When collecting information to identify IT-related risk, a risk practitioner should FIRST focus on IT: