An organization wants to quantify the potential financial impact of a data breach to prioritize remediation. Which approach aligns with risk assessment best practices for SC-400?
-
A
Use only qualitative risk ratings (high/medium/low)
-
B
Combine asset sensitivity classification with likelihood and impact scoring
-
C
Run Microsoft Secure Score and use it as the financial risk figure
-
D
Rely solely on Compliance Manager scores for financial impact