Legal Requirements and the Ethics of Risk Management
For any organization, legal, regulatory, and contractual requirements play a major role in how the organization is governed, and this is no different from how IT risk is managed. Failure to comply with the local laws and applicable regulations could lead to severe penalties causing monetary and reputational damages. Multinational organizations need to be wary of the local, federal, and international regulations in addition to the specific laws of each industry, making it extremely difficult for the organization to comply with all the laws of each location.
Historically, these requirements were delegated to business owners to ensure controls against business processes such as financial fraud and corporate governance controls were in place. However, in the last two decades, the responsibility has also equally shifted on the IT side with the responsibilities of confidentiality/integrity/availability of data, privacy requirements...