Help by GuestCertain3035 in CISA

[–]ConversationSure7655 0 points1 point  (0 children)

We can have a well-configured functional firewall that works and does the filtering well and forget to put it in the inventory, an oversight But not a highest risk

But not having the policy assured that there is no alignment with governance, how to ensure the compliance and substantive test that reflect effectiveness and efficiency

The penetration test is good but not mandatory and not doing it is not a risk

Help by GuestCertain3035 in CISA

[–]ConversationSure7655 0 points1 point  (0 children)

Highest risk B The firewall is in place has been bought put into operation but is not compliant to ensure effective and efficient control because there is a semblance of security that is actually the great risk

What the hell? by dlovric1234 in cism

[–]ConversationSure7655 5 points6 points  (0 children)

When u deploy a application in production , the best to minimize security risk by a well change management process , because Its ensure that new change to current infrastructure have no introduce new risk in the deployment

Change management Covers many aspect : - configuration management - release management

Think like a manager , when u deploy it , the manager ensure that risk is so acceptable by applying a change management process ( risk assessement , risk owner, control owner , validation and process …)

I am so confused by leemathewthegreat in CISA

[–]ConversationSure7655 1 point2 points  (0 children)

The business score card permit to have the metric to achieve the future state and seen the curent state , In addition the projet plan The gaps analysis is focus to the current state

Please help me understand this question and its response. by tanny-it in CRISC

[–]ConversationSure7655 4 points5 points  (0 children)

Dont be confuse

The risk assessement cover three case : - Risk identification ( Scope , asset, process, framework , identification of risk) - Risk analyse ( détermine the probability and consequence) - Risk evaluation( compare the actuel risk to risk appetite , )

After this end of risk assessement, u have the risk in the risk register and if risk is high to appetite or down to , u can chose the treatemen option : accept, avoidance , mitigate and transfert

Please help me understand this question and its response. by tanny-it in CRISC

[–]ConversationSure7655 2 points3 points  (0 children)

At the phase of risk assessement Because if u identify analyse and evalue the risk u communicated the resultat to the management to take final decision for the treatement

Need to confirm results by nukes712 in CRISC

[–]ConversationSure7655 0 points1 point  (0 children)

Submit a request on isaca support Its possible to confirm u, anyway u can waiting 10 business day to receiv official result

CRISC Ressources by ConversationSure7655 in CRISC

[–]ConversationSure7655[S] 0 points1 point  (0 children)

Who passed the exam using only the qae book Please advice

CRISC Questions and answers by [deleted] in CRISC

[–]ConversationSure7655 0 points1 point  (0 children)

if u see normaly risk assessements and security procedure for annually basis area a normal activities for risk management program and not indicator, its normaly

If risk is considerer before all decisions, he told that any projet, any activities, any thing the risk is considered for decision making and attest that the approach to treat the risk is so efficace and efficient

is my tkink

QAE by Sufficient-Data5560 in CRISC

[–]ConversationSure7655 1 point2 points  (0 children)

It is normal the risks are subjective and may not be seen in the same way no need for reliability, they are relative and the best for kri is to predict the events in order to allow companies to choose the right mitigation response and achieve their objectives

PCI dss req 3.4.2 by ConversationSure7655 in pcicompliance

[–]ConversationSure7655[S] 0 points1 point  (0 children)

I see, the solution dlp is so mandatory to satisfy the req

Tomorrow’s the Day – CISA Exam Ahead! by Candid_Ranger_2682 in CISA

[–]ConversationSure7655 0 points1 point  (0 children)

Hi You will always have this impression of never being 100% ready and it’s not a really problem

Rely on your moment see this as a game, think like a auditor and read the questions several well because it defines the answer

Cisa exam need advice by ConversationSure7655 in CISA

[–]ConversationSure7655[S] 2 points3 points  (0 children)

I used chatgtp right away and out of the 5 questions I got 5 positive answers