COSO notes that "Enterprise risk management is not strictly a serial process, where one component affects only the next. It is a multidirectional, iterative process in which almost any component can and does influence another." COSO reinforces this point by integrating these components with standard corporate objectives as represented by the complex, three dimensional image on the right. The observation is correct, information security is a complex field where one element can have multiple impacts across the framework. However, there is a tendency for information security officers to become swept up in these inter-relationships and become lost or overwhelmed. In order to minimize confusion, this Web site advocates a sequential approach in order to keep the focus on the process. Keep it simple - just Assess, Control, Monitor and Respond.