Correct Answer: Identifying assets, threats, and vulnerabilities specific to the system, engaging business stakeholders to understand actual criticality and context, and validating the assessment against the system's actual current deployed configuration
Explanation: Asset/threat/vulnerability identification, stakeholder-informed business context, and validation against actual deployed configuration together provide an accurate assessment, unlike a generic uncustomized checklist, technical-only assessment with no business input, diagram-only assessment with no validation, skipping identification to jump to mitigations, or a one-time assessment with no ongoing relevance.
Correct Answer: Identifying assets, threats, and vulnerabilities specific to the system, engaging business stakeholders to understand actual criticality and context, and validating the assessment against the system's actual current deployed configuration
Explanation: Asset/threat/vulnerability identification, stakeholder-informed business context, and validation against actual deployed configuration together provide an accurate assessment, unlike a generic uncustomized checklist, technical-only assessment with no business input, diagram-only assessment with no validation, skipping identification to jump to mitigations, or a one-time assessment with no ongoing relevance.