CRISC Certified in Risk and Information Systems Control – Question479

An organization that has been the subject of multiple social engineering attacks is developing a risk awareness program. The PRIMARY goal of this program should be to:

A.
communicate the consequences for violations
B. implement industry best practices
C. reduce the organization’s risk appetite
D. reduce the risk to an acceptable level

Correct Answer: D