Certified in Risk and Information Systems Control (CRISC) — Question 446
Which of the following is the BEST way for an organization to enable risk treatment decisions?
Answer options
- A. Establish clear accountability for risk.
- B. Develop comprehensive policies and standards.
- C. Allocate sufficient funds for risk remediation.
- D. Promote risk and security awareness.
Correct answer: A
Explanation
Establishing clear accountability for risk ensures that there are designated individuals responsible for managing and making decisions about risk treatment, which is crucial for effective risk management. While developing policies, allocating funds, and promoting awareness are important, they do not directly facilitate decision-making as accountability does.