B) To reduce the risk of today's security threats, poor security practices, and operational security compliance failures. This is the most comprehensive answer.
I'm leaning towards B as well. The other options seem too narrow or specific. Risk management is about taking a holistic view and implementing controls to lower the organization's overall security risk profile.
B sounds right to me. IT security risk management is all about identifying, assessing, and mitigating the various risks the organization faces. The goal is to proactively reduce those risks.
The key here is "overarching goal," so I'm guessing it's not just about cataloging risks or giving confidence in breach response. Reducing threats and poor security practices seems like the broader objective.
Sabra
3 days agoMaile
8 days agoTiffiny
14 days agoAnabel
19 days agoRodney
24 days agoAshlee
29 days agoLindy
1 month agoHollis
1 month agoHaydee
1 month agoLinwood
2 months agoKarma
2 months agoAnnice
2 months ago