From the operational side, it includes the infrastructure. Does the infrastructure itself present risks of achieving the business goals and objectives? If the IT function writes or modifies code, the degree to which the staff uses best practices of systems development life cycle (SDLC) reduces risks in the outcomes of the staff and IT. Almost always there will be a significant need for an effective information security program to protect assets and mitigate unauthorized access to information assets and systems.