This document discusses taking a value-centric approach to governance, risk, and compliance. It argues that governance, risk, and compliance should be integrated, not separate activities, with governance directing the IT organization to achieve business objectives while managing risks and ensuring compliance. The document provides examples of governance frameworks and principles and emphasizes measuring the right things to demonstrate the value of IT investments.