The areas of concern for organizations regarding information security best practices

What are the areas of concern for organizations regarding information security best practices and IT Risk Management and who is responsible for implementing and enforcing the usage of information security best practices and IT Risk Management within an organization?