Regulations

Mandatory rules issued by federal, state, local, or industry authorities that a program or portfolio is required to follow. When these rules change, the Scrum Guidance Body should update its guidance so teams stay compliant.

Key Points

  • Regulations come from government levels (federal, state, local) and industry bodies.
  • Compliance is not optional; it can shape scope, priorities, and the Definition of Done.
  • Failure to comply can trigger penalties, audits, rework, or delivery delays.
  • The Scrum Guidance Body should revise recommendations, policies, and templates when rules change.

Example

A portfolio delivering healthcare products must meet a newly updated privacy law. The PMO works with the Scrum Guidance Body to revise guidance, adds privacy-related acceptance criteria to user stories, updates the Definition of Done for encryption and access logging, creates compliance tasks in team backlogs, and schedules training so all teams align before the effective date.

PMP Example Question

Legal informs the program manager that a new industry regulation will take effect next quarter. What should the program manager do to ensure agile teams comply?

  1. Wait until the next planning cycle and address issues if they arise.
  2. Update Scrum Guidance Body recommendations and embed the regulation into the Definition of Done, acceptance criteria, and backlog items across teams.
  3. Ask each Product Owner to add a generic "stay compliant" user story.
  4. Defer action until an audit identifies concrete gaps.

Correct Answer: B - Update guidance and integrate compliance into agile practices

Explanation: Regulations are mandatory. The best response is to update organizational guidance and incorporate specific compliance criteria into teams' workflows and backlogs so compliance is built in, not inspected in later.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build complete project plans in minutes with AI

Stop spending hours on documentation. Learn how to use AI to create charters, WBS, schedules, risk registers, and executive reports faster—while staying fully in control. This course gives you ready-to-use prompt templates and practical workflows based on real project work. No guesswork, no fluff—just tools you can apply immediately. Backed by Udemy’s 30-day money-back guarantee, so you can start risk-free.

Learn More