This type of program typically comes into existence because of concerns about Data Information Security controls, or compliance. Compliance, in this context, may refer to regulatory compliance, contractual compliance, or compliance with internal requirements.

Focus Areas for Data Governance: Privacy, Compliance, Security

This focus is often seen combined with a focus on policy enforcement. It’s also seen combined with a focus on Data Quality.

The program almost always results from a senior management mandate. It may be formally sponsored by Business or IT, or it may be an outgrowth of a Governance, Risk, and Compliance (GRC) program.

These programs generally begin with an enterprise scope, but often efforts are limited to specific types of data. They almost always include technologies to locate sensitive data, to protect data, and/or to manage policies or controls.

 

A charter for this type of program may hold Data Governance and Stewardship participants accountable to:

  • Help locate sensitive data across systems
  • Align governance, compliance, security, and technology frameworks and initiatives
  • Help assess risk and define data-related controls to manage risk
  • Help enforce regulatory, contractual, architectural compliance requirements
  • Support Access Management and Security requirements
  • Identify stakeholders, establish decision rights, clarify accountabilities

Read Next:

Goals and Principles for Data Governance

What do you want Data Governance to accomplish?  Regardless of the focus of your program, chances are you hope to accomplish the following universal goals for Data Governance programs: Goal – Enable better decision-making Goal – Reduce operational friction Goal –...

Engaging Stewards and Stakeholders

It seems like there are two types of Data Governance and Stewardship programs: Thriving ones, with highly-engaged stakeholders, and Ones whose futures are in question, since stakeholders and stewards are only sporadically involved or give only weak support to the...

Starting a Data Governance Program

A successful Data Governance program does not begin with the design of the program! Before you start deciding who goes on what committee, you should be clear about your program’s value statement. You should have developed a roadmap to share with stakeholders. Those...

Focus Areas for Data Governance: Data Quality

This type of program typically comes into existence because of issues around the quality, integrity, or usability of data. It may be sponsored by a Data Quality group or a business team that needs better quality data. (For example: Data Acquisition or  Mergers &...

Setting Governance Roles and Responsibilities

Who does what in a Data Governance program? First, a group of individuals (or a hierarchy of groups) representing a cross-section of stakeholder groups makes a set of rules in the form of policies, standards, requirements, guidelines, or data definitions. (Or, they...

Assigning Data Ownership

One of the tenets of Data Governance is that enterprise data doesn’t “belong” to individuals. It is an asset that belongs to the enterprise. Still, it needs to be managed…

Focus Areas for Data Governance

All Data Governance programs are not alike. Quite the contrary: programs can use the same framework, employ the same processes, and still appear very different. Why is this? It’s because of what the organization is trying to make decisions about or enforce rules for....

Defining Data Governance

How you define your program will influence your ability to manage it — to keep all participants on focus, in sync, and striving toward the same goals.

Focus Areas for Data Governance: Management Alignment

This type of program typically comes into existence when managers find it difficult to make “routine” data-related management decisions because of their potential effect on operations or compliance efforts.Managers may realize they need to come together to make...

Implementing Change Management

Most organizations have string change management – or at least change control – mechanisms for technology. They usually have change management for software applications. They have change management for websites. And yet, many organizations do not practice structured...