ISACA has posted an exposure draft on Enterprise Risk: Identify, Govern and Manage Risk The Risk IT Framework. The association is inviting authors to provide feedback, comments and suggestions to improve the publication. Per ISACA,
This IT enterprise risk management framework was designed to allow business managers to identify and assess IT-related business risks and manage them effectively. It provides the missing link between enterprise risk management (ERM) and IT risk management and control, fitting in the overall IT governance framework of ITGI, and building upon all existing risk related components within the current frameworks, i.e., COBIT and Val IT.