1. What are the three primary aspects of information security risk management? Why is each important?
2. What is a management maintenance model? What does it accomplish?
3. What changes needed to be made to the model presented in SP 800-100 to adapt it for use in security management maintenance?