Establish an IT risk management framework that is aligned to the organization’s (enterprise’s) risk management framework.