For these reasons, a robust IT security risk management
process is required in order to manage IT security risks to a
tolerable level [3][6]. This paper therefore presents a process
that was employed to defme the proposed IT Security Risk
Based (ITSRB) approach, which may used as a blueprint as
well as a mechanism that can be applied by organisations to
respond to IT security risk better.