B) To reduce the risk of today's security threats, poor security practices, and operational security compliance failures. This is the most comprehensive answer.
I'm leaning towards B as well. The other options seem too narrow or specific. Risk management is about taking a holistic view and implementing controls to lower the organization's overall security risk profile.
B sounds right to me. IT security risk management is all about identifying, assessing, and mitigating the various risks the organization faces. The goal is to proactively reduce those risks.
The key here is "overarching goal," so I'm guessing it's not just about cataloging risks or giving confidence in breach response. Reducing threats and poor security practices seems like the broader objective.
Skye
15 days agoMerlyn
20 days agoNieves
26 days agoMerilyn
1 month agoDetra
1 month agoThea
1 month agoErnie
2 months agoPhung
2 months agoJarvis
2 months agoCatrice
2 months agoTy
2 months agoMonroe
2 months agoSabra
3 months agoMaile
3 months agoTiffiny
3 months agoAnabel
4 months agoRodney
4 months agoAshlee
4 months agoLindy
4 months agoHollis
4 months agoHaydee
4 months agoLinwood
5 months agoKarma
5 months agoAnnice
5 months ago