Governance Compliance Flashcards

(21 cards)

1
Q

What is the overall purpose of governance in IT?

A

Overall management of IT infrastructure, policies, procedures, and operations

Governance ensures alignment with organizational objectives and regulatory requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the four crucial aspects of governance?

A
  • Risk Management
  • Strategic Alignment
  • Resource Management
  • Performance Measurement

These aspects help in identifying risks, aligning IT with business goals, managing resources effectively, and measuring IT performance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does compliance refer to in the context of governance?

A

Adherence to laws, regulations, standards, and policies

Compliance is essential for legal obligations, trust, data protection, and business continuity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False: Non-compliance can lead to penalties such as fines and sanctions.

A

True

Non-compliance can also result in reputational damage and loss of licenses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the governance structures typically involved in organizations?

A
  • Boards
  • Committees
  • Government Entities
  • Centralized vs Decentralized Structures

These structures play a significant role in overseeing and influencing governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Fill in the blank: High-level guidelines indicating organizational commitments are known as _______.

A

[Policies]

Policies guide the organization’s approach to various issues, including acceptable use and information security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the two types of standards in governance?

A
  • Mandatory actions
  • Rules adhering to policies

Standards ensure compliance and provide a framework for security measures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the purpose of procedures in governance?

A

Step-by-step instructions ensure consistency and compliance

Procedures detail how to implement policies and standards effectively.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the consequences of non-compliance?

A
  • Fines
  • Sanctions
  • Reputational Damage
  • Loss of License
  • Contractual Impacts

These consequences highlight the importance of compliance in IT governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the primary role of compliance reporting?

A

Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements

Compliance reporting can be internal or external.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False: Internal compliance reporting is conducted by external auditors.

A

False

Internal compliance reporting is conducted by an internal audit team or compliance department.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is due diligence in the context of compliance?

A

Identifying compliance risks through thorough review

It is a proactive measure to ensure adherence to regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What do the terms ‘attestation’ and ‘acknowledgement’ refer to in compliance?

A
  • Attestation: Formal declaration of compliance
  • Acknowledgement: Recognition of compliance requirements

Both are essential for confirming adherence to governance standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the difference between centralized and decentralized governance structures?

A
  • Centralized: Decision-making authority at top management levels
  • Decentralized: Decision-making authority distributed throughout the organization

Each structure has its advantages and disadvantages regarding responsiveness and consistency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does an Acceptable Use Policy (AUP) outline?

A

Do’s and don’ts for users interacting with an organization’s IT systems

It aims to protect organizations from legal issues and security threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the focus of a Business Continuity Policy?

A

Ensures operations continue during and after disruptions

It includes strategies for various types of disruptions.

17
Q

Fill in the blank: The systematic approach to handling organizational changes is known as _______.

A

[Change Management]

Change management aims to implement changes smoothly with minimal disruption.

18
Q

What are the key stages in the Change Management process?

A
  • Identifying the need for change
  • Assessing impacts
  • Developing a plan
  • Implementation
  • Post-change review

These stages ensure effective management of changes within the organization.

19
Q

What is the role of automation in compliance?

A

Streamlines data collection, improves accuracy, and provides real-time monitoring

Automation enhances the efficiency of compliance processes.

20
Q

What are the regulatory considerations organizations must comply with?

A
  • Data Protection
  • Privacy
  • Environmental Standards
  • Labor Laws

Non-compliance with these regulations can lead to penalties and reputational damage.

21
Q

What does the term ‘geographical considerations’ refer to in governance?

A

Impact of regulations at local, regional, national, and global levels

Organizations must navigate various legal landscapes based on their operational areas.