Governance and Compliance Flashcards
Governance
leadership, structures, and processes that IT has for buisness objectives
Boards
a group of individuals elected by shareholders to oversee the management of an organization
Committees
a subgroup of a board of directors w/ a specific focus
Government Entities role in your buisness
ensure laws and regulations are complied with
Centralized Structures
decision-making authority is concentrated at the top levels
Decentralized Structures
distributes decision-making authority throughout the org
Acceptable Use Policy
document that outlines the do’s and donts for user’s within that org
Information Security Policies
outlines how an organization protects its infromation assets from threats
Buisness Continuity
focuses how an organization will continue its operations before/after disruption
Disaster Recovery
focuses specifically on how the org will reocver its IT systems and data
Incident Response
plan for handling security incidents
Software Development Lifecyle
how software is developed
Purpose of Change Management
ensure changes are implemented in a controlled and cordinated manner
Pupose of Standards
to give a framework of security measures that covers all aspects
Policy Standards Types (P Ac Ps E)
Password, Access Controls, Physical Security, and Encryption
Procedures
sequence of actions take to get an outcome;Uses Change Management
Onboarding
process of integrating new employees into the org
Playbooks
checklist of actions to perfrom, detect, and respond to a specific incident
Regulatory Considerations
can cover a wde range of areas from data protection and privacy to environmental standards and labor laws
Legal Considerations
similar to Regualatory Considerations but incldes areas like contract law, intellectual property
Industry Considerations
the specific standards and pratices pervelant in an industry
Global Consideration Level Order (National global local regional)
are under the local → regional → national → global regulations
Compliance Reporting
systematic process of collecting and presenting data to demostrate adherance
Internal Complicance Reporting
collection/analysis of data to ensure the org is fufilling internal policies and procedures