer: D