Skip to the content.

Governance and Compliance

Governance

Governance refers to overall management of the organization’s IT infrastructure, policies, procedures, and operations.

Monitoring

Involves regularly reviewing and assessing the effectiveness of the governance framework.

Revision

Involves updating the governance framework to address these gaps or weaknesses.

Governance Structure

Boards

Committees

Government Entities

Centralized and Decentralized Structures

Governance Elements

Policies

Policies, influenced by laws and standards, provide strategic direction and priorities , guiding decision-making and compliance.

Key IT Policies:

For more information, please see Common Security Policies.

Standards

Organizations use standards as compliance documents and guidelines, which defines the specific technical requirements for security controls, including incident response procedures.

Procedures

Procedures typically contains the detailed steps to complete tasks supporting departmental or organizational policies.

Emergency Evacuation Procedure

Data Backup Procedure

Regulations and Laws

Regulations and associated fines and penalties can be imposed by governments at the national, regional, or local level. Note that regulations and laws can be imposed and enforced differently in different parts of the world:

Governance Considerations

Regulatory

Industry

Geographical

Compliance

Compliance refers to adherence to laws, regulations, standards, and policies that apply to the operations of the organizations.

Compliance Reporting

Systematic process of collecting and presenting data to demonstrate adherence to compliance requirements.

Types:

Compliance Monitoring

The process of regularly reviewing and assessing organizational practices to ensure compliance with laws, regulations, and internal policies.

Key components:

Automation in Compliance

Automated compliance systems can streamline data collection, improve accuracy, and provide real-time compliance monitoring.

Consequences of Non-Compliance


Back to main page