Section 11.95 Governance and Compliance Flashcards
Objectives 5.1 Summarise elements of effective security governance. Objectives 5.4 Summarise elements of effective security compliance
Governance
Overall management of IT infrastructure, policies, procedures, and operations
Establishment of a strategic Framework that alligns with organisational objectives and regulatory requirements
Governance Crucial Apects
Risk Management
Identify, assess, and manage potential risks
Governance Crucial Apects
Strategic Alignment
Ensure IT strategy aligns with business objectives
Governance Crucial Apects
Resource Management
Efficient and effective use of IT resources
Governance Crucial Apects
Performance Measurement
Mechanisms for measuring and monitoring the performance of IT processes
Compliance
Adherence to laws, regulations, standards, and policies
Compliance Importance
Legal Obligations
Non-compliance leads to penalties (fines, sanctions)
Compliance Importance
Trust and Reputation
Compliance enhances reputation and fosters trust
Compliance Importance
Data Protection
Prevents breaches and protects privacy
Compliance Importance
Business Continuity
Ensures operation in disasters or disruptions