Module 3 Governance, Risk and Compliance Flashcards
(111 cards)
Two Governance Components
- Separation of Duties
2. Policy Definition
GRC
Governance
Risk
Compliance
3 Characteristics of GRC
- Integrated and holistic
- Organization structures
- Process oriented
Two Risk Management Components
- Change Management
2. Configuration Management
Two Compliance Components
- Adherence to Regulations
2. Industry Aligned
Integrated approach to organization-wide governance, risk management, and compliance.
GRC
Helps ensure that an organization acts ethically correct and in accordance with its risk appetite, internal policies and external regulations.
GRC
Integrated, holistic, and organization-wide
GRC
Managed and supported through GRC
Operations
Defines the guidelines and performance goals of an organization.
Governance
Must include measurements of success to determine if the operation is performing to the company’s standard and, if not, what type of remediation is required.
Governance
Four Consequences of Bad / Failed / No GRC
- Risk of fines for failed audits.
- Compliance concerns stall virtualization and Cloud.
- Audits - time consuming and costly.
- Concerns of identifying risk and proper valuation.
Examples of external events that drive a company to have a GRC program
- A breach where information is lost and has to be reported due to regulations.
- A new Federal regulation
Companies usually accept the risk of exposure until what?
Until they have an actual breach
Why GRC is important
- Breach
- Regulation
- Other?
Is security GRC?
No. Security is not GRC.
- Related to information processing systems.
2. Mechanisms and techniques that control who may use or modify the computer or the information stored in it.
Security
Three key security tenets
- Confidentiality
- Integrity
- Availability
CIA
CIA
Confidentiality
Integrity
Availability
Purpose of IT security
To mitigate risks
IT risks are coupled with what?
Business risks
A framework for decision making, accountability, and measuring success.
Governance
Data protection and regulatory laws require what?
Security controls
How does Compliance relate to Security?
- Data protection and regulatory laws require security controls.
- Access to information and enforcement.