リスク評価の実施により、サービス拒否 (DoS) 攻撃の脅威が特定されました。経営陣は、このリスクに関連するこれ以上の措置を講じないことを決定しました。MO ST がこの決定を下した理由として考えられるのは、
正解:D
Explanation Executive management may not take action related to a risk if they have determined that the cost of implementing necessary controls to mitigate the risk exceeds the potential financial losses that the organization may incur if the risk were to materialize. In cases such as this, it is important for the information security team to provide the executive team with thorough cost-benefit analysis that outlines the cost of implementing the controls versus the expected losses from the risk.