A CISO presents a risk appetite statement to the board. What does this statement primarily define?
-
A
The level of risk the organization is willing to accept in pursuit of its objectives
-
B
The list of all identified threats and vulnerabilities
-
C
The budget allocated to cybersecurity controls
-
D
The technical specifications of security tools deployed