Question 221

An organization has established a contract with a vendor that includes penalties for loss of availability. Which risk treatment has been adopted by the organization?
  • Question 222

    Who should have the authority to approve an exception to a control?
  • Question 223

    A part of a project deals with the hardware work. As a project manager, you have decided to hire a company to deal with all hardware work on the project. Which type of risk response is this?
  • Question 224

    Which of the following represents lack of adequate controls?
  • Question 225

    An organization has made a decision to purchase a new IT system. During when phase of the system development life cycle (SDLC) will identified risk MOST likely lead to architecture and design trade-offs?