CRISC Certified in Risk and Information Systems Control – Question565

An organization has determined a risk scenario is outside the defined risk tolerance level. What should be the NEXT course of action?

A.
Develop a compensating control
B. Identify risk responses
C. Allocate remediation resources
D. Perform a cost-benefit analysis

Correct Answer: A