CAS-005 · Question #271
CAS-005 Question #271: Real Exam Question with Answer & Explanation
The correct answer is D: Appetite. Risk appetite defines the level of residual risk an organization is willing to accept. The CIO must clarify this to guide remediation activities and align business continuity practices with organizational tolerance.
Question
An organization determines existing business continuity practices are inadequate to support critical internal process dependencies during a contingency event. A compliance analyst wants the Chief Information Officer (CIO) to identify the level of residual risk that is acceptable to guide remediation activities. Which of the following does the CIO need to clarify?
Options
- AMitigation
- BImpact
- CLikelihood
- DAppetite
Explanation
Risk appetite defines the level of residual risk an organization is willing to accept. The CIO must clarify this to guide remediation activities and align business continuity practices with organizational tolerance.
Community Discussion
No community discussion yet for this question.