Question 281:
After assessing and mitigating the risks of a web application, who should decide on the acceptance of residual application risks?
Answer options:
A. Information security officer B. Chief information officer (CIO) C. Business owner D. Chief executive officer (CFO)