An SE approach to IT security will facilitate managing it effectively. Understanding IT security risk and its impact in terms of damage to the organization will help to identify the level of risk that the organization must manage or accept. First, the System Security Engineer (SSE) must understand the nature of risks in terms of vulnerabilities and exposures and their likelihood of being used against the organization along with their impact. Second, the SSE must have a good grasp of mitigation factors, the extent to which risks are mitigated by various technologies and their relative costs. Third, the SSE must be able to provide critical reports to management to obtain needed resources to implement the mitigations and maintain a level of currency in risk management