I think we might need to evaluate the responses first, but I also recall something about closing findings if the evidence is adequate. It’s a bit confusing!
I remember a practice question where we had to decide if we should close findings or schedule follow-ups. I’m not sure if we should close them right away without further evaluation.
This seems like a straightforward question about mitigating scope creep. I'd focus on the key controls mentioned, like project change management and configuration management.
Okay, let me think this through step-by-step. COBIT and ISO 31000:2009 are definitely risk management frameworks, and NIST SP 800-37 is also a well-known one. That leaves Hex GBL as the odd one out. I'm going to go with that as my answer.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Vilma
3 months agoDesmond
3 months agoHubert
3 months agoShonda
4 months agoIra
4 months agoLuann
4 months agoRodolfo
4 months agoFletcher
4 months agoTwana
5 months agoPearly
5 months agoJohana
5 months ago