Upon receiving an external vulnerability alert, the first step in the CRISC risk process is to determine organizational exposure - i.e., whether and where the vulnerable software is actually used in the enterprise environment. ISACA's CRISC framework states: "The initial step upon receiving notice of a new vulnerability is to assess the enterprise's exposure to the threat to determine relevance and potential impact." Only after confirming exposure should the practitioner recommend patching, escalation, or other actions. Acting prematurely without confirmation could cause unnecessary disruptions. Hence, B. Determine organizational exposure is correct. CRISC Reference: Domain 2 - IT Risk Assessment, Topic: Vulnerability Management and Exposure Analysis.