Plan refers to establishing the proposed IT security risk
management approach. Do refers to the activities involved in
implementing and operating the proposed IT security risk
management approach. Check refers to the process of monitoring and reviewing the IT security risk management
approach. Act refers to the process of maintaining and
improving the IT security risk management approach which
involves maintaining the IT security controls.