The Cybersecurity Control Framework is designed to integrate risk and security management into Information Technology (IT) operations. IT must take a risk-based approach to operational activities, initiatives, projects, and services. Information and data that is not secured is subject to increasing levels of risk that can exceed the risk appetite and capacity of the GoA.