The management and control security of an entity's information technology infrastructure and processes. Specific topics include information security risk identification and management, telecommunications, applications, and operational security, physical security, and business continuity and disaster recovery planning.