Question 266

Of the following, who should be responsible for determining the inherent risk rating of an application?
  • Question 267

    An organization has outsourced a critical process involving highly regulated data to a third party with servers located in a foreign country. Who is accountable for the confidentiality of this data?
  • Question 268

    A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner's GREATEST concern?
  • Question 269

    Which of the following is MOST important for a multinational organization to consider when developing its security policies and standards?
  • Question 270

    Mary is a project manager in her organization. On her current project she is working with her project team and other key stakeholders to identify the risks within the project. She is currently aiming to create a comprehensive list of project risks so she is using a facilitator to help generate ideas about project risks. What risk identification method is Mary likely using?