Compliance means aligning organizational operations and processes to meet the requirements of laws, regulations, customers, and other defined standards. This content covers the core factors that drive compliance obligations, how compliance is implemented through policies and procedures, and how the compliance life cycle works in practice.
Compliance
We'll kick this lesson off defining what compliance is, then we're going to take a look at some factors, some considerations when it comes to compliance. We'll talk about compliance implementation and what that looks like, and also the compliance life cycle.
To comply with something just means that we're meeting that specified standard. So when it comes to compliance, what we're doing is we're aligning our operations — what is it that we're doing — and the processes that we have, so that we're meeting those requirements of the customers, of laws, of regulations, and any other defined standards.
There's lots of things that will drive us to comply. There are things that we have to comply with, such as laws and regulations, or if there's some sort of lawsuit or legal action, we have to comply with that. There are also customers and partners. It's not necessarily something that's legal, but there are things that we want: to create these relationships with other people, with vendors, with partners, with customers. In order to do that, we have to comply with what they are going to require of us. Also, we may just have some things that we want to follow as a business, usually to mitigate things like risk.
What plays into what we have to comply to is determined by things like the geographical location — and we're going to get much more in depth into that. We're going to talk about industry: whatever industry we're in, we may have to comply to certain laws and regulations. Or if we're providing some sort of service, or if we have certain customers and what they're demanding of us, or if there's some sort of data that we're storing, or if there's some sort of specific risk that we're concerned around.
It also depends on what data we're storing, so there's different data types. If we're storing personally identifiable information, there's certain requirements we have to fall under. If it's health data, there's a different set of requirements for that. If it's financial records, there's a different set of requirements for that. So depending on what data we're storing, that means that we're going to have to comply with different compliance, different laws, different regulations.
Let's take a look at an example so we get an understanding of what we're talking about here. Let's use GDPR as an example. GDPR is a regulation, so it's a set of rules that we would legally have to follow, and we'd have to legally follow it if we have certain users that come from Eastern Europe. If we're storing their data, or we're collecting their data and we're working with those clients, then we're going to have to follow GDPR because of the location of those clients.
Once we understand what it is that we're going to have to comply with — all the different sets of standards that we'll have to comply with — what we would do then is we'd take those standards and we would implement them into our policies. From there, policies drive our procedures, and so we would change our procedures to match those standards of what we're supposed to be doing. And from there, of course, we're following those procedures, so that turns into action. So now what we have is whatever compliance there is out there has turned into action and we're complying with it. We're now complied.
Now, it would be nice if we could just implement this and not have to worry about it again, but unfortunately there are updates that happen. We might get a new client, and then they may make different demands of us. Or perhaps there are some updates to some laws and regulations. Or maybe we're moving into another geographical location and taking on new clients in a new geographical location, and so we have to adapt to their laws and regulations.
Compliance has a life cycle of beginning, middle and end. What we're going to do is we're going to identify what compliance we have to comply with, what standards we have to comply with, what laws and regulations. We've got to take our customers' requirements and fit them into this picture as well. We will research the impact and develop off of that — develop our policies and procedures — and then we would implement those policies and procedures.
Now, this isn't a static thing. We are going to get new clients all the time, we're going to be moving into other territories, we're going to have updates to laws and regulations, so we have to do a re-evaluation. That could be triggered from some sort of change that's happened, or we would want to do this on a regular basis, maybe a yearly basis, and take a look: is there anything new that we need to comply with? So there's a re-evaluation that happens.
It is not as typical that we have to end a compliance, where we take some sort of compliance away. That's generally not how it works. We would maybe do that with customers or accounts or that type of stuff, but this one, not really — usually, when we are bringing on a law and regulation, it's there to stay. There might be changes to it where we take some aspects out of it, but usually it's on there for the most part. So we just have to be thinking about the compliance life cycle.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →