1
00:00:00,180 --> 00:00:02,100
In this lesson we're going to talk about

2
00:00:02,100 --> 00:00:03,750
governance and compliance.

3
00:00:03,750 --> 00:00:05,910
Now, governance refers to the overall management

4
00:00:05,910 --> 00:00:08,070
of the organization's IT infrastructure,

5
00:00:08,070 --> 00:00:10,440
policies, procedures, and operations.

6
00:00:10,440 --> 00:00:11,670
This involves the establishment

7
00:00:11,670 --> 00:00:13,650
of a strategic framework that aligns with

8
00:00:13,650 --> 00:00:16,740
the organization's objectives and regulatory requirements.

9
00:00:16,740 --> 00:00:19,170
This framework includes the rules, responsibilities

10
00:00:19,170 --> 00:00:21,360
and practices that are going to guide an organization

11
00:00:21,360 --> 00:00:23,040
in achieving its goals and managing

12
00:00:23,040 --> 00:00:25,110
its overall IT resources.

13
00:00:25,110 --> 00:00:27,270
Now, governance is crucial for several reasons,

14
00:00:27,270 --> 00:00:29,610
including risk management strategic alignments,

15
00:00:29,610 --> 00:00:31,650
resource management and performance measurement,

16
00:00:31,650 --> 00:00:32,940
and many others.

17
00:00:32,940 --> 00:00:34,890
In terms of risk management, governance helps us

18
00:00:34,890 --> 00:00:37,440
to identify, assess and manage potential risks

19
00:00:37,440 --> 00:00:39,750
that could impact our organization's security.

20
00:00:39,750 --> 00:00:41,370
Strategic alignment, on the other hand,

21
00:00:41,370 --> 00:00:43,140
is a fancy way of saying that we want to ensure

22
00:00:43,140 --> 00:00:45,270
the organization's IT strategy aligns

23
00:00:45,270 --> 00:00:47,310
with its overall business objectives.

24
00:00:47,310 --> 00:00:48,930
Resource management, on the other hand,

25
00:00:48,930 --> 00:00:50,550
is going to be supported by governance

26
00:00:50,550 --> 00:00:52,781
by making sure we have an efficient

27
00:00:52,781 --> 00:00:53,970
and effective use of our resources.

28
00:00:53,970 --> 00:00:56,130
And performance measurement is going to be focused on

29
00:00:56,130 --> 00:00:58,560
making sure we have mechanisms in place for monitoring

30
00:00:58,560 --> 00:01:01,470
and measuring the performance of our IT processes.

31
00:01:01,470 --> 00:01:03,990
After that, we're going to start talking about compliance.

32
00:01:03,990 --> 00:01:05,400
Now, compliance on the other hand,

33
00:01:05,400 --> 00:01:07,200
is going to refer to the adherence to laws,

34
00:01:07,200 --> 00:01:09,330
regulations, standards and policies

35
00:01:09,330 --> 00:01:11,820
that apply to an organization's operations.

36
00:01:11,820 --> 00:01:13,950
In the IT world, compliance means ensuring

37
00:01:13,950 --> 00:01:16,500
that the organization's IT systems and processes

38
00:01:16,500 --> 00:01:19,440
meet the required security standards and regulations.

39
00:01:19,440 --> 00:01:21,450
Compliance is important for many reasons,

40
00:01:21,450 --> 00:01:24,360
including legal obligations, trust and reputation,

41
00:01:24,360 --> 00:01:26,880
data protection, and business continuity.

42
00:01:26,880 --> 00:01:28,680
Now, in terms of legal obligations

43
00:01:28,680 --> 00:01:31,500
if you have non-compliance this can lead to legal penalties,

44
00:01:31,500 --> 00:01:34,290
including fines and sanctions against your company.

45
00:01:34,290 --> 00:01:35,970
In terms of trust and reputation,

46
00:01:35,970 --> 00:01:37,290
we need to make sure we have compliance

47
00:01:37,290 --> 00:01:39,000
with our industry standards and regulations

48
00:01:39,000 --> 00:01:41,100
to enhance our organization's reputation

49
00:01:41,100 --> 00:01:44,490
and foster trust among our customers and our partners.

50
00:01:44,490 --> 00:01:46,140
When it comes to data protection,

51
00:01:47,037 --> 00:01:49,037
compliance is going to help us by making sure

52
00:01:49,037 --> 00:01:50,070
that we're going through the data protection regulations

53
00:01:50,070 --> 00:01:53,280
properly to prevent data breaches and protect our privacy

54
00:01:53,280 --> 00:01:55,620
of our customers and employees' data.

55
00:01:55,620 --> 00:01:57,330
Now, in terms of business continuity,

56
00:01:57,330 --> 00:01:59,820
our compliance with standards related to disaster recovery

57
00:01:59,820 --> 00:02:01,800
and business continuity can really help to ensure

58
00:02:01,800 --> 00:02:03,930
that our organization can continue to operate

59
00:02:03,930 --> 00:02:07,260
in the event of a disaster or disruption to our services.

60
00:02:07,260 --> 00:02:08,910
So in this section of the course,

61
00:02:08,910 --> 00:02:11,070
we're going to be focused solely on domain five,

62
00:02:11,070 --> 00:02:13,980
and specifically we'll be looking at objective 5.1

63
00:02:13,980 --> 00:02:15,900
and objective 5.4.

64
00:02:15,900 --> 00:02:18,300
Now, objective 5.1 states that you must be able

65
00:02:18,300 --> 00:02:21,060
to summarize elements of effective security governance

66
00:02:21,060 --> 00:02:23,490
and objective 5.4 states that you must be able to

67
00:02:23,490 --> 00:02:26,520
summarize elements of effective security compliance.

68
00:02:26,520 --> 00:02:28,770
Now, first, we're going to cover governance

69
00:02:28,770 --> 00:02:30,690
and we're going to go over much more detailed definition

70
00:02:30,690 --> 00:02:33,360
of governance as part of governance, risk and compliance

71
00:02:33,360 --> 00:02:35,310
and how these three will affect guidelines,

72
00:02:35,310 --> 00:02:37,590
policies, standards, and procedures.

73
00:02:37,590 --> 00:02:40,259
We'll also go over the need for monitoring

74
00:02:40,259 --> 00:02:42,090
and revision of your governance as technology,

75
00:02:42,090 --> 00:02:45,180
regulatory and cultural changes occur within your industry.

76
00:02:45,180 --> 00:02:46,830
Then we'll jump into a discussion

77
00:02:46,830 --> 00:02:48,780
on the different governance structures,

78
00:02:49,640 --> 00:02:51,150
including boards, committees government entities,

79
00:02:51,150 --> 00:02:53,670
and centralized versus decentralized structures.

80
00:02:53,670 --> 00:02:55,560
We'll also explain each of these in detail

81
00:02:55,560 --> 00:02:56,940
and how they work and fit into

82
00:02:56,940 --> 00:02:58,800
your overall organization.

83
00:02:58,800 --> 00:03:01,170
After that, we'll talk about policies.

84
00:03:01,170 --> 00:03:03,180
Now, policies are high level guidelines

85
00:03:03,180 --> 00:03:04,830
that outline the organization's commitments

86
00:03:04,830 --> 00:03:06,930
and intentions towards certain actions,

87
00:03:06,930 --> 00:03:09,420
such as data protection or ethical conduct.

88
00:03:09,420 --> 00:03:11,790
We're going to be discussing lots of topics in this lesson,

89
00:03:11,790 --> 00:03:13,530
including acceptable use policies,

90
00:03:13,530 --> 00:03:16,560
information security policies, business continuity policies,

91
00:03:16,560 --> 00:03:19,500
disaster recovery policies, incident response policies,

92
00:03:19,500 --> 00:03:21,780
change management policies and the overall

93
00:03:21,780 --> 00:03:25,140
software development lifecycle known as the SDLC.

94
00:03:25,140 --> 00:03:27,420
Then we're going to focus on standards.

95
00:03:27,420 --> 00:03:30,150
Standards are specific mandatory actions or rules

96
00:03:30,150 --> 00:03:32,250
that must be followed to adhere to a policy

97
00:03:32,250 --> 00:03:33,900
and these are often defined by an industry

98
00:03:33,900 --> 00:03:35,370
or regulatory body.

99
00:03:35,370 --> 00:03:36,450
We're also going to be covering things

100
00:03:36,450 --> 00:03:39,060
like password standards, access control standards,

101
00:03:39,060 --> 00:03:41,820
physical security standards, and encryption standards.

102
00:03:41,820 --> 00:03:44,550
Following that, we'll start talking about procedures.

103
00:03:44,550 --> 00:03:46,650
Now, procedures are step-by-step instructions

104
00:03:46,650 --> 00:03:48,060
on how to perform specific tasks

105
00:03:48,060 --> 00:03:49,860
or activities to ensure consistency

106
00:03:49,860 --> 00:03:52,920
and compliance with both policies and standards.

107
00:03:52,920 --> 00:03:55,080
We're going to be going over change management procedures,

108
00:03:55,080 --> 00:03:56,550
onboarding and off-boarding procedures

109
00:03:56,550 --> 00:03:58,140
and the use of playbooks.

110
00:03:58,140 --> 00:04:00,630
Then we'll take a look at governance considerations,

111
00:04:00,630 --> 00:04:03,480
including regulatory considerations, legal considerations,

112
00:04:03,480 --> 00:04:06,420
industry considerations, local and regional considerations,

113
00:04:06,420 --> 00:04:08,820
national considerations, global considerations,

114
00:04:08,820 --> 00:04:10,770
and we'll also look at some of your legal issues

115
00:04:10,770 --> 00:04:13,140
that your organization could face if you went astray

116
00:04:13,140 --> 00:04:15,330
of any of these governance considerations.

117
00:04:15,330 --> 00:04:17,310
After that, we'll dive into compliance

118
00:04:17,310 --> 00:04:19,800
and we'll be discussing compliance, monitoring and reporting

119
00:04:19,800 --> 00:04:22,019
as we explain the different concepts like due diligence

120
00:04:22,019 --> 00:04:24,690
and due care, attestation and acknowledgement,

121
00:04:24,690 --> 00:04:26,280
internal and external compliance,

122
00:04:26,280 --> 00:04:29,220
and the use of automation in your compliance processes.

123
00:04:29,220 --> 00:04:31,680
Then we'll cover the consequences of non-compliance,

124
00:04:31,680 --> 00:04:34,680
including fines, sanctions, reputational damage,

125
00:04:34,680 --> 00:04:37,560
the loss of your license, and contractual impacts.

126
00:04:37,560 --> 00:04:39,300
Finally, we're going to take a short quiz

127
00:04:39,300 --> 00:04:41,190
to see what you learned during this section of the course

128
00:04:41,190 --> 00:04:43,020
and review each of those quiz questions fully

129
00:04:43,020 --> 00:04:45,300
to ensure that you can explain why each answer was right

130
00:04:45,300 --> 00:04:46,980
and why the wrong ones were wrong.

131
00:04:46,980 --> 00:04:49,650
So let's go ahead and jump into governance and compliance

132
00:04:49,650 --> 00:04:51,150
in this section of the course.

