medium
Single Answer
0You are completing your business continuity planning effort and have decided that you want to accept one of the risks. What should you do next?
Answer Options
A
Implement new security controls to reduce the risk level.
B
Design a disaster recovery plan.
C
Repeat the business impact assessment.
D
Document your decision-making process.
Correct Answer: D
Explanation
Whenever you choose to accept a risk, you should maintain detailed documentation of the risk acceptance process to satisfy auditors in the future. This should happen before implementing security controls, designing a disaster recovery plan, or repeating the business impact analysis (BIA).