The best practice for documenting and prioritizing IT risks

What is the best practice for documenting and prioritizing IT risks so you can make a plan to address the risks?