<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130099&AdID=209259&TargetID=2556&Segments=91,115,350,2549,2690,2943,3108,3448,8877,9991,100 60,13943,13985,14402,14497,14750&Targets=39,315,302,2164,2556,2625,2878,6529,10068,10537,10640&Values=34,46,51,63,77,87,91,102,140,203,222,227,279, 382,442,657,940,1311,1716,1767,1785,1925,1970,2299,2310,2327,2352,2678,2767,2862,2878,2942,3890,3904,4080,6236,6293,6325,6352,6389,6391,6392,6393,6 422,6440,6541,6567,6580&RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e896w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>
home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek 

Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers

Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Regulatory Resource / Tactics

Developing an Information Governance Policy

By Courtney Macavinta

Despite increased regulation, the list of organizations that has acknowledged data privacy breaches in the past few years -- such as Choicepoint, Bank of America, Eli Lilly, and the U.S. Veteran's Affairs Department -- keeps growing. Whether a security breakdown involved a lost or stolen laptop, a break-in, human error, or a misplaced backup tape, once those people who are potentially affected receive notice of such an incident (as is usually required by law these days), they are often left wondering: Why did this happen? And this is the hard question that no CIO wants to have to answer.

On the data protection front, CIOs are contending with a battery of state, federal, and international privacy laws, such as the U.S. Health Insurance Portability and Accountability Act (HIPAA) or the European Union Data Protection Directive, along with recent amendments to the U.S. Federal Rules for Civil Procedure (FRCP), which reinforce that business records like email can be fair game for legal discovery.

"What that translates to for the CIO is you have to put in place a policy now that defines what is a business record," says Nancy Flynn, executive director of The ePolicy Institute. "Then you have to establish a policy governing the retention of those business records and the deletion of non-records."

To comply with such regulations and stave off bad press -- many CIOs are now creating information governance policies. The goal is to create a policy that governs what information can be collected from customers, clients, or employees, and how the data can be accessed, archived, disposed of, and secured. To create a policy that will not only help safeguard entrusted information, but perhaps even give an organization a competitive edge based on its information governance standards, experts offer these best practices:

1. Think: Responsible  At Carnegie Mellon's CIO Institute, Larry Ponemon, founder of the ethical information practices think tank the Ponemon Institute, teaches CIOs a process for creating information governance policies dubbed Responsible Information Management (or RIM). "It's a process for engendering trust and confidence in how an organization's leaders ... manage, retain, and secure ... confidential information," he notes.

The RIM process advises CIOs to take steps that include assessing their organization's information risks and vulnerabilities, developing a plan to educate executive management about the ROI for RIM, and developing key performance indicators (KPIs) to establish firm criteria for manager accountability and long-term success. CIOs should also, the RIM process outlines, help implement educational programs and a communications strategy to train and inform all employees "who handle private, confidential, or sensitive personal information."

2. Think: Comprehensive Although some organizations already have content policies that apply to email, instant messaging (IM), or employee blogs, for example, an information governance policy should cover how sensitive data is handled throughout an organization. "The CIO needs to work in conjunction with the legal, human resources, and audit departments in creating a comprehensive policy," says Stephen Pickett, the immediate past president of the Society for Information Management. "The policy needs to be comprehensive so as to leave little to the imagination of those handling information, but at the same time needs to be practical, making it easy to implement."

Ponemon adds that organizations "need an overarching framework that applies to the entire enterprise and that is respectful of the information owner who could be a customer, employee, or a business unit." Classes of information that CIOs need to consider protecting include intellectual property, customer data, employee data, and confidential business information.

3. Think: Enforcement  At the end of the day, an information governance policy is only effective if it's backed up by monitoring, performance measurement, and -- perhaps most important -- enforcement, experts say. This means CIOs need to help establish a formal process for responding to complaints and holding employees or business units responsible for clear violations of the policy. "You have to have a set of rules and policies -- and ways to vigorously monitor them -- or people won't take it seriously," Ponemon says.

And Ponemon adds that no information governance policy will be perfect, but that CIOs can prioritize based on the organization's responsibility to customers, employees, and shareholders and investors. "They need to build an [information governance] framework that doesn't just look good to regulators, but is real."

Courtney Macavinta is a Silicon Valley-based business and technology writer. Her articles have appeared in CNET News, Business 2.0, Red Herring, Wired News, and The Washington Post. She also is managing editor of  the online program The Online Family.

IT Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Sectors
Law
Tactics
Related Content
Fast Fact

"The CIO needs to work in conjunction with the legal, human resources, and audit departments in creating a comprehensive policy."

-- Stephen Pickett, former president, Society for Information Management


Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR

RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.





Internet Evolution









<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=132180&AdID=212017&TargetID=347&Segments=92,118,335,351,3108,3448,8879,10297,13986,14405,14 496&Targets=40,347,2625,2878,6527,10071,10470&Values=34,46,51,63,77,87,90,102,140,205,222,227,279,382,442,657,940,1431,1716,1767,1785,1925,1945,197 0,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567&RawValues=&Redirect= http://www.informationagenda.techweb.com/?cid=webtile_ms_bi" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/gml/IBM/Leveraging_infoagenda/tile.gif" WIDTH=125 HEIGHT=125 BORDER=0></A>

What's Hot at NWC
Editor's Picks
Network Computing Reports
 


Advertisement
<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130106&AdID=209266&TargetID=294&Segments=94,117,334,353,2567,2692,3108,3448,4080,10296,1398 8,14467,14495&Targets=322,294,298,2625,2878,3348,10067,10535,10641&Values=34,46,51,63,77,87,90,102,140,206,222,227,279,382,442,657,940,1431,1716,17 67,1785,1925,1945,1970,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567 &RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e897w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_SKY_c.gif" WIDTH=160 HEIGHT=600 BORDER=0></A>


Microsite of the Week

< Advertisement >

Powerful Information at Your Fingertips

 










<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130079&AdID=209235&TargetID=42&Segments=93,116,352,2689,3108,3448,8547,9985,13942,13987,144 93&Targets=42,321,2625,2878,10069,10556&Values=34,46,51,63,77,87,91,102,140,204,222,227,279,442,657,1311,1716,1767,1785,1798,1925,1970,2299,2310,23 13,2327,2352,2678,2767,2862,2878,2942,3712,3714,3890,3904,4079,6236,6293,6325,6356,6359,6389,6391,6392,6393,6422,6440,6541,6567,6580,6643&RawValues =&Redirect=http://www.apc.com/promo/get.cfm?keycode=e901w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/isx_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>

InformationWeek Business Technology 

Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business 

ExpoSoftware ConferenceCSI - Computer Security Institute
Black 

HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight 

Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower 

Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights