Governance and compliance

Governance

Part of the GRC triad (Governance, Risk, Compliance): the strategic framework aligning IT with business objectives through risk management, resource allocation, and performance measurement. It must adapt to tech, regulatory, and cultural change.

The structures: boards set strategic direction, committees are focused subgroups, and government entities set laws and regulations. Centralized decision-making is consistent but slow; decentralized is fast but potentially inconsistent.

The document hierarchy

The AUP defines the do’s and don’ts for using IT resources. Access control standards name the models (DAC, MAC, RBAC) and enforce least privilege and separation of duties.

Considerations

Regulatory (data protection, privacy, environmental, labor), legal (contract, IP, employment, litigation), industry (not legally binding but it shapes expectations), and geographical (city ordinances up through CCPA at state level, ADA nationally, GDPR extraterritorially).

Conflict of laws between jurisdictions is the hard part.

Compliance

Reporting is internal (to your own policies, by an internal audit team) and external (to regulators, often mandatory).

The monitoring concepts: due diligence (identify compliance risks) vs due care (mitigate them); attestation (a formal declaration that controls are compliant) vs acknowledgement (all parties accept the requirements); internal vs external monitoring. Automation takes most of the manual work out of it.

The cost of non-compliance: fines, sanctions, reputational damage, loss of license, contractual breach.