SAMMY UI is optimized for resolutions with a width 1024px and higher.
Governance Program Policy and Procedures
GRC-01: Are information governance program policies and procedures sponsored by organizational leadership established, documented, approved, communicated, applied, evaluated, and maintained?
Organizational leadership should govern the program. The program should include—but is not limited to—policies and procedures regarding legal matters, industry-specific regulations, regional requirements, compliance mandates, security and privacy requirements, and information governance. Management of each business area should include the implementation of all applicable governance policies and procedures. Policies and procedures should be reviewed and updated at least annually.
Control implemented
Control ownership
Description

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.

Governance Program Policy and Procedures
GRC-01: Are the policies and procedures reviewed and updated at least annually?
Organizational leadership should govern the program. The program should include—but is not limited to—policies and procedures regarding legal matters, industry-specific regulations, regional requirements, compliance mandates, security and privacy requirements, and information governance. Management of each business area should include the implementation of all applicable governance policies and procedures. Policies and procedures should be reviewed and updated at least annually.
Control implemented
Control ownership
Description

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.