Certified in Risk and Information Systems Control (CRISC) — Question 366

A recent internal risk review reveals the majority of core IT application recovery time objectives (RTOs) have exceeded the maximum time defined by the business application owners. Which of the following is MOST likely to change as a result?

Answer options

Correct answer: B

Explanation

The correct answer is B, as exceeding RTOs indicates a higher probability of risks occurring, which would lead to a reassessment of risk likelihood. Options A, C, and D do not directly relate to the changes necessitated by the failure to meet RTOs; they focus more on the general framework of risk management rather than the specific likelihood of risks materializing.