Correct Answer: Selecting a mitigation proportionate to the assessed risk severity and organizational risk tolerance, independently reviewing the mitigation's own architecture for secondary risks, and formally documenting any accepted residual risk with appropriate stakeholder sign-off
Explanation: Proportionate mitigation selection, independent secondary-risk review, and documented residual risk acceptance with sign-off together provide effective governance, unlike selecting the most expensive option regardless of severity, deploying without review, leaving residual risk undocumented, compliance-only selection, or accepting every risk by default.
Correct Answer: Selecting a mitigation proportionate to the assessed risk severity and organizational risk tolerance, independently reviewing the mitigation's own architecture for secondary risks, and formally documenting any accepted residual risk with appropriate stakeholder sign-off
Explanation: Proportionate mitigation selection, independent secondary-risk review, and documented residual risk acceptance with sign-off together provide effective governance, unlike selecting the most expensive option regardless of severity, deploying without review, leaving residual risk undocumented, compliance-only selection, or accepting every risk by default.