Skip to content

IT Governance

What is IT Governance?

The framework of policies, processes, and organizational structures that ensure IT investments support business objectives and manage technology risks.

Governance

Each of these is named in at least one of the same controls as it governance. The number is how many controls name both.

What the standards actually require on it governance

Requirements naming it governance across 5 standards, quoted from the control text.

Review the IT governance policies and procedures of supply chain partners on a recurring cycle.

CCM-STA-13 · Supply Chain Governance Review

GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails)...

GAMP5-CrossMapping-NIST-ISO · Crosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL

Per Norwegian PDPA + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + Datatilsynet lists + (b) implement Privacy by Design and Defau...

NORWAY-4 · DPIA, Privacy by Design, Records of Processing

Per Poland law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + UODO (Urzad Ochrony Danych Osobowych) lists + (b) implement Privac...

POLAND-4 · DPIA, Privacy by Design, Records of Processing

Per Portugal law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + CNPD (Comissao Nacional de Proteccao de Dados) lists + (b) imple...

PORTUGAL-4 · DPIA, Privacy by Design, Records of Processing

Questions people ask about it governance

What is IT Governance?
The framework of policies, processes, and organizational structures that ensure IT investments support business objectives and manage technology risks.
Why is IT Governance important for compliance?
IT Governance is a key concept in Governance. Understanding it governance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address IT Governance?
IT Governance appears in the requirement text of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, GAMP 5 - Good Automated Manufacturing Practice, Personal Data Act (personopplysningsloven), Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018), Portugal Law No. 58/2019 - Data Protection Implementation Act. Across these standards we have identified 5 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about IT Governance?
Explore our compliance framework pages to see how it governance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how IT Governance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.