CRISC Certified in Risk and Information Systems Control – Question405

Which of the following aspects of an IT risk and control self-assessment would be MOST important to include in a report to senior management?

A decrease in the number of key controls
B. Changes in control design
C. An increase in residual risk
D. Changes in control ownership

Correct Answer: D