Which of the following is a true statement about BIS infrastructure security risk assessment?
A. BIS security risk assessments consider the likelihood of potential threats to disrupt business operations, the severity of the disruptions, and the adequacy of existing security controls to guard against disruptions.
B. COBIT is a widely used risk assessment framework for BIS infrastructures.
C. Risk assessments are used to identify security improvements for BIS infrastructures.
D. All the above