正解:B
The percentage of risk investments with defined business cases is a metric that measures how well the information security program aligns with the operational objectives of the organization. It indicates how many of the security-related investments are justified by a clear analysis of the expected benefits, costs, and risks, and how they support the business goals and priorities. This metric can help the organization optimize its security spending, demonstrate the value of security to the stakeholders, and align the security strategy with the business strategy1. Reference = Performance Measurement Guide for Information Security, Section 3.2.3, page 16; Key Performance Indicators for Security Governance, Part 1, Section 3, page 3.