1/52
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Governance
Overall management of the org’s IT infrastructure, policies, procedures, and operations
Compliance
Adherence to laws, regulations, standards and policies that apply to the operations of the organization
GRC
Governance, Risk, Compliance
Purpose of Governance
establishes a strategic framework aligning with objectives and guidelines. Defines rules, responsibilities, and practices for achieving goals and managing IT resources
Monitoring
Regularly reviewing and assessing the effectiveness of governance framework
Revision
Updating the governance framework to address these gaps or weaknesses
Organizational Governance
Complex, multifaceted concept essential for successful org operation and comprises various components with unique functions
Boards
a board of directors is a group of individuals elected by shareholders to oversee the management of an organization
Committees
Subgroups of a boards of directors each with a specific focus
Government Entities
Establish laws and regulations that orgs must comply with
Centralized Structures
Decision-making authority is concentrated at the top levels of management
Decentralized Structures
Distributes decision-making authority throughout the organization
Acceptable Use Policy (AUP)
Document that outlines the do’s and don'ts for users when interacting with an org’s IT systems and resources
Information Security Policies
Outline how an organization protects its information assets from threats both internal and external. Cover data classification, access control, encryption, physical security
Business Continuity
Focuses on how an org with continue its critical operations during and after s disruption
Disaster Recovery
Focuses specifically on how an org with recover its IT systems and data after a disaster. Outlines data backup, restoration, hardware/software recovery, and alt locations
Incident Response
Plan for handling security incidents
Software Development LifeCycle (SDLC)
Guides how software is developed within an organization
Change Management
Aims to ensure that changes are implemented in a controlled and coordinated manner, minimizing the risk of disruptions
Standards
Provide a framework for implementing security measures, ensuring that all aspects of an org’s security posture are addressed
Password Standards
Define password complexity and management
Access Control Standards
Determine who had access to what resources within an org
Discretional Access Control (DAC)
Allows the order of the information or resource to decide who can access it
Mandatory Access Control (MAC)
uses labels or classifications to determine access, common in gov or military
Role-Based Access Control (RBAC)
Assigns access based on roles within an org so users only have access to things based on role in org
Physical Security Standards
Cover the physical measures to protect an org’s assets and information
Encryption Standards
Ensure that data intercepted or accessed without authorization remains unreadable and secure
Procedures
Systematic sequences of actions or steps taken to achieve a specific outcome
Stages for change management
Identifying need for change, assessing impact, developing a plan, implementation, post change review
Onboarding procedures
Process of integrating new employees into the organization. Make sure new employees are productive and engaged as soon as possible
Offboarding procedures
Ensure a smooth transition for when an employee leaves, both for the departing employee and org, and to gather feedback
Playbooks
Step by step Checklists of actions to perform to detect and respond to a specific type of incident
Regulatory Considerations of Governance
Can cover a wide range or areas, from data protection and privacy to environmental standards and labor laws. EG: GDPR (General Data Protection Regulation).
Legal Considerations of Governance
Encompass areas like contact law, intellectual property, and corporate law
Industry Considerations of Governance
Specific standards and practices that are prevalent in a particular industry. Not legally binding but influence customer, partner, and regulator expectations and if you don’t use them, it can lead to competitive disadvantages and stakeholder criticism
Geographical Considerations
Local (city), regional (state or province), national, and global regulations can impact orgs
Compliance Reporting
Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements
Internal Compliance Reporting
Collection and analysis of data to ensure that an org is following its internal policies and procedures
External Compliance Reporting
Demonstrating compliance to eternal entities and is mandatory by law or contract
Compliance Monitoring
The process of regularly reviewing and analyzing an organization’s operations to ensure compliance with laws, regulations, and internal policies
Due Diligence
Conducting an exhaustive review an org’s operations to identify potential compliance risks
Due Care
The steps taken to mitigate risk found by due diligence
Attestation
Formal declaration by a responsible party that an org’s process and controls are compliant
Acknowledgement
Regcognition and acceptance of compliance requirements by all relevent parties
Internal Monitoring
Regularly reviewing an org’s operations to ensure compliance with internal policies
External Monitoring
3rd-party reviews for compliance with external regulations or standards
Automation in Compliance
Streamlines data collection, improves accuracy and provides real-time monitoring
Fines
Monetary penalties imposed by regulatory bodies for non-compliance with laws and regulations
Sanctions
Strict measures taken by regulatory bodies to enforce compliance, like restrictions and bans
Reputational Damage
Negative impact on a company’s reputation, significant and long-lasting in the age of social media
Loss of License
Non-compliance can cause the loss of the right to operate, relevant in regulated industries
Contractual impacts
Breach of contracts due to non-compliance with laws and regulations, can lead to legal disputes, financial penalties, or contract termination
How to avoid non-compliance
Understand and adhere to relevant laws and regulations, implement robust security measures, regularly reviewing and updating compliance programs