CISM Certified Information Security Manager – Question0355

Which of the following is the PRIMARY goal of a risk management program?

A.
Implement preventive controls against threats.
B. Manage the business impact of inherent risks.
C. Manage compliance with organizational policies.
D. Reduce the organization’s risk appetite.

Correct Answer: B