Opinion: Getting to governance
Asserting information security's place at the management table
Computerworld - Looking over his glasses with a librarian's stare, an executive recently told me, "You IT people love the word governance, but it just seems too...." His voice trailed off as he searched for a way to tactfully convey his sense that "information governance" was a linguistic wedge designed to throw open the doors of board-level access for unkempt geeks and help desk managers. Instead of "governance," more comfortable phrases were suggested: "information policy board," "data management" or perhaps "IT steering committee."
Governance is a powerful word, and its use in an IT context implies that information is important -- which of course it is. Stripping away the trappings of applications, systems and networks, information is the core asset of most organizations. Establishing information governance is not, as some might think, the elevation of firewall administration to a board-level duty, and it doesn't mean the security controls that protect information subvert all other business processes.
Quite to the contrary, if information governance is planned and managed properly, information security controls end up being close parallels to, or integrated within, existing business processes. It is the establishment and maintenance of a connection between the organization's most valuable assets and the organization's control structure. Embracing governance concepts is the admission that we have assets we've ignored and that there needs to be some sort of structure that makes information tangible, addressable and protected.
"We've got some rules around here"
When challenged to explain information governance to executives, it's easy to digress into academic and philosophical debates over the centrality of information in a business. But that structure -- identifying information so that it's tangible and can be protected -- is the essence of governance. It's the explicit statement that there are rules about how people use processes and technology that affect or protect information.
The good news is that the concepts surrounding governance are becoming more easily understood as the professional dialogue and community body of knowledge becomes more mature and refined. A few years ago, one might have had to dig through the ISO 20000 IT service management (or the IT Infrastructure Library) and ISO 27001 (security management) standards to find the right words about establishment of a "management system" and to explain the desired governance framework for an information-heavy organization. Now there are numerous voices -- some better than others -- providing definitions and discussion on the topic.
More recently, respectable certifications have become available for professionals involved in the establishment or operation of information governance systems. For example, the Information Systems Audit and Control Association (ISACA) is administering its first test for the Certification in the Governance of Enterprise IT (CGEIT) this fall.
More columns
- Four signs your security program has gone too far
- Where are those infosec jobs?
- Security ahead of risk at the border
- A spring column cleaning
- Phishing in the backyard
- Four good reasons for Security to talk to HR
- Not where you think they are
- When disaster recovery's down to you
- At the airport, an ID theft takes flight
- Goodbye to the Year of the Fire Pig
- Mixing open- and closed-source, managing risk
- Privacy and piracy: What are we telling the kids?



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Smarter Commerce is redefining value chain visibility
- Smarter Commerce is redefining the value chain in the age of the customer. It starts with putting the customer at the center of...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
- The Executive Buyer's Guide to Project Portfolio Management
- The Innotas Executive Buyer's Guide provides you with a concise overview of Project Portfolio Management (PPM) and delivers important buying criteria to help... All Management and Careers White Papers
- Live Webcast
Integrated IT Operations Management in the Cloud - Join award-winning technology editor Stan Gibson and Andrew White, CMO at Numara Software, to learn how asset management and service management are converging...
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at Numara Software, to learn how asset management and service management are converging...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Management and Careers Webcasts