CRISC Certified in Risk and Information Systems Control – Question659

Which of the following should be the PRIMARY input when designing IT controls?

A.
Internal and external risk reports
B. Outcome of control self-assessments
C. Benchmark of industry standards
D. Recommendations from IT risk experts

Correct Answer: A