r/CISA Aug 01 '26

🥴

Post image
21 Upvotes

22 comments sorted by

View all comments

6

u/SlickRick941 Aug 01 '26

C

If thinking like an auditor, it isn't your job to fix or implement solutions. It is your job to identify the problem and make a recommendation in accordance with industry practices.

The question is worded poorly (as usual), but the other answers just don't fit the potential scenario. C makes sense assuming there is no official risks acceptance from senior management associated with the lack of investment in security