Governance Compliance Flashcards
(21 cards)
What is the overall purpose of governance in IT?
Overall management of IT infrastructure, policies, procedures, and operations
Governance ensures alignment with organizational objectives and regulatory requirements.
What are the four crucial aspects of governance?
- Risk Management
- Strategic Alignment
- Resource Management
- Performance Measurement
These aspects help in identifying risks, aligning IT with business goals, managing resources effectively, and measuring IT performance.
What does compliance refer to in the context of governance?
Adherence to laws, regulations, standards, and policies
Compliance is essential for legal obligations, trust, data protection, and business continuity.
True or False: Non-compliance can lead to penalties such as fines and sanctions.
True
Non-compliance can also result in reputational damage and loss of licenses.
What are the governance structures typically involved in organizations?
- Boards
- Committees
- Government Entities
- Centralized vs Decentralized Structures
These structures play a significant role in overseeing and influencing governance.
Fill in the blank: High-level guidelines indicating organizational commitments are known as _______.
[Policies]
Policies guide the organization’s approach to various issues, including acceptable use and information security.
What are the two types of standards in governance?
- Mandatory actions
- Rules adhering to policies
Standards ensure compliance and provide a framework for security measures.
What is the purpose of procedures in governance?
Step-by-step instructions ensure consistency and compliance
Procedures detail how to implement policies and standards effectively.
What are the consequences of non-compliance?
- Fines
- Sanctions
- Reputational Damage
- Loss of License
- Contractual Impacts
These consequences highlight the importance of compliance in IT governance.
What is the primary role of compliance reporting?
Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements
Compliance reporting can be internal or external.
True or False: Internal compliance reporting is conducted by external auditors.
False
Internal compliance reporting is conducted by an internal audit team or compliance department.
What is due diligence in the context of compliance?
Identifying compliance risks through thorough review
It is a proactive measure to ensure adherence to regulations.
What do the terms ‘attestation’ and ‘acknowledgement’ refer to in compliance?
- Attestation: Formal declaration of compliance
- Acknowledgement: Recognition of compliance requirements
Both are essential for confirming adherence to governance standards.
What is the difference between centralized and decentralized governance structures?
- Centralized: Decision-making authority at top management levels
- Decentralized: Decision-making authority distributed throughout the organization
Each structure has its advantages and disadvantages regarding responsiveness and consistency.
What does an Acceptable Use Policy (AUP) outline?
Do’s and don’ts for users interacting with an organization’s IT systems
It aims to protect organizations from legal issues and security threats.
What is the focus of a Business Continuity Policy?
Ensures operations continue during and after disruptions
It includes strategies for various types of disruptions.
Fill in the blank: The systematic approach to handling organizational changes is known as _______.
[Change Management]
Change management aims to implement changes smoothly with minimal disruption.
What are the key stages in the Change Management process?
- Identifying the need for change
- Assessing impacts
- Developing a plan
- Implementation
- Post-change review
These stages ensure effective management of changes within the organization.
What is the role of automation in compliance?
Streamlines data collection, improves accuracy, and provides real-time monitoring
Automation enhances the efficiency of compliance processes.
What are the regulatory considerations organizations must comply with?
- Data Protection
- Privacy
- Environmental Standards
- Labor Laws
Non-compliance with these regulations can lead to penalties and reputational damage.
What does the term ‘geographical considerations’ refer to in governance?
Impact of regulations at local, regional, national, and global levels
Organizations must navigate various legal landscapes based on their operational areas.