The BEST way to validate that a risk treatment plan has been implemented effectively is by reviewing:
Correct Answer: D
A post-implementation RCSA is a process of verifying whether the risk treatment plan has been executed as intended and whether the residual risk is within the acceptable level. It involves testing the effectiveness of the controls that have been implemented to mitigate the risk and identifying any gaps or issues that need to be addressed. A BIA, the original risk response plan, and the training program and user awareness documentationare not sufficient to validate the effectiveness of the risk treatment plan, as they do not measure the actual performance of the controls or the residual risk.
References:
*ISACA, Risk IT Framework, 2nd Edition, 2019, p. 761
*ISACA, Risk and Information Systems Control Review Manual, 7th Edition, 2020, p. 2112