answers
A risk assessment ends with a report. Ans✓✓✓ True
A risk assessment provides a point-in-time report. Ans✓✓✓ True
After you collect data on risks and recommendations, you include that
information in a report, and you give that report to management. Why do
you do this? Ans✓✓✓ to help management decide which
recommendations to use
All of the following are risk treatments in different frameworks except?
Ans✓✓✓ Ignore
COBIT worked with ISACA to develop ITGI. Ans✓✓✓ False
FAIR's BRAG relies uses qualitative assessment of many risk
components using scales with value ranges. Ans✓✓✓ False
In information security, a framework or security model customized to an
organization, including implementation details is known as a floor plan.
Ans✓✓✓ False
Information Technology Infrastructure Library provides guidance in the
development and implementation of an organizational InfoSec
governance structure. Ans✓✓✓ False