How environmental, social, governance, security, compliance, and privacy requirements constrain and inform project delivery.
Governance requirements are delivery constraints, not cleanup tasks after a project finishes. They affect scope, solution design, supplier selection, data handling, records, acceptance criteria, and release decisions.
| Area | Project implication |
|---|---|
| Security | Consider physical, operational, application, identity, network, and data controls |
| Privacy | Minimize collection, restrict access, protect sharing, define retention, and involve appropriate reviewers |
| Compliance | Map an applicable requirement to controls, evidence, owner, review frequency, and exceptions |
| ESG | Consider environmental, social, governance, and reputation effects where they are material to the project or organization |
Compliance and privacy obligations vary by jurisdiction, contract, and data context. Use the organization’s policy and appropriate professional guidance for actual requirements.