Which of the following is not one of the seven steps recommended by the NIST 800-53 standard for building an effective risk management system?
A. Understanding the impact of risk on each system in the organization
B. Adjust or tailor the initial baseline of security controls after assessing the impacts of identified risk
C. Monitor and assess selected controls continually
D. Perform adequate penetration testing activities to ensure security of software products
Computer Science & Information Technology