組織のリスク管理慣行の監査中に、情報システム監査人は、文書化されたいくつかの IT リスク受容が、割り当てられた有効期限後にタイムリーに更新されていないことを発見しました。 ?
正解:A
Explanation The mitigating factor that would most significantly minimize the impact of not renewing IT risk acceptances in a timely manner is having documented compensating controls over the business processes. Compensating controls are alternative controls that reduce or eliminate the risk when the primary control is not feasible or cost-effective. The other factors, such as previous approval by senior management, unchanged business environment, and small percentage of issues, do not mitigate the risk as effectively as compensating controls. References: ISACA CISA Review Manual 27th Edition Chapter 1