1. Define IT security management. 2. List the three fundamental questions IT sec
ID: 3623694 • Letter: 1
Question
1. Define IT security management.2. List the three fundamental questions IT security management tries to address.
3. List the steps in the process used to address the three fundamental questions.
4. List some of the key national and international standards that provide guidelines on IT security management and risk assessment.
5. List and briefly describe the four steps in the iterative security management process.
6. List and briefly describe the four approaches to identifying and mitigating IT risks.
7. List the steps in the detailed security risk analysis process.
8. Define asset, control, threat, risk, and vulnerability.
9. Define consequence and likelihood.
10. List and define the three broad classes of controls from those given the following table
http://ecpionline.com/file.php/3461/documents/Unit_4/NISTControls.docx