Which of the following BEST describes the concept of 'residual risk' in the context of a DPIA?
-
A
Risk that has been fully eliminated through technical controls
-
B
Risk that remains after all identified mitigation measures have been applied
-
C
Risk transferred to a third-party processor via contract
-
D
Risk covered by the organization's cyber insurance policy