1. When choosing recommended practices, what limitations should you keep in mind?
2. What is baselining? How does it differ from benchmarking?
3. What are the NIST-recommended documents that support the process of baselining?
4. What is a performance measurement in the context of InfoSec management?