An organization has a high IT risk appetite but weak internal controls. An IS auditor should PRIMARILY recommend:
-
A
Increasing IT spending to match the risk appetite
-
B
Aligning the control environment with the documented risk appetite
-
C
Reducing the risk appetite to match existing controls
-
D
Transferring all residual risk to a third party