Governance and Compliance

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/52

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:30 PM on 8/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

53 Terms

1
New cards

Governance

Overall management of the org’s IT infrastructure, policies, procedures, and operations

2
New cards

Compliance

Adherence to laws, regulations, standards and policies that apply to the operations of the organization

3
New cards

GRC

Governance, Risk, Compliance

4
New cards

Purpose of Governance

establishes a strategic framework aligning with objectives and guidelines. Defines rules, responsibilities, and practices for achieving goals and managing IT resources

5
New cards

Monitoring

Regularly reviewing and assessing the effectiveness of governance framework

6
New cards

Revision

Updating the governance framework to address these gaps or weaknesses

7
New cards

Organizational Governance

Complex, multifaceted concept essential for successful org operation and comprises various components with unique functions

8
New cards

Boards

a board of directors is a group of individuals elected by shareholders to oversee the management of an organization

9
New cards

Committees

Subgroups of a boards of directors each with a specific focus

10
New cards

Government Entities

Establish laws and regulations that orgs must comply with

11
New cards

Centralized Structures

Decision-making authority is concentrated at the top levels of management

12
New cards

Decentralized Structures

Distributes decision-making authority throughout the organization

13
New cards

Acceptable Use Policy (AUP)

Document that outlines the do’s and don'ts for users when interacting with an org’s IT systems and resources

14
New cards

Information Security Policies

Outline how an organization protects its information assets from threats both internal and external. Cover data classification, access control, encryption, physical security

15
New cards

Business Continuity

Focuses on how an org with continue its critical operations during and after s disruption

16
New cards

Disaster Recovery

Focuses specifically on how an org with recover its IT systems and data after a disaster. Outlines data backup, restoration, hardware/software recovery, and alt locations

17
New cards

Incident Response

Plan for handling security incidents

18
New cards

Software Development LifeCycle (SDLC)

Guides how software is developed within an organization

19
New cards

Change Management

Aims to ensure that changes are implemented in a controlled and coordinated manner, minimizing the risk of disruptions

20
New cards

Standards

Provide a framework for implementing security measures, ensuring that all aspects of an org’s security posture are addressed

21
New cards

Password Standards

Define password complexity and management

22
New cards

Access Control Standards

Determine who had access to what resources within an org

23
New cards

Discretional Access Control (DAC)

Allows the order of the information or resource to decide who can access it

24
New cards

Mandatory Access Control (MAC)

uses labels or classifications to determine access, common in gov or military

25
New cards

Role-Based Access Control (RBAC)

Assigns access based on roles within an org so users only have access to things based on role in org

26
New cards

Physical Security Standards

Cover the physical measures to protect an org’s assets and information

27
New cards

Encryption Standards

Ensure that data intercepted or accessed without authorization remains unreadable and secure

28
New cards

Procedures

Systematic sequences of actions or steps taken to achieve a specific outcome

29
New cards

Stages for change management

Identifying need for change, assessing impact, developing a plan, implementation, post change review

30
New cards

Onboarding procedures

Process of integrating new employees into the organization. Make sure new employees are productive and engaged as soon as possible

31
New cards

Offboarding procedures

Ensure a smooth transition for when an employee leaves, both for the departing employee and org, and to gather feedback

32
New cards

Playbooks

Step by step Checklists of actions to perform to detect and respond to a specific type of incident

33
New cards

Regulatory Considerations of Governance

Can cover a wide range or areas, from data protection and privacy to environmental standards and labor laws. EG: GDPR (General Data Protection Regulation).

34
New cards

Legal Considerations of Governance

Encompass areas like contact law, intellectual property, and corporate law

35
New cards

Industry Considerations of Governance

Specific standards and practices that are prevalent in a particular industry. Not legally binding but influence customer, partner, and regulator expectations and if you don’t use them, it can lead to competitive disadvantages and stakeholder criticism

36
New cards

Geographical Considerations

Local (city), regional (state or province), national, and global regulations can impact orgs

37
New cards

Compliance Reporting

Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements

38
New cards

Internal Compliance Reporting

Collection and analysis of data to ensure that an org is following its internal policies and procedures

39
New cards

External Compliance Reporting

Demonstrating compliance to eternal entities and is mandatory by law or contract

40
New cards

Compliance Monitoring

The process of regularly reviewing and analyzing an organization’s operations to ensure compliance with laws, regulations, and internal policies

41
New cards

Due Diligence

Conducting an exhaustive review an org’s operations to identify potential compliance risks

42
New cards

Due Care

The steps taken to mitigate risk found by due diligence

43
New cards

Attestation

Formal declaration by a responsible party that an org’s process and controls are compliant

44
New cards

Acknowledgement

Regcognition and acceptance of compliance requirements by all relevent parties

45
New cards

Internal Monitoring

Regularly reviewing an org’s operations to ensure compliance with internal policies

46
New cards

External Monitoring

3rd-party reviews for compliance with external regulations or standards

47
New cards

Automation in Compliance

Streamlines data collection, improves accuracy and provides real-time monitoring

48
New cards

Fines

Monetary penalties imposed by regulatory bodies for non-compliance with laws and regulations

49
New cards

Sanctions

Strict measures taken by regulatory bodies to enforce compliance, like restrictions and bans

50
New cards

Reputational Damage

Negative impact on a company’s reputation, significant and long-lasting in the age of social media

51
New cards

Loss of License

Non-compliance can cause the loss of the right to operate, relevant in regulated industries

52
New cards

Contractual impacts

Breach of contracts due to non-compliance with laws and regulations, can lead to legal disputes, financial penalties, or contract termination

53
New cards

How to avoid non-compliance

Understand and adhere to relevant laws and regulations, implement robust security measures, regularly reviewing and updating compliance programs