1
00:00:00,000 --> 00:00:01,410
Governance.

2
00:00:01,410 --> 00:00:03,840
In the IT and cybersecurity world,

3
00:00:03,840 --> 00:00:07,410
governance plays a huge role in everyday operations.

4
00:00:07,410 --> 00:00:09,060
It is the backbone that supports

5
00:00:09,060 --> 00:00:12,090
an organization's information security framework,

6
00:00:12,090 --> 00:00:14,310
shaping its guidelines, policies,

7
00:00:14,310 --> 00:00:16,530
standards, and procedures.

8
00:00:16,530 --> 00:00:19,380
As technology evolves, regulations change

9
00:00:19,380 --> 00:00:22,650
and cultural shifts occur within the industry.

10
00:00:22,650 --> 00:00:25,470
The need for monitoring and revising governance

11
00:00:25,470 --> 00:00:27,900
becomes increasingly important.

12
00:00:27,900 --> 00:00:30,720
So, first of all, what is governance?

13
00:00:30,720 --> 00:00:34,260
Governance is the first component of the GRC triad,

14
00:00:34,260 --> 00:00:37,410
or governance, risk, and compliance.

15
00:00:37,410 --> 00:00:39,810
It refers to the strategic leadership,

16
00:00:39,810 --> 00:00:41,970
structures, and processes

17
00:00:41,970 --> 00:00:45,330
that ensure an organization's IT infrastructures

18
00:00:45,330 --> 00:00:48,270
aligns with its business objectives.

19
00:00:48,270 --> 00:00:50,100
It involves making key decisions

20
00:00:50,100 --> 00:00:52,920
about risk management, resource allocation,

21
00:00:52,920 --> 00:00:55,350
and performance measurement.

22
00:00:55,350 --> 00:00:56,190
Simply put,

23
00:00:56,190 --> 00:00:59,130
governance is about establishing a strategic framework

24
00:00:59,130 --> 00:01:01,860
that aligns with the organization's objectives

25
00:01:01,860 --> 00:01:03,900
and regulatory requirements.

26
00:01:03,900 --> 00:01:07,260
This framework includes the rules, responsibilities,

27
00:01:07,260 --> 00:01:10,200
and practices that guide an organization

28
00:01:10,200 --> 00:01:14,970
in achieving its goals and managing its IT resources.

29
00:01:14,970 --> 00:01:18,270
Governance directly influences the creation

30
00:01:18,270 --> 00:01:21,150
and implementation of an organization's guidelines,

31
00:01:21,150 --> 00:01:23,940
policies, standards, and procedures.

32
00:01:23,940 --> 00:01:25,650
Governance plays a crucial role

33
00:01:25,650 --> 00:01:28,050
in shaping the path an organization should follow.

34
00:01:28,050 --> 00:01:30,780
Particularly in situations involving risk,

35
00:01:30,780 --> 00:01:32,520
it helps establish guidelines,

36
00:01:32,520 --> 00:01:34,080
which, while not mandatory,

37
00:01:34,080 --> 00:01:35,760
provide a recommended approach

38
00:01:35,760 --> 00:01:37,770
to handling various situations.

39
00:01:37,770 --> 00:01:40,470
Furthermore, governance is instrumental

40
00:01:40,470 --> 00:01:42,060
in policy development,

41
00:01:42,060 --> 00:01:43,890
creating high-level guidelines

42
00:01:43,890 --> 00:01:46,140
that outline the organization's commitment

43
00:01:46,140 --> 00:01:49,020
and intentions towards certain actions,

44
00:01:49,020 --> 00:01:52,230
such as data protection or ethical conduct.

45
00:01:52,230 --> 00:01:55,200
It also influences the creation of standards,

46
00:01:55,200 --> 00:01:58,350
which are more specific, often mandatory rules

47
00:01:58,350 --> 00:02:01,500
that must be followed to adhere to a policy,

48
00:02:01,500 --> 00:02:05,010
typically defined by industry or regulatory bodies.

49
00:02:05,010 --> 00:02:08,789
Lastly, governance ensures that alignment of procedures,

50
00:02:08,789 --> 00:02:10,350
the detailed steps to be followed

51
00:02:10,350 --> 00:02:12,030
to accomplish specific tasks,

52
00:02:12,030 --> 00:02:14,880
with the organization's strategic objectives,

53
00:02:14,880 --> 00:02:18,150
and so ensures the consistency and compliance

54
00:02:18,150 --> 00:02:21,240
with both policies and standards.

55
00:02:21,240 --> 00:02:25,020
As technology advances, regulatory landscapes shift

56
00:02:25,020 --> 00:02:28,170
and cultural changes occur within an industry.

57
00:02:28,170 --> 00:02:30,840
The governance framework must adapt.

58
00:02:30,840 --> 00:02:34,710
This is where monitoring and revision come into play.

59
00:02:34,710 --> 00:02:36,990
Monitoring involves regularly reviewing

60
00:02:36,990 --> 00:02:40,560
and assessing the effectiveness of the governance framework.

61
00:02:40,560 --> 00:02:43,140
It helps identify any gaps or weaknesses

62
00:02:43,140 --> 00:02:46,230
that might have arisen due to changes in technology,

63
00:02:46,230 --> 00:02:48,423
regulations, or industry culture.

64
00:02:49,290 --> 00:02:51,030
Revisions, on the other hand,

65
00:02:51,030 --> 00:02:53,400
involves updating the governance framework

66
00:02:53,400 --> 00:02:55,830
to address these gaps or weaknesses.

67
00:02:55,830 --> 00:02:58,080
This could involve updating the policies,

68
00:02:58,080 --> 00:02:59,940
standards and procedures,

69
00:02:59,940 --> 00:03:01,110
or making changes

70
00:03:01,110 --> 00:03:05,580
to the organization's IT infrastructure or operations.

71
00:03:05,580 --> 00:03:07,230
Let's consider an example.

72
00:03:07,230 --> 00:03:10,410
TechFirm is a hypothetical software development company

73
00:03:10,410 --> 00:03:12,360
with a governance framework in place

74
00:03:12,360 --> 00:03:14,730
to ensure secure coding practices.

75
00:03:14,730 --> 00:03:18,690
In 2015, TechFirm started using cloud-based services

76
00:03:18,690 --> 00:03:20,520
for some of its operations.

77
00:03:20,520 --> 00:03:22,110
This technological advancement

78
00:03:22,110 --> 00:03:24,780
required a review of their governance framework.

79
00:03:24,780 --> 00:03:27,360
They had to update their policies and procedures

80
00:03:27,360 --> 00:03:30,420
to include secure use of cloud services.

81
00:03:30,420 --> 00:03:34,500
In 2018, new data protection regulations were introduced,

82
00:03:34,500 --> 00:03:37,530
requiring more stringent protection of customer data.

83
00:03:37,530 --> 00:03:40,980
TechFirm had to monitor these regulatory changes

84
00:03:40,980 --> 00:03:44,490
and revise their governance framework accordingly.

85
00:03:44,490 --> 00:03:47,010
They updated their data protection policies

86
00:03:47,010 --> 00:03:49,770
and adopted new security standards.

87
00:03:49,770 --> 00:03:53,310
Recently there's been a cultural shift towards remote work.

88
00:03:53,310 --> 00:03:54,390
In response,

89
00:03:54,390 --> 00:03:57,630
TechFirm revised their governance framework once again.

90
00:03:57,630 --> 00:04:00,240
They updated their policies on remote work,

91
00:04:00,240 --> 00:04:03,450
adopted new procedures for secure remote access,

92
00:04:03,450 --> 00:04:08,310
and implemented new IT systems to support remote workers.

93
00:04:08,310 --> 00:04:11,550
In each case, TechFirm monitored changes

94
00:04:11,550 --> 00:04:15,000
in technology, regulations, and industry culture,

95
00:04:15,000 --> 00:04:17,760
and revised their governance framework

96
00:04:17,760 --> 00:04:19,440
to address these changes.

97
00:04:19,440 --> 00:04:21,750
This ensured that their governance framework

98
00:04:21,750 --> 00:04:22,890
remained effective,

99
00:04:22,890 --> 00:04:26,250
and that they continued to maintain secure operations.

100
00:04:26,250 --> 00:04:29,460
So remember, governance refers to the overall management

101
00:04:29,460 --> 00:04:32,070
of the organization's IT infrastructure,

102
00:04:32,070 --> 00:04:35,070
policies, procedures, and operations,

103
00:04:35,070 --> 00:04:38,010
and involves the establishment of a strategic framework

104
00:04:38,010 --> 00:04:40,410
that aligns with the organization's objectives

105
00:04:40,410 --> 00:04:42,450
and regulatory requirements.

106
00:04:42,450 --> 00:04:45,090
Governance affects the creation of guidelines,

107
00:04:45,090 --> 00:04:48,150
policies, standards, and procedures directly.

108
00:04:48,150 --> 00:04:51,270
Finally, by adapting to changes in technology,

109
00:04:51,270 --> 00:04:53,460
regulations, and industry culture,

110
00:04:53,460 --> 00:04:54,900
governance helps ensure

111
00:04:54,900 --> 00:04:58,050
that an organization's IT systems and processes

112
00:04:58,050 --> 00:05:00,780
are secure, efficient, and compliant

113
00:05:00,780 --> 00:05:03,903
with all relevant laws and regulations.

