Governance and Compliance Flashcards

1
Q

Governance

A

leadership, structures, and processes that IT has for buisness objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Boards

A

a group of individuals elected by shareholders to oversee the management of an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Committees

A

a subgroup of a board of directors w/ a specific focus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Government Entities role in your buisness

A

ensure laws and regulations are complied with

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Centralized Structures

A

decision-making authority is concentrated at the top levels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Decentralized Structures

A

distributes decision-making authority throughout the org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Acceptable Use Policy

A

document that outlines the do’s and donts for user’s within that org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Information Security Policies

A

outlines how an organization protects its infromation assets from threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Buisness Continuity

A

focuses how an organization will continue its operations before/after disruption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Disaster Recovery

A

focuses specifically on how the org will reocver its IT systems and data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Incident Response

A

plan for handling security incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Software Development Lifecyle

A

how software is developed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Purpose of Change Management

A

ensure changes are implemented in a controlled and cordinated manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Pupose of Standards

A

to give a framework of security measures that covers all aspects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Policy Standards Types (P Ac Ps E)

A

Password, Access Controls, Physical Security, and Encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Procedures

A

sequence of actions take to get an outcome;Uses Change Management

17
Q

Onboarding

A

process of integrating new employees into the org

18
Q

Playbooks

A

checklist of actions to perfrom, detect, and respond to a specific incident

19
Q

Regulatory Considerations

A

can cover a wde range of areas from data protection and privacy to environmental standards and labor laws

20
Q

Legal Considerations

A

similar to Regualatory Considerations but incldes areas like contract law, intellectual property

21
Q

Industry Considerations

A

the specific standards and pratices pervelant in an industry

22
Q

Global Consideration Level Order (National global local regional)

A

are under the local → regional → national → global regulations

23
Q

Compliance Reporting

A

systematic process of collecting and presenting data to demostrate adherance

24
Q

Internal Complicance Reporting

A

collection/analysis of data to ensure the org is fufilling internal policies and procedures

25
External Compliance Reporting
demostrating compliance to external entities such as regulatory bides, auditions often mandated by law
26
Compliance Monitorying
reguarly reviewing and analyzing an org’s operations
27
Due Diligence
the act of monitoring
28
Due Care
the steps take while monitoring
29
Attestation
formal decleartion from a responsible party that they are compliant
30
Acknowledgement
recognition and acceptance of compliance requirements by all parties
31
Concequences of Non-Compliance (S F LoL CI)
Fines, Sanctions, Loss of Licence, and Contractual Impacts
32
Sanctions
strict measures taken by regulatory bodies to enforce compliance
33
Contractual Impacts
the consequences/effects that arrise as a result of a contract of two parties