The PRIMARY purpose of implementing additional security controls is to:
Security controls are implemented to reduce risk until its residual level falls within the organization’s acceptable risk tolerance. Compliance obligations and data-protection laws can be inputs to risk management, but managing risk to an acceptable level is the fundamental objective.
Community Discussion