Regulations

Mandatory rules issued by federal, state, local, or industry authorities that a program or portfolio is required to follow. When these rules change, the Scrum Guidance Body should update its guidance so teams stay compliant.

Key Points

  • Regulations come from government levels (federal, state, local) and industry bodies.
  • Compliance is not optional; it can shape scope, priorities, and the Definition of Done.
  • Failure to comply can trigger penalties, audits, rework, or delivery delays.
  • The Scrum Guidance Body should revise recommendations, policies, and templates when rules change.

Example

A portfolio delivering healthcare products must meet a newly updated privacy law. The PMO works with the Scrum Guidance Body to revise guidance, adds privacy-related acceptance criteria to user stories, updates the Definition of Done for encryption and access logging, creates compliance tasks in team backlogs, and schedules training so all teams align before the effective date.

PMP Example Question

Legal informs the program manager that a new industry regulation will take effect next quarter. What should the program manager do to ensure agile teams comply?

  1. Wait until the next planning cycle and address issues if they arise.
  2. Update Scrum Guidance Body recommendations and embed the regulation into the Definition of Done, acceptance criteria, and backlog items across teams.
  3. Ask each Product Owner to add a generic "stay compliant" user story.
  4. Defer action until an audit identifies concrete gaps.

Correct Answer: B - Update guidance and integrate compliance into agile practices

Explanation: Regulations are mandatory. The best response is to update organizational guidance and incorporate specific compliance criteria into teams' workflows and backlogs so compliance is built in, not inspected in later.

AI for Project Managers — Build Plans Faster, Lead Better

Turn messy inputs into structured project plans in minutes. If you are a project manager tired of spending hours on documentation, this course shows you how to use AI to work faster while staying fully in control.

This is not a generic AI course. You will learn how to use AI as a practical co-pilot to build real project artifacts—charters, WBS, schedules, risk registers, and executive reports—using structured, reliable prompt frameworks.

You will also learn how to keep your project aligned across scope, schedule, cost, and risk, and how to interpret performance data like Earned Value Management to support better decisions and communication.

Everything is designed for immediate use. You get ready-to-use prompt templates and workflows you can apply right away in your projects. Watch the video to see how it works and start building your first AI-supported project plan.

Explore the Course


Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course