Section 11.102 Compliance Flashcards
Objectives 5.1 Summarise elements of effective security governance. Objectives 5.4 Summarise elements of effective security compliance
Compliance
Ensures adherence to laws, regulations, guidelines, and specifications
■ Includes compliance reporting and compliance monitoring
Compliance Reporting
Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements
■ Two Types of Compliance Reporting: Internal & External
Internal Compliance Reporting
Ensures adherence to internal policies and procedures
○ Conducted by an internal audit team or compliance department
External Compliance Reporting
Demonstrates compliance to external entities
○ Mandatory, often by law or contract
Compliance Monitoring
Regularly reviews and analyses operations for compliance
■ Includes due diligence and due care, attestation and acknowledgement, and internal and external monitoring
Due Diligence and Due Care
Due Diligence: Identifying compliance risks through thorough review
Due Care: Steps taken to mitigiate identified risks
Attestation
Formal declaration by a responsible party that the organisation’s processes and controls are compliant
Acknowledgement
Recognition and acceptance of compliance requirements by all relevant parties
Internal Monitoring
Regularly reviewing an organisation’s operations to ensure compliance with internal policies
External Monitoring
Third-party reviews for compliance with external regulations or standards
Role of Automation in Compliance
Automated compliance systems can streamline data collection, improves accuracy, and provides real-time
monitoring