In this whitepaper, Michael Rasmussen of Corporate Integrity, leading authority on Governance, Risk and Compliance (GRC), discusses best practices, approaches and strategies for creating a sustainable IT and Risk Program to meet the ever changing demands of today's and tomorrow's GRC needs. Critical to sustainability include content management, workflow, infrastructure and asset discovery and classification, identity management, change & configuration management, problem management and remediation, automated protection and enforcement, and reporting.