ARMA Flashcards

1
Q

Areas to Monitor

A
  • Assessments or audits of internal patterns and practices
  • Changes in the legal and regulatory environment
  • Benchmarking the program according to objective standards
  • Technology developent
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Internal Factors (business drivers) Examples

A
  • Specific technology adoption within the organization: BYOD, remote access, IoT,impact on IG
  • Internal business requirements that impact how the organization conducts business: It is important to understand how information flows throughout the organization: know and understand business preocesses to id info handling reqs and ensure those req can be met
  • Internal information-handling practices: are interal tools for manageing info in various formats, how do different dep. or business entities share, ways to analze business processes to understand the info access needs of each dept.
  • Org strategic plans and key initiatives: how info used, what opportunities, gaps, how info stored
  • Internal resource allocations or limitations: standard accounting and budgeting methods, elements of cost feasibilities studies, ROI
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

External Business drivers

A
  • Legal and Regulatory req. unique to business
  • litigation patterns in an organization
  • Regulation or legistlation that results from the industry the org is part of
  • Industry standards and codes of conduct
  • technolgy trends and impact on org
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Risk Assessment steps TLPCR

A
  • profile types of risk
  • assess level of risk
  • assess probability of occurrence
  • describe potential consequences
  • develop remediation plans and prioritize actions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk Profile

A
  • Risk Factors
  • Levels of Risk
  • Potential Consequences
  • Records Collections
  • acceptable Risk
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Developing IG Strategic Plan

A
  • Align Resources to Develop the plan
  • Analyze Internal and External Drivers
  • Develop Strategic Plan
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Developing IG Framework

A
  • Identify and evaluate applicable standards
  • Analyze policies and Procedures
  • Establish Enterprise IG policies and Standards
  • Develop Communication and Training
  • Develop Auditing and Enforcement Mechanisms
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Analyze policies and procedure

A

Think can my lawyer defend it.

  • Due diligence you followed to id potentally relevant standards, guidelines, req
  • critera you used to decide which fo the above organization should follow
  • Rationale for establishing the above criteria
  • Process you followed to obtain support from upper management
  • Communication process you followed to ensure that all relevant parties were able to participate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Establishing enterprise IG policies and standards

A

Based on the gap analysis begin developing policies and standards to be used

  • Key part developing internal req. for assigning authority levels, roles, and responsibilities for IG
  • Id training and knowldged needed
  • be familiar with how job descripitons are develop
  • Training should be specific to role
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Develop auditing and enforcement mechanisms

A

critera and metrics should be created and audits against those meterics. T
Auditing should be iterative building on itself
Audits are used to effect accountability
keep corporate culter in mind

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Establishing IG Program

A
  • Establish prog scope, Mandate, reporting
  • Assign Accountabilities
  • Implement the IG Program
  • Manage the IG program
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Establish program scope, mandate and reporting

A
  • must engage executive leaders to advocate for changes in org. policy and the allocation of resources
  • use appropriate methods of communication
  • use facts and data to substantial your statements about the program, industry or both
  • business case
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Generally Accepted Recordkeeping principles

AT IP CARD

A
  • accountability
  • Transparency
  • integrity
  • protection
  • compliance
  • availability
  • retention
  • disposition
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

BUsiness case for IG

A

*Id issues you seek to solve
*Description of ho IG is related to the issue and is part of the solution
*quanitifcation of the problem in terms of cost and risk to org
*description of solution
*estimate costs money time equip
ID potential funding sources and methods
*defined accountability for the new process or prog
*metrics by which you will judge success
ROI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Factors to modify IG program

A
  • changed or new laws and regulations
  • reorganization of the business
  • mergers, acquisitions, or divestitures
  • New LInes of business
  • Employees’ recommendations for improvements
  • employees’ resistance to change
  • new technology adoption
  • Change in competitive landscape
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Establishing IG governance integration and oversight

A
  • Define the current state (culture, systems, process, req)

* identifying benchmarks

17
Q

Algining Tech with IG framework

A
  • know how tech is used
  • evaluate Hardwar, software, and data life cycles
  • algign IG with IT strategy and operations
18
Q

Auditing stages 7

A
  • Gain stakeholder support and involvement in the audit process
  • establish meterics and will be used to audit for compliance with IG processes
    3. Determine frequency of audits and indiv ivolved
    4. conduct the audits according to the defined schedule
    5. Analyze audit results and determine required follow-up actions
    6. present audit findings and recommendations to stakeholders
    7. Update risk mitigation plans and modify policies and procedures to address needed improvments.