CRISC Certified in Risk and Information Systems Control – Question636

Which of the following is the MOST relevant input to an organization’s risk profile?

A.
External audit’s risk assessment
B. Management’s risk self-assessment
C. Internal audit’s risk assessment
D. Information security’s vulnerability assessment

Correct Answer: A