CRISC Certified in Risk and Information Systems Control – Question735

Which of the following would be the BEST recommendation if the level of risk in the IT risk profile has decreased and is now below management’s risk appetite?

A.
Decrease the number of related risk scenarios.
B. Optimize the control environment.
C. Realign risk appetite to the current risk level.
D. Reduce the risk management budget.

Correct Answer: B