Some of the handbook ’s core ideas include that institutions must identify assets and develop a method for identifying the risks to each IT asset. This method should promote confidentiality, integrity and, finally , availability. Furthermore, the IT Audit should also cover management activities and evaluate the adequacy of both policy and controls implemented by the bank.