Which of the following is the PRIMARY reason for granting a security exception?
A.
The risk is justified by the cost to the business.
B.
The risk is justified by the benefit to security.
C.
The risk is justified by the cost to security.
D.
The risk is justified by the benefit to the business.
The Answer Is:
A
This question includes an explanation.
Explanation:
= A security exception is a formal authorization to deviate from a security policy, standard, or control, due to a valid business reason or requirement. The primary reason for granting a security exception is that the risk associated with the deviation is justified by the benefit to the business, such as increased efficiency, productivity, customer satisfaction, or competitive advantage. The security exception should be approved by the appropriate authority, such as the senior management or the risk committee, based on a risk assessment and a cost-benefit analysis. The security exception should also be documented, communicated, monitored, and reviewed periodically123. References =