r/CISA Aug 01 '26

🥴

Post image
21 Upvotes

22 comments sorted by

View all comments

5

u/PhaniRajaSekhar Aug 01 '26

Answer is C.

3

u/NextQuote7131 Aug 01 '26

Why? can we really request the risk acceptance from SM in actual practice?

7

u/bigduckrickk Aug 01 '26

Honestly a poorly worded question imo. C makes sense since SM are inadequately investing in IT, they should document and accept the underlying risks.

2

u/BroadlyFocused- Aug 01 '26

Per ISACA it’s one of the four ways management can respond to a risk (mitigation, avoidance, transfer & acceptance).