Security and compliance reviewers must determine whether material threats have been identified, whether required controls address those threats, how remaining exposure will be accepted, and whether the decision can be demonstrated during an audit. Option C supplies exactly that evidence.
The threat model establishes protected assets, trust boundaries, adversaries, attack paths, and likely failure modes. Control mappings connect technical and procedural safeguards to organizational policies, regulatory requirements, and assurance frameworks. Residual-risk acceptance criteria define which risks may remain after mitigation, who has authority to accept them, and when further treatment is mandatory. Audit traceability connects requirements and decisions to implementation evidence, evaluations, approvals, logs, and operational monitoring.
Option A is designed primarily for product management. Option B addresses engineering planning and execution. Option D is appropriate for an executive sponsor who requires business justification and a concise risk summary but normally does not perform detailed control verification.
Audience adaptation should not alter the architectural decision itself. It changes the depth, terminology, evidence, and ordering used to communicate the decision. Security and compliance reviewers require verifiable control evidence rather than only schedule, implementation, or business-level summaries.
Study Guide references/topics: Audience-specific communication; threat modeling; compliance control mapping; residual-risk acceptance; audit evidence; architectural decision traceability.
===============