With an emphasis on the use of simple, pragmatic risk management as a decision-making tool, this guide concentrates on the proactive development and implementation of IT security.