A. Risk assessment before the system has been deployed B. Risk assessment while the system is being developed C. All of the mentioned D. None of the mentioned
A. Controls that are intended to ensure that attacks are unsuccessful B. Controls that are intended to detect and repel attacks C. Controls that are intended to support recovery from problems D. All of the mentioned