B) To reduce the risk of today's security threats, poor security practices, and operational security compliance failures. This is the most comprehensive answer.
I'm leaning towards B as well. The other options seem too narrow or specific. Risk management is about taking a holistic view and implementing controls to lower the organization's overall security risk profile.
B sounds right to me. IT security risk management is all about identifying, assessing, and mitigating the various risks the organization faces. The goal is to proactively reduce those risks.
The key here is "overarching goal," so I'm guessing it's not just about cataloging risks or giving confidence in breach response. Reducing threats and poor security practices seems like the broader objective.
Ernie
24 hours agoPhung
6 days agoJarvis
11 days agoCatrice
16 days agoTy
22 days agoMonroe
27 days agoSabra
2 months agoMaile
2 months agoTiffiny
2 months agoAnabel
2 months agoRodney
2 months agoAshlee
2 months agoLindy
3 months agoHollis
3 months agoHaydee
3 months agoLinwood
3 months agoKarma
3 months agoAnnice
3 months ago