The first step in managing IT security is to develop a security policy based on confidentiality, integrity, and availability. A security policy is what is secured for a system, organization or another entity. This keeps make sure that all important information is kept secure and only available to those tho should have access to it.