1. What is benchmarking?
2. What is the standard of due care? How does it relate to due diligence?
3. What is a recommended security practice? What is a good source for finding such recommended practices?
4. When selecting recommended practices, what criteria should you use?