🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control84 / 150
Question 84 of 150
A financial services company's board has approved a formal statement declaring that the enterprise will accept minimal risk to customer data confidentiality but is willing to pursue moderate operational risk to enable rapid product innovation. During a project review, a risk practitioner finds a proposed feature that would expose customer personal data to a level exceeding the defined threshold, though it stays within the enterprise's overall ability to absorb a loss without threatening solvency. What is the practitioner's BEST course of action?
Reviewed for accuracy · Report an issueNext question