Section 11.102 Compliance Flashcards

Objectives 5.1 Summarise elements of effective security governance. Objectives 5.4 Summarise elements of effective security compliance

1
Q

Compliance

A

Ensures adherence to laws, regulations, guidelines, and specifications

■ Includes compliance reporting and compliance monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Compliance Reporting

A

Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements

■ Two Types of Compliance Reporting: Internal & External

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Internal Compliance Reporting

A

Ensures adherence to internal policies and procedures

○ Conducted by an internal audit team or compliance department

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

External Compliance Reporting

A

Demonstrates compliance to external entities

○ Mandatory, often by law or contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compliance Monitoring

A

Regularly reviews and analyses operations for compliance

■ Includes due diligence and due care, attestation and acknowledgement, and internal and external monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Due Diligence and Due Care

A

Due Diligence: Identifying compliance risks through thorough review

Due Care: Steps taken to mitigiate identified risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Attestation

A

Formal declaration by a responsible party that the organisation’s processes and controls are compliant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Acknowledgement

A

Recognition and acceptance of compliance requirements by all relevant parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Internal Monitoring

A

Regularly reviewing an organisation’s operations to ensure compliance with internal policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

External Monitoring

A

Third-party reviews for compliance with external regulations or standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Role of Automation in Compliance

A

Automated compliance systems can streamline data collection, improves accuracy, and provides real-time
monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly