The first step in establishing an ethical governance culture is to create a clear and formal policy outlining acceptable behavior and consequences for violations. ISACA guidance: "Developing and approving an enterprise code of ethics or ethical policy establishes the foundation for enforcing ethical conduct and guiding all subsequent training and enforcement activities." Training and enforcement follow policy creation. Therefore, D. Create a policy regarding ethical behavior is correct. CRISC Reference: Domain 1 - IT Risk Governance, Topic: Ethics and Governance Policies.