Security 11: Governance and Compliance

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/36

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

37 Terms

1
New cards

Governance

Overall management of the organizations, IT infrastructure, policies, procedures, and operations

2
New cards

governance is needed because

risk management

strategic alignment

resource management

performance measurement

3
New cards

compliance

Adherence to laws and regulations.

4
New cards

why we need compliance:

legal obligations

trust and reputation

data protection

business continuity

5
New cards

Governance Structure

boards

committees

government entities

centralized and decentralized structures

6
New cards

boards

A board of directors is a group of individuals elected by shareholders to oversee the management of an organization

7
New cards

committees

Subgroups of a board of directors, each with a specific focus

8
New cards

government entities

They establish laws and regulations that organizations must comply with

9
New cards

Centralized Structure

Decision-making concentrated at the top levels.

10
New cards

Decentralized Structure

Decision-making distributed across various levels.

11
New cards

What are the policies

acceptable use

information security

business continuity

disaster recovery

incident response

SDLC

change management

12
New cards

Acceptable Use Policy

A document that defines what a person may and may not do on an organization's computers and networks.

13
New cards

information security policies

Outline how an organization protects its information assets from threats, both internal and external

14
New cards

Business Continuity

Focuses on how an organization will continue its critical operations during and after a disruption

15
New cards

Disaster Recovery

Focuses specifically on how an organization will recover its IT systems and data after a disaster

16
New cards

Incident Response

Actions taken to address security breaches.

17
New cards

Software Development Life Cycle (SDLC)

Guides how software is developed within an organization

18
New cards

Change Management

Process of making sure changes are made smoothly and efficiently and do not negatively affect systems reliability, security, confidentiality, integrity, and availability.

19
New cards

Standards

provide a framework

20
New cards

Password Standards

Complexity, rotation, and storage requirements.

21
New cards

access control standards

Determine who has access to what resources within an organization

DAC

MAC

RBAC

22
New cards

what are the considerations?

regulatory considerations

legal considerations

industry considerations

geographical boundaries

23
New cards

Regulatory Considerations

These regulations can cover a wide range of areas, from data protection and privacy to environmental standards and labor laws

24
New cards

Legal Considerations

Closely tied to regulatory considerations, but they also encompass other areas such as contract law, intellectual property, and corporate law

25
New cards

Industry Considerations

The specific standards and practices that are prevalent in a particular industry

26
New cards

National Considerations

Laws like the Americans with Disabilities Act (ADA) in the United States

27
New cards

Global Considerations

General Data Protection Regulation ( GDPR ) implemented by the European Union

28
New cards

Compliance Reporting

Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements

29
New cards

Internal Compliance Reporting

Collection and analysis of data to ensure that an organization is following its internal policies and procedures

30
New cards

External Compliance Reporting

Demonstrating compliance to external entities such as regulatory bodies, auditors, or customers, often mandated by law or contract

31
New cards

Compliance Monitoring

The process of regularly reviewing and analyzing an organization's operations to ensure compliance with laws, regulations, and internal policies

32
New cards

due diligence

conducting the necessary research and investigation to make informed decisions that minimize risk

33
New cards

due care

the steps taken to mitigate these risks

34
New cards

Attestation

Formal declaration by a responsible party that the organization's processes and controls are compliant

35
New cards

acknowledgement

recognition for a notable deed

36
New cards

Non-compliance Consequences

Fines, Sanctions, Reputational Damage, Loss of License, Contractual Impacts

37
New cards

Sanctions

restrictions intended to enforce international law