Laws, Regulations and Compliance Management
The final Domain 2 lesson. How an organisation knows which obligations apply, proves it meets them, and why the auditor reports non-compliance rather than fixing it.
What this makes you able to do
Evaluate whether an organisation identifies its legal and regulatory obligations and manages compliance with them on an ongoing basis.
By the end you can
- Explain why identifying applicable obligations is the first compliance control.
- Distinguish the auditor's role from management's in achieving compliance.
- Recognise compliance treated as a one-off event rather than an ongoing process.
Transcript
Laws, regulations and compliance management. This is the last lesson of Domain 2, and it ties the governance half of the exam back to a single discipline: knowing what applies to you, proving you meet it, and keeping the auditor on the right side of the line.
Start with the situation. An organisation proudly shows you a compliance certificate. It is framed, it is genuine, and it is two years old. In those two years the systems have been rebuilt and the regulation itself has been amended. The certificate proves the company was compliant once. It says nothing about today.
That is the failure this lesson is about: compliance treated as a trophy rather than a process. Something you win and hang on the wall, instead of something you maintain. Hold that image, because the exam keeps coming back to it.
Now the first control, and it is the one people skip. You cannot comply with what you have not identified. The very first step in compliance management is determining which laws and regulations actually apply to you. Not implementing controls, not booking an audit, not buying a tool. Identifying the obligations comes first.
What drives those obligations. First, jurisdiction: where the organisation operates, and where its data subjects are. The same company can face different rules in every country it touches.
Second, industry: the sector-specific rules for finance, for health, for payments. A hospital and a payment processor carry very different obligations from the same starting point.
And third, data and services: what the organisation actually holds and does. Holding personal data triggers data-protection and breach-notification duties that a business without that data simply does not have. Jurisdiction, industry, data and services. Those three tell you what applies.
So the order matters. Identify first, then build. If you implement a stack of common controls before knowing your actual obligations, you risk meeting requirements that do not apply to you, while missing the ones that do. When a question asks for the first step in compliance management, the answer is identifying what applies.
Now the auditor’s role, because the exam draws a hard line here. When you find non-compliance, you do the same thing you do with every finding in Domain 1. You report it to management and to those charged with governance, and you evaluate their response. You do not implement the fix. You do not, by default, report the organisation straight to the regulator, that bypasses management and governance and is not your responsibility absent a specific legal duty. And you never ignore a known non-compliance because detection seems unlikely, that is not a judgement call, it is an ethics breach.
Why not just fix it. Because the moment you implement the control you found broken, you become the doer of that control, and you can no longer independently assess it. Report, do not remediate. The remediation, and the accountability for it, stays with management. This is the independence principle you have seen in every findings question.
And now the deepest point, a favourite exam theme. Compliance is a continuous process, not a one-off event. Systems change, regulations change, and controls degrade over time. A certification is point-in-time evidence, and exactly like the current access listing back in Domain 1, it describes a state that may no longer exist.
So carry this away. A two-year-old certificate does not prove the organisation is compliant today. The concern is not that the original certificate was wrong, it is that current compliance is simply unknown. Effective compliance builds in continuous monitoring and periodic reassessment, so the question, are we compliant, can be answered about today. That completes Domain 2.
1.What is the FIRST step in managing regulatory compliance for IT?
2.During an audit, an IS auditor discovers the organisation is not complying with a data protection regulation. What is the auditor's PRIMARY responsibility?
3.An organisation achieved a compliance certification two years ago and has not reassessed since, though its systems and the regulations have both changed. What is the MAIN concern?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
