Governance and compliance
Governance
Part of the GRC triad (Governance, Risk, Compliance): the strategic framework aligning IT with business objectives through risk management, resource allocation, and performance measurement. It must adapt to tech, regulatory, and cultural change.
The structures: boards set strategic direction, committees are focused subgroups, and government entities set laws and regulations. Centralized decision-making is consistent but slow; decentralized is fast but potentially inconsistent.
The document hierarchy
- Policies: high-level commitments. AUP, information security, business continuity, disaster recovery, incident response, SDLC, change management.
- Standards: mandatory specifics. Password, access control, physical security, encryption.
- Procedures: step-by-step. Change management, onboarding and offboarding, playbooks.
The AUP defines the do’s and don’ts for using IT resources. Access control standards name the models (DAC, MAC, RBAC) and enforce least privilege and separation of duties.
Considerations
Regulatory (data protection, privacy, environmental, labor), legal (contract, IP, employment, litigation), industry (not legally binding but it shapes expectations), and geographical (city ordinances up through CCPA at state level, ADA nationally, GDPR extraterritorially).
Conflict of laws between jurisdictions is the hard part.
Compliance
Reporting is internal (to your own policies, by an internal audit team) and external (to regulators, often mandatory).
The monitoring concepts: due diligence (identify compliance risks) vs due care (mitigate them); attestation (a formal declaration that controls are compliant) vs acknowledgement (all parties accept the requirements); internal vs external monitoring. Automation takes most of the manual work out of it.
The cost of non-compliance: fines, sanctions, reputational damage, loss of license, contractual breach.