A healthcare organization must comply with HIPAA while managing cybersecurity risks. Which concept describes the influence that regulatory requirements have on acceptable risk levels?
-
A
Risk tolerance constrained by compliance obligations
-
B
Inherent risk without controls applied
-
C
Exposure factor derived from threat frequency
-
D
Asset value adjusted for depreciation