A Risk Control Self-Assessment (RCSA) is a process where business units, such as application development teams, evaluate their own risks and controls. The questions provided focus on identifying and assessing potential risks associated with the application, such as: * External patches: Identifies risks from third-party sources. * Open-source code: Assesses the presence of potentially unvetted or vulnerable components. * External accessibility: Evaluates exposure to external threats. * Password standards: Ensures compliance with corporate security policies. These questions directly align with a self-assessment of risks and the effectiveness of controls in place. * B. Risk management strategy: This refers to an overarching plan for identifying, assessing, and mitigating risks, not the process of asking specific operational questions. * C. Risk acceptance: This is a decision to accept identified risks rather than mitigate them; it does not involve assessing controls. * D. Risk matrix: A tool used to evaluate and prioritize risks, not a process for asking detailed application- specific questions. Why not the other options?