Latest Research Report
IT governance, risk and compliance
data protection
performance
spend management







2008 Annual Report: IT Governance, Risk and Compliance – Improving Business Results and Mitigating Financial Risk

IT governance, risk and compliance (IT GRC) is about striking an appropriate balance between business reward and risk. The maturity of IT GRC practices for managing reward and risk has a direct impact on the organization.

The 2008 Annual Report, assembled from benchmark research conducted with more than 2,600 organizations around the World, reveals the IT GRC maturity profiles, business outcomes, capabilities and practices that are most responsible for influencing and impacting business rewards and risks.

IT GRC encompasses the practices for delivering:

  • Greater business value from IT strategy, investment and alignment,
  • Significantly reduced business and financial risk from the use of IT, and
  • Conformance with policies of the organization and its external legal and regulatory compliance mandates.

What is striking from the benchmarks is the organizations with best business results are the same firms with the most mature practices. The converse is also true: the organizations with the worst business results are the same firms with the least mature practices.

Business Results and IT GRC Maturity



To determine the IT GRC maturity and business outcomes of your own organization, and the practices and capabilities needed to improve results:



You must be a member to view this report. Join ITPolicyCompliance.com now!





"We are pleased to add to this body of knowlege", said Dave Richards, Prsident of The Institute of Interal Auditors.  "Technology application is advancing so quickly and there's so much associated risk that organizations are in deperate need of as much guidance as possible."  more...



Latest Blog Topics:

Topic : Policy Shapes Outcomes
Topic : Who’s sets objectives: Legal, Business lines or IT?
Topic : Who Manages Information Security?