Want to know:
During an audit, an IS auditor notices that the IT department of a medium-sized organization has no separate risk management function, and the organization's operational risk documentation only contains a few broadly described types of IT risk. What is the MOST appropriate recommendation in this situation?A.Create an IT risk management department and establish an IT risk framework with the aid of external risk management experts.B.Use common industry standard aids to divide the existing risk documentation into several individual types of risk which will be easier to handle.C.No recommendation is necessary because the current approach is appropriate for a medium-sized organization.D.Establish regular IT risk management meetings to identify and assess risk and create a mitigation plan as input to the organization's risk management.
Get a detailed, AI-powered explanation for this question and thousands more on StudyFetch.
Get the Answer for FreeHow StudyFetch Helps You Master This Topic
AI-Powered Answers
Get instant, detailed explanations powered by AI that understands your course material.
Deep Understanding
Go beyond surface-level answers with step-by-step breakdowns and examples.
Personalized Learning
Spark.E adapts to your learning style and helps you connect ideas.
Practice & Test
Turn any question into flashcards, quizzes, and practice tests to solidify your knowledge.
Explore More Questions
- In a sequence diagram, the _____ indicates when an object sends or receives a message.
- Construction phase (Designers, programmers, quality, assurance, analysts, users)
- 19) A firm in the finance industry should do which of the following to ensure that it stays current with technology?A) Select only low-cost, low risk projectsB) Limit work to those projects with great rewardsC) Select only low-risk, high-reward projectsD) Have a few high-risk, high benefit projectsE) Avoid projects that were very costly