A large organization is implementing a security controls framework and wants to prioritize controls that provide the greatest risk reduction with the least operational friction. Which approach should the security manager adopt?
This risk-based approach ensures resources are focused on the most impactful controls.
Why this answer
Prioritizing critical controls first, especially those that address the most significant risks and are business-enabling, aligns with defense-in-depth and risk-based decision making.