Question 1: Please describe the merits and drawbacks of OCTAVE Allegro, NIST, and FAIR. Describe 1 merit and 1 drawback for each method/framework.
Question 2: When would you recommend using each of the above methods/frameworks? Give at least two recommendation criteria for each method/framework.
Question 3: When looking at risk management and cyber security for any given organization or company, how do you know when you have "enough security"? What pushback might you receive on your response from the first part of this question, and how would you respond to it?