Chapter 1 mod 4 Flashcards

1
Q

What is the primary purpose of any business or organization, according to the text?

A

The primary purpose of any business or organization, according to the text, is to fulfill a specific purpose, whether it’s providing raw materials, manufacturing equipment, developing software, constructing buildings, or offering goods and services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What guides leaders and management when implementing systems and structures within an organization?

A

Leaders and management are guided by laws and regulations created by governments to enact public policy when implementing systems and structures within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do laws and regulations influence the development of standards within an organization?

A

Laws and regulations influence the development of standards within an organization, cultivating policies that, in turn, result in procedures to guide the organization in achieving its goals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are procedures in the context of organizational governance?

A

Procedures, in the context of organizational governance, are detailed steps to complete a task that support departmental or organizational policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What role do policies play in organizational governance?

A

Policies, put in place by organizational governance, provide guidance in all activities to ensure that the organization supports industry standards and regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do standards contribute to the implementation of policies and procedures within an organization?

A

Standards are often used by governance teams to provide a framework for introducing policies and procedures in support of regulations within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What distinguishes regulations from other elements in the text?

A

Regulations, commonly issued in the form of laws, typically come from the government and carry financial penalties for noncompliance, distinguishing them from other elements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How are procedures related to departmental or organizational policies?

A

Procedures are related to departmental or organizational policies as they provide detailed steps to complete tasks in alignment with these policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the source of regulations, and what distinguishes them from governance?

A

Regulations, issued in the form of laws, come from the government and carry financial penalties for noncompliance, distinguishing them from governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who is responsible for putting policies in place within organizational governance?

A

Policies are put in place by organizational governance, such as executive management, to provide guidance in all activities and ensure alignment with industry standards and regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

At what levels can regulations and associated fines and penalties be imposed by governments?

A

Regulations and associated fines and penalties can be imposed by governments at the national, regional, or local level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the focus of the Health Insurance Portability and Accountability Act (HIPAA) of 1996?

A

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 governs the use of protected health information (PHI) in the United States.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What consequences can individuals and companies face for violating the HIPAA rule?

A

Violation of the HIPAA rule can result in fines and/or imprisonment for both individuals and companies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the purpose of the General Data Protection Regulation (GDPR) enacted by the European Union (EU)?

A

The General Data Protection Regulation (GDPR) was enacted by the European Union (EU) to control the use of Personally Identifiable Information (PII) of its citizens and those in the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What makes the GDPR unique in terms of its international reach?

A

The GDPR has international reach as it includes provisions that apply financial penalties to companies handling data of EU citizens and those living in the EU, even if the company does not have a physical presence in the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In what ways can multinational organizations be subject to regulations?

A

Multinational organizations can be subject to regulations in more than one nation, in addition to multiple regions and municipalities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What recommendation does the text provide for organizations regarding compliance with regulations?

A

Organizations need to consider the regulations that apply to their business at all levels—national, regional, and local—and ensure they are compliant with the most restrictive regulation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How does the international reach of the GDPR impact companies handling data?

A

The international reach of the GDPR impacts companies handling data of EU citizens and those in the EU, regardless of the company’s physical presence in the EU, by subjecting them to financial penalties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What specific type of information does HIPAA govern?

A

HIPAA governs the use of protected health information (PHI) in the United States.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Why is it important for organizations to consider regulations at multiple levels, according to the text?

A

Organizations need to consider regulations at multiple levels (national, regional, and local) to ensure compliance with the most restrictive regulation and avoid legal consequences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

How do organizations commonly use standards in the context of information systems security programs?

A

Organizations use standards both as compliance documents and as advisories or guidelines in their information systems security programs.

22
Q

What assurance can standards provide for organizations in terms of their policies and procedures?

A

Standards can provide assurance that an organization is operating with policies and procedures that support regulations and are widely accepted best practices.

23
Q

Which organization develops and publishes international standards on technical subjects, including information systems and information security?

A

The International Organization for Standardization (ISO) develops and publishes international standards on technical subjects, including information systems and information security.

24
Q

How does ISO gather input for the development of its standards?

A

ISO solicits input from the international community of experts to provide input on its standards prior to publishing.

25
Q

Where can documents outlining ISO standards be obtained?

A

Documents outlining ISO standards can be purchased online.

26
Q

Which U.S. government agency, under the Department of Commerce, publishes information technology and information security standards?

A

The National Institute of Standards and Technology (NIST) publishes information technology and information security standards.

27
Q

What is the significance of NIST standards in the context of industries worldwide?

A

NIST standards are considered recommended standards by industries worldwide and are requirements for U.S. government agencies.

28
Q

How does NIST gather input for its standards?

A

NIST standards solicit and integrate input from industry, and the standards are free to download from the NIST website.

29
Q

How do computers communicate globally, and what ensures their ability to connect with each other?

A

Computers communicate globally through standards in communication protocols, ensuring their ability to connect with each other, thanks to the Internet Engineering Task Force (IETF).

30
Q

What disciplines do the Institute of Electrical and Electronics Engineers (IEEE) set standards for?

A

The Institute of Electrical and Electronics Engineers (IEEE) sets standards for telecommunications, computer engineering, and similar disciplines.

31
Q

What informs organizational policies, and what do they specify?

A

Organizational policies are informed by applicable law(s) and specify which standards and guidelines the organization will follow.

32
Q

How would you describe the breadth and detail of policies?

A

Policies are broad but not detailed; they establish context, set out strategic direction and priorities, and are not overly detailed.

33
Q

What role do governance policies play in decision-making and compliance?

A

Governance policies are used to moderate and control decision-making, ensure compliance when necessary, and guide the creation and implementation of other policies.

34
Q

Who typically uses high-level governance policies, and for what purpose?

A

High-level governance policies are typically used by senior executives to shape and control decision-making processes.

35
Q

How do high-level policies impact the behavior and activity of the entire organization?

A

High-level policies direct the behavior and activity of the entire organization as it moves toward specific or general goals and objectives.

36
Q

What are some examples of functional areas that usually have their own sets of policies?

A

Functional areas such as human resources management, finance and accounting, and security and asset protection usually have their own sets of policies.

37
Q

When might the need for compliance necessitate the development of specific high-level policies?

A

The need for compliance, whether imposed by laws and regulations or contracts, might necessitate the development of specific high-level policies.

38
Q

How are policies carried out or implemented within an organization?

A

Policies are implemented by people, and for that, someone must expand the policies from statements of intent and direction into step-by-step instructions or procedures.

39
Q

What is the purpose of someone expanding policies into step-by-step instructions or procedures?

A

Expanding policies into step-by-step instructions or procedures is necessary to carry out or implement the policies within an organization.

40
Q

In terms of governance, what role do policies play in decision-making and compliance?

A

Governance policies play a crucial role in moderating and controlling decision-making, ensuring compliance when necessary, and guiding the overall creation and implementation of other policies within an organization.

41
Q

What do procedures define in an organizational context?

A

Procedures define the explicit, repeatable activities necessary to accomplish a specific task or set of tasks within an organizational context.

42
Q

What type of knowledge do procedures provide to support task performance?

A

Procedures provide supporting data, decision criteria, or other explicit knowledge needed to perform each task.

43
Q

What types of actions can procedures address?

A

Procedures can address both one-time or infrequent actions and common, regular occurrences.

44
Q

Besides detailing specific activities, what do procedures establish in relation to task completion?

A

Procedures establish the measurement criteria and methods to determine whether a task has been successfully completed.

45
Q

Why is it important to properly document procedures within an organization?

A

Properly documenting procedures is important for deriving the maximum organizational benefits from procedures.

46
Q

How can procedures benefit organizational activities?

A

Procedures benefit organizational activities by providing explicit guidance for task execution, ensuring consistency and repeatability.

47
Q

What role does training play in optimizing organizational benefits from procedures?

A

Training personnel on how to locate and follow procedures is necessary to optimize organizational benefits from procedures.

48
Q

In terms of frequency, what types of actions can procedures address?

A

Procedures can address both one-time or infrequent actions and common, regular occurrences.

49
Q

Besides supporting data, what other knowledge aspects can procedures provide?

A

Besides supporting data, procedures can provide decision criteria and other explicit knowledge needed to perform tasks.

50
Q

What aspect of task completion do procedures specify?

A

Procedures specify the measurement criteria and methods used to determine whether a task has been successfully completed.

51
Q
A