# Gobernanza y Compliance Digital — material de repaso

# Chuleta — Gobernanza y Compliance

## Map one control across the 3 frameworks (course exercise)
'Access management' → ISO 27001 A.9 · NIST CSF PR.AC · ENS [op.acc]
Trick: the control is one; what changes is the language of each framework.

## RGPD in 5 questions (any form)
1. ¿What do I collect? → minimum
2. ¿Why? → purpose + lawful basis
3. ¿For how long? → deadline + deletion
4. ¿Where? → location + security
5. ¿Who sees it? → internal register + processors
→ If a question has no answer: don't collect that data

## Risk in one line
`asset + threat + probability × impact + treatment (mitigate/transfer/accept/eliminate) + owner + review date`

## Treatment decision
- Cost of control < cost of impact → MITIGATE
- There is insurance/contract that covers it → TRANSFER
- Impact tolerable and documented → ACCEPT (signed)
- The asset is not needed → ELIMINATE

## Compliance file (minimum index)
1. Asset inventory · 2. Risk matrix · 3. Policies in force (versioned)
4. Training records · 5. Incident log · 6. Signed reviews

## Golden rule
Data that doesn't exist can't leak. User = anonymous token.

*Generado por edu-forge academy. Imprímela: es lo que llevas al examen.*
