Governance Flashcards

(36 cards)

1
Q

Governance

A
  • Strategic leadership, structures, and processes that ensure an organization’s IT infrastructure aligns with its business objectives
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Compliance

A
  • Adherence to laws, regulations, standards, and policies that apply to the operation of the organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the aspects that make up a governance framework?

A
  • Rules, Responsibilities and Practices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Governance Monitoring

A
  • Regularly reviewing and assessing the effectiveness of the governance framework
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Governance Revisions

A
  • Updating the governance framework to address any gaps or weaknesses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Board of Directors

A
  • A group of individuals elected by shareholder to oversee the management of an organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Committees

A
  • Subgroups of a board of directors, each with a specific focus
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Government Entities

A
  • They establish laws and regulations that organizations must comply with

EXAMPLES: Federal Trade Commissions makes laws against unfair trade practices you must adhere to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Centralized Structures

A
  • Decision-making authority is concentrated at the top levels of management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DeCentralized Structures

A
  • Distributes decision making authority throughout the organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Acceptable Use Policy (AUP)

A
  • A document outlining the do’s and don’ts for users when interacting with an organization’s IT systems and resources

EXAMPLE: Might prohibit users from visiting unwanted websites, or downloading files they shouldn’t

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Information Security Policies

A
  • Outlines how an organization protects its information assets from threats, both internal and external

*** This covers a range of areas including Data Classification, Access Control, Encryption, and Physical Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Business Continuity

A
  • Focuses on how an organization will continue its critical operations during and after a disruption
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Disaster Recovery

A
  • Focuses specifically on how an organization will recover its IT systems and data after a disaster
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Incident Response

A
  • A plan for handling security incidents

EXAMPLE: States the who/what/when/where of disaster actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Change Management

A
  • Aims to ensure that changes are implemented in a controlled and coordinated manner, minimizing the risk for disruption
17
Q

Standards

A
  • Provide a framework for implementing security measures, ensuring that all aspects of an organization’s security posture are addressed
18
Q

Password Standards

A
  • Dictate the complexity and management of passwords, which are the first line of defense against unauthorized access

*** Minimum length of characters, upper/lower case, numbers, and special characters

19
Q

Access Control Standards

A
  • Determines who has access to what resources within an organization

*** This includes…
Discretionary Access Control (DAC) - resource owner decides who gets access

Mandatory Access Control (MAC) - system enforces access based on security clearances and data classifications

Role-Based Access Control (RBAC) - access is tied to job functions/roles rather than individual users

20
Q

Physical Security Standards

A
  • Standards that cover the physical measures taken to protect an organization’s assets and information
21
Q

Encryption Standards

A
  • Ensures that data intercepted or accessed without authorization remains unreadable and secure
22
Q

Procedures

A
  • Systematic sequences of actions or steps taken to achieve a specific outcome

EXAMPLE: Data back-up procedure, Emergency Evacuation Procedure

23
Q

Onboarding/Off-boarding Procedures

A
  • Process of either integrating new employees or managing their transition when leaving
24
Q

Playbooks

A
  • Checklist of actions to perform to detect and respond to a specific type of incident
25
What are some of the main Governance considerations?
- Regulatory - Legal - Industry - Geographical
26
Regulatory Considerations
- These regulations can cover a wide range of areas, from data protection and privacy to environmental standards and labor laws EXAMPLE: GDPR (General Data Protection Regulation) in Europe
27
Legal Considerations
- Closely tied to regulatory considerations, but they also encompass other areas such as contract law, intellectual property, and corporate law EXAMPLE: Employment laws like minimum wage, overtime and anti-discrimination
28
Industry Considerations
- The specific standards and practices that are prevalent in a particular industry EXAMPLE: Use of Agile methodology in software development
29
Geographical Considerations
- Local, regional, national, and global regulations can all impact an organization's operations
30
Compliance Reporting
- Systematic process of collecting and presenting data to demonstrate adherence to compliant requirements - Includes internal and external
31
Compliance Monitoring
- The process of regularly reviewing and analyzing an organization's operations to ensure compliance with laws, regulations, and internal policies
32
Due Diligence in Compliance Monitoring
- Conducting an exhaustive review of an organization's operations to identify potential compliance risks
33
Due Care in Compliance Monitoring
- The steps taken to mitigate risks
34
Attestation
- Formal declaration by a responsible party that the organization's processes and controls are compliant
35
Acknowledgement
- Recognition and acceptance of compliance requirements by all relevant parties
36
What are some of the consequences of non-compliance?
- Fines - Sanctions - Reputational Damage - Loss of License - Contractual impacts - Breach of contract