What should be done NEXT if the final set of security controls does not eliminate all of the risks in a given system?
1) Continue to apply additional controls until there is zero risk
2) Accept the risk if the residual risk is low enough
3) Remove the current controls since they are not completely effective
4) Ignore any remaining risk