I'm not sure about the other options, but I think C is definitely wrong. The control objective being compliant doesn't necessarily mean the related risks have been mitigated.
Option B seems like the correct answer here. A control related to the control objective should be linked as a mitigating control for the associated risk statement.
Margery
7 days agoAlysa
12 days agoAzalee
13 days agoLawana
18 days agoVeronique
19 days ago