CRISC Certified in Risk and Information Systems Control – Question529

Which of the following should be an element of the risk appetite of an organization?

A.
The enterprise’s capacity to absorb loss
B. The effectiveness of compensating controls
C. The amount of inherent risk considered appropriate
D. The residual risk affected be preventive controls

Correct Answer: A