正解:C
Verified answer: According to the CISM Review Manual, 15th Edition, Chapter 3, Section 3.2.1.1,
"Recommendations for enterprise investment in security technology should be primarily based on the organization's risk tolerance."1 Comprehensive and Detailed Explanation: The organization's risk tolerance is the degree of uncertainty that the organization is willing to accept in order to pursue its objectives. It reflects the organization's appetite for risk and its ability to cope with potential losses or disruptions. The higher the risk tolerance, the more aggressive and innovative the security investments can be, as they can help achieve faster growth or competitive advantage. The lower the risk tolerance, the more conservative and defensive the security investments should be, as they can help protect the organization's assets and reputation from potential threats.
References: 1: CISM Review Manual, 15th Edition, Chapter 3, Section 3.2.1.1