Information Security Compliance

All posts must be a minimum of 250 words. APA reference. 100% original work. no plagiarism.

1. What is IT Security Auditing? What does it involve?
2. Why are Governance and Compliance Important?
3. Explain in details the roles and responsibilities in an organization associated with the following:
    Risk Manager
    Executive Manager
4. Define the Certification and Accreditation (C&A) Process and briefly discuss the phases of C&A.

