A company has been improving its organizational security and compliance program since the last security review was conducted one year ago. What should the company do to evaluate its current risk profile?
A) Conduct follow-up audits in areas that were found deficient in the previous review
B) Monitor the key risk indicators and use the results to develop targeted assessments
C) Perform a new enterprise risk assessment using an independent expert
D) Implement a random risk inspection policy