Certified in Risk and Information Systems Control (CRISC) — Question 472
Which of the following proposed benefits is MOST likely to influence senior management approval to reallocate budget for a new security initiative?
Answer options
- A. Reduction in the number of incidents
- B. Reduction in inherent risk
- C. Reduction in residual risk
- D. Reduction in the number of known vulnerabilities
Correct answer: C
Explanation
The correct answer is C, as reducing residual risk directly demonstrates a decrease in the risks that remain after security controls are applied, making it a strong argument for budget reallocation. Options A and D focus on incident counts and vulnerabilities, which may not directly address the overall effectiveness of security measures, while B concerns inherent risk, which does not reflect the current risk post-controls.