A Chief Risk Officer is reviewing the organization's cyber risk appetite statement. Which element is most critical to include when defining cyber risk tolerance thresholds?
-
A
The number of IT staff available for incident response
-
B
Quantified maximum acceptable loss exposure tied to business objectives
-
C
The age of existing firewall infrastructure
-
D
The number of security certifications held by employees