Establish a IT security risk management program based on enterprise business goals and objectives.
12.1.2 Establish the risk assessment process.
12.1.3 Advise senior management on the impact during the decision making process by helping them understand and evaluate the impact of IT security risks on business goals, Objectives, plans, programs, and actions.