4. Analyzing Risks
IT controls are selected and implemented on the basis of the risks they are designed to manage. As risks are identified, suitable risk responses are determined and range from doing nothing and accepting the risk as a cost of doing business to applying a wide scope of specific controls. This section explains the concepts of when to apply IT controls