A risk practitioner is defining metrics for security threats that were not identified by antivirus software. Which type of metric is being developed?
When reviewing the business continuity plan (BCP) of an online sales order system, a risk practitioner notices that the recovery time objective (RTO) has a shorter lime than what is defined in the disaster recovery plan (DRP). Which of the following is the BEST way for the risk practitioner to address this concern?
Which of the following is the BEST method to mitigate the risk of an unauthorized employee viewing confidential data in a database''
The PRIMARY objective for requiring an independent review of an organization's IT risk management process should be to: