Challenges and solutions: critical factors required to make a risk based approach successful The start of the journey: achieving close alignment between IT and the business Focusing on people and process: establishing accountability and responsibility for systems and processes Delivering benefits through a converged approach to information security and business continuity From theory to practice: turning frameworks into effective governance mechanism