The CCISO Body of Knowledge defines the primary goal of risk management as achieving an economic balance between risk exposure and the cost of controls. CCISO materials emphasize that not all risks should be eliminated—only managed within acceptable tolerance.
Therefore, option B is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit