Compliance

profileAj0150
Pleaseexplainyourunderstandingoforganizationalpoliciesforcompliance.docx

1. Please explain your understanding of organizational policies for compliance.

Solution

Organizations often implement policies to ensure they remain compliant with different laws and regulations. These policies can contain multiple elements. the most important element is fiduciary responsibility. A fiduciary could be a person who is trusted to hold someone else’s assets. The trusted person has the responsibility to act in the other person’s best interests.

An attorney and a client—The client trusts the attorney to act in the best interests of the client.

A CeO and a board of directors—The board trusts the CEO to act in the best interests of the company.

Shareholders and a board of directors—Shareholders trust the board to act in the best interests of the shareholders.

the fiduciary is expected to take extra steps to uphold this trust. Two steps that can be taken are

due care and due diligence:

• Due diligence—The fiduciary takes a reasonable amount of time and effort to identify risks. They investigate risks so they are understood. Failure to exercise due diligence can be considered negligence.

• Due care—If a risk is known, the fiduciary needs to take reasonable steps to protect against the risks. Failure to take due care to protect assets can also be considered negligence.

Other elements of an organizational policy could include

Mandatory vacations—Employees may be required to take an annual vacation of at least five consecutive days. The purpose of a mandatory vacation is to reduce fraud or embezzlement.

Job rotation—Employees may be rotated through different jobs. When an employee is transferred into a new job, past transactions are often reviewed and examined. This oversight can uncover suspicious activity. Job rotation helps prevent or reduce fraudulent activity.

Separation of duties

Acceptable use—An acceptable use policy (AUP) defines acceptable use for IT systems and data. Companies often inform employees of acceptable use when they are hired.

2. Why is it important to use the capability maturity model integration when managing projects?

Solution

The Capability Maturity Model Integration (CMMI) is a process improvement approach to management. It uses different levels to determine the maturity of a process.

1. CMMI is often used with software development. It helps ensure the final product meets the original goals. It also helps ensure the product is completed within budget and time constraints.

2. CMMI can be used to measure the effectiveness of services. Security can be considered a service. Security helps ensure confidentiality, integrity and availability of data and systems.

3. This can be used to ensure you consistently buy what you need. It also helps to ensure you get what you pay for.