Control Objectives: Governance, Risk and Compliance

No control objectives match the current filters.
Approved Hosting and Processing Locations
SNow
Classification: PreventiveState: Published
Business sensitive information and data with compliance requirements (e.g. GxP, Personal Data), must be processed by an approved supplier at approved processing locations.
Artificial Intelligence Security Requirements
SNow
Classification: PreventiveState: Published
Data Science is a multidisciplinary field that encompasses various techniques, methods, and processes for extracting knowledge and gaining insights from data. In the context of artificial intelligence (AI), data science plays a crucial role as a foundational component. Therefore, to process the da
Compliance with Export Control & Economic Sanctions
SNow
Classification: PreventiveState: Published
Export control and economic sanctions (EC&S) requirements apply to the access to and use of software, systems, digital solutions and services across jurisdictions. These apply both to software and solutions developed by Roche as well as external hardware, software and solutions used by Roche based
Compliance with Internal Controls over Financial Reporting (ICFR)
SNow
Classification: MandatedState: Published
ICFR framework defines control activities to detect and prevent errors/fraud in financial reporting.
Compliance with Roche eDiscovery Requirements
SNow
Classification: PreventiveState: Published
Solutions containing business records (mainly document repositories, communication, and collaboration tools) are required to have the ability to: 1) preserve material that is or becomes subject to Legal/Law Hold; and 2) extract the material, if needed, in an eDiscovery-compliant format. "Material" i
Confidentiality Disclaimer at Login
SNow
Classification: PreventiveState: Published
Roche systems containing business critical, C3/C4, sensitive personal data intended for internal use must present a confidentiality disclaimer to users when storing or processing Roche business critical data.
Ensure Compliance with Applicable Local Laws
SNow
Classification: MandatedState: Published
Projects must ensure compliance with applicable laws and regulations. Local privacy, legal and compliance roles must be adequately informed and involved in the planned rollout of solutions to local markets/countries.
Information Compliance Requirements
SNow
Classification: MandatedState: Published
All IT systems must comply with the Information Compliance requirements: Classify information in your system according to the GRIC. The system must delete information at the end of the retention period. Ensure information is findable and retrievable in your system. Ensure continuous ownership of all
Local Worker´s Council Notice
SNow
Classification: PreventiveState: Published
For new software systems or services, ensure that local Worker's Councils (employees' representative bodies) are informed or involved as applicable.
PCI DSS Compliance (Credit Card Data Processing)
SNow
Classification: PreventiveState: Published
Processes which involve the storing, processing or transmission of credit card data shall assess the applicability of the Payment Card Industry Data Security Standard (PCI DSS) and comply with it as required.
Platform Operational Governance
SNow
Classification: PreventiveState: Published
A platform operational governance framework document shall be created, approved with clear roles & responsibilities (governing body) for all enterprise wide platforms/systems. The framework shall include terms of use, application on-boarding process, development/deployment best practices, legal/priv
Remote access to the manufacturing system or its component for 3rd party vendors should be under service terms and conditions, with liability for incidents due to weak cyber security practices.
SNow
Classification: IdentifyState: Published
Remote access to the manufacturing system or its component for 3rd party vendors should be under service terms and conditions, with liability for incidents due to weak cyber security practices.
Roche Digital Channel Registry Entry
SNow
Classification: PreventiveState: Published
It must be ensured that all Roche digital channels (e.g., web and mobile applications, social media accounts ) are included in Roche Digital Registry.
Solution Specific Security & Privacy Awareness Training
SNow
Classification: PreventiveState: Published
Protecting business data is critical to the overall security of Roche IT solutions and information assets. Not handling the Business data, the Business IT solution or even platform with appropriate care, could lead to unauthorized access and/or data breach within the given environment. An appropri
System Risk Assessment Verification
SNow
Classification: PreventiveState: Published
Control to check whether a System Risk Assessment is in place for Business Applications Contact: Martin Aeschlimann, Dionysia Patsou Last Update: 13-May-2025
US DoJ Compliance
SNow
Classification: ProtectState: Published
Control for compliance governance of systems in scope of Department of Justice's (DOJ) Data Security Program
Graph Explorer