1. Choosing the level of acceptable risk for the organization
2. Development of basic options for the analysis and assessment of security risks
3. Implementing the organization's security plan implementation of protective measures, their knowledge and understanding, training in the application of protective measures
4. Implementation of additional security measures including verification of the implementation of protective measures, monitoring, change management, handling possible security incidents in the organization