There is no single best practice that is appropriate for all areas of risk associated with IT. Each risk area has a number of practices that should be considered. In this Executive Update, I focus on the following three areas:
-          
Business strategy risks
 -          
Compliance risks
 -          
Process risks
 

