Pyramid of Regulation

Pyramid of Regulation

Let's explore the intricacies of our regulations, including the importance of binding strength, flexibility, and the required level of details.

Laws

a binding custom or practice of a community : a rule of conduct or action prescribed or formally recognized as binding or enforced by a controlling authority.

Ordinances and Directives

  • Ordinances - An ORDINANCE is a law or rule made by a government or authority
  • Directives - A DIRECTIVE is a legislative act that sets out a goal that personal / organizations / countries must achieve, However, it is up to the individual countries to devise their own laws on how to reach these goals.

Recognized Standards


www.iso.org

  • Standards are voluntary regulations developed by experts for almost every area of modern commercial and everyday life.
  • You encounter standards every day – usually quite unnoticed. Even before you arrive at work in the morning, numerous standards have already made your life safer and more comfortable.
  • These ?invisible helpers? ensure the smooth interaction of various products, processes and services, and assist and accompany you through your everyday life.

What are the benefits of standards ?

Specifications and Guidelines of Associations

Company Standards

IT Policies, Procedures & Guidelines

IT Policies

  • High-level statements of management intent, expectations, and direction
  • Considered the constitution of governance and must align with the enterprise strategic objectives
  • Should be updated regularly
  • Should be evaluated for compliance by IS auditors

IT Procedures


  • Are documented, defined steps for achieving policy objectives
  • Must be derived from and reflect the parent policy
  • Document business and aligned IT processes and embedded controls
  • Must be deployed in a way that ensures awareness by the individuals who rely on them

IT Guidelines

  • Are created by process owners to give more details to the individual following the procedure steps
  • Should contain information that will help execute the procedures

INDIKA RAJAKARUNA

CISO | Professional Banker| Specialist & Senior Practitioner Info Sec & Cyber Security, Audit, Data Governance, Risk & Compliance| Speaker, Mentor & Growth Facilitator| Lecturer MBA(UK)| MSc | CISA & CISM (ISACA-USA)

4 个月

Very informative

要查看或添加评论,请登录

Lakmal Embuldeniya的更多文章

社区洞察

其他会员也浏览了