“…Given that the PSPRM as a document is an objective form of data, the logic was that the fundamental or foundational issues in the guide could be readily verified by anyone with an interest (by looking at the literature referenced and the PSPRM guide itself), and further that these gaps should be corrected prior to moving onto more specific issues flowing from these foundations. It is hoped that the limited review provides a useful starting point in this regard, while at the same time illustrating existence proofs [41] of the argumentation. Further, it is hoped that the starting point provided here endows a useful platform for future research seeking to integrate other areas of organizational risk knowledge that are already wellestablished, into the IS risk literature, including such topics as risk communications and risk migration [23,42].…”