In DevSecOps, what does a 'risk appetite statement' formally define?
-
A
The maximum number of vulnerabilities allowed per release
-
B
The level and type of risk an organization is willing to accept in pursuit of objectives
-
C
The budget allocated for security tooling each quarter
-
D
The list of approved third-party vendors for security services