Which activity is MOST critical to maintaining an accurate risk register over time?
-
A
Regular review and update based on changes in threats, controls, and business context
-
B
Annual recertification of all risks by IT management
-
C
Automated import of vulnerability scan data into the register
-
D
Archiving old risks to keep the register manageable