Business:Concepts:Principle:PRINC-0006: Comply With Laws And Standards
<data principle #PRINC-0006>
Categories : Business
Title : Compliance with Law and Standards
Statement : The organisations’ systems MUST comply with all applicable laws, policies, regulations and standards.
Rationale : The potential cost of potential loss of reputation, litigation, penalties and subsequent modifications required to comply are more expensive than planning and executing the steps required to comply.
Implications : The sector must be mindful to comply with applicable laws, regulations, internal and external policies and standards regarding the collection, retention, management and disposal of data.
The sector’s organisation’s must provide access to the rules, educate and manage their application.
The sector’s organisations must remain mindful of the current state of regulations and when necessary proactively drive changes in processes or applications to meet changes in order to remain compliant at all times.
Changes in the law and changes in regulations may drive changes in processes or applications.
Recommendation : Planning and execution does not preclude action improvements that lead to changes in policies and regulations.
Ensure organization stakeholders understand the principle and ensuing requirement to comply with New Zealand Information Security Manual (NZISM) standard, New Zealand Web Accessibility Standard (NZWAS) and New Zealand Usability Standard (NZWUS).
Resources : * Principle
* See TOGAF Principle 6
</data>