A. Structure of the ITSRB Approach
It is common practice for frameworks to follow a
structured life cycle, as highlighted in the comparative
analysis section of this paper. Additionally, the "iteration"
attribute as defmed in section three of this paper highlights the
importance of using a systematic process that is continuous for
IT security risk management. Furthermore, it was previously
stated that one of the objectives of this study is to re-use the
best characteristics of the best practice frameworks in order to
avoid re-inventing the wheel. Accordingly, the ITSRB
approach will not deviate from this practice and will adopt the
PDCA model as well as the "Iteration" attribute. Figure V
presents the four phases of the ITSRB approach based on the
PDCA model.