IT Governance
What is IT Governance?
The framework of policies, processes, and organizational structures that ensure IT investments support business objectives and manage technology risks.
Terms that appear alongside it governance
Each of these is named in at least one of the same controls as it governance. The number is how many controls name both.
- governance 9 shared controls
- impact assessment 3 shared controls
- privacy risk 3 shared controls
- privacy by design 3 shared controls
- records of processing activities 3 shared controls
- high risk processing 3 shared controls
- data protection 3 shared controls
- data protection impact assessment 3 shared controls
Frameworks that govern it governance
What the standards actually require on it governance
Requirements naming it governance across 5 standards, quoted from the control text.
Review the IT governance policies and procedures of supply chain partners on a recurring cycle.
CCM-STA-13 · Supply Chain Governance Review →GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails)...
GAMP5-CrossMapping-NIST-ISO · Crosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL →Per Norwegian PDPA + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + Datatilsynet lists + (b) implement Privacy by Design and Defau...
NORWAY-4 · DPIA, Privacy by Design, Records of Processing →Per Poland law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + UODO (Urzad Ochrony Danych Osobowych) lists + (b) implement Privac...
POLAND-4 · DPIA, Privacy by Design, Records of Processing →Per Portugal law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + CNPD (Comissao Nacional de Proteccao de Dados) lists + (b) imple...
PORTUGAL-4 · DPIA, Privacy by Design, Records of Processing →Questions people ask about it governance
What is IT Governance?
Why is IT Governance important for compliance?
Which compliance frameworks address IT Governance?
Where can I learn more about IT Governance?
See how IT Governance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.