This document provides information on IT security management, including the cost of security breaches, the NIST framework, tiers of a framework, essential focus functions, incident response plan, phases of IRP, types of penetration testing, metrics for measuring incident response, challenges faced by incidence response teams, considerations in computer forensics, and data acquisition.