The MOST essential content to include in an IT risk awareness program is how to:
A.
define the IT risk framework for the organization
B.
populate risk register entries and build a risk profile for management reporting
C.
comply with the organization ' s IT risk and information security policies
D.
prioritize IT-related actions by considering risk appetite and risk tolerance
The Answer Is:
C
This question includes an explanation.
Explanation:
An IT risk awareness program shouldprimarily ensure that employees and stakeholders understand and comply with the organization ' s risk and information security policies. ISACA highlights that an awareness program must reinforce policy understanding to drive compliant and secure behavior across the organization.
===========
CRISC PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"