正解:B
Risk appetite reflects how much risk the organization is willing to tolerate. It is the primary driver when defining control objectives, ensuring alignment with overall business strategy.
"Risk appetite should be used to guide the selection and design of control objectives to ensure risk is managed within acceptable boundaries."
- CISM Review Manual 15th Edition, Chapter 2: Risk Management Strategy* Support, budget, and threats matter, but without alignment to risk appetite, controls may be misaligned.