正解:A
Explanation
Risk analysis is the process of defining and analyzing the dangers to individuals, businesses, and government agencies posed by potential natural and human-caused adverse events. Risk analysis involves identifying the sources and consequences of risk, estimating the likelihood and severity of risk events, and evaluating the effectiveness and feasibility of risk mitigation strategies. Risk analysis can be applied to various domains, such as IT, finance, security, health, environment, etc. Risk analysis can help to make informed decisions, optimize resource allocation, and enhance performance and resilience. One of the aspects of risk analysis is to measure the maturity level of the security program, which is the degree of development and capability of the security processes and controls that protect the organization from threats and vulnerabilities. A security maturity model is a framework that defines the stages or levels of security maturity and provides a roadmap for improvement.
A security maturity model can help to identify the strengths and weaknesses of the security program, prioritize the actions and resources, and benchmark the progress and impact of the security program. References:
Security Maturity Models: Levels, Assessment, and Benefits, paragraph 1 Maturity Model | SANS Security Awareness, paragraph 1 CBAP / CCBA Certified Business Analysis Study Guide, 2nd Edition, page 47