{"id":1809,"date":"2014-02-11T01:40:35","date_gmt":"2014-02-11T01:40:35","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=1809"},"modified":"2019-03-08T19:52:31","modified_gmt":"2019-03-09T00:52:31","slug":"symposium-series-what-is-information-governance","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2014\/02\/11\/symposium-series-what-is-information-governance\/","title":{"rendered":"Symposium Series: What Is Information Governance?"},"content":{"rendered":"<p style=\"text-align: center\">\u00a0\u00a0\u00a0\u00a0\u00a0by Peter Sloan, Husch Blackwell LLP<\/p>\n<p align=\"center\">February 5, 2014<\/p>\n<p style=\"text-align: center\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n<p>If anything cries out for organizational governance today, surely it is information.\u00a0\u00a0 Data volumes are rising relentlessly; information is flowing in and out of organizations more pervasively than ever; and mobile computing, cloud services, big data analytics, and social networking are fundamentally transforming the organization\u2019s relationship with information.\u00a0 Meanwhile, the compliance environment grows yet more complicated, as organizations, regulators, and the courts wrestle with the repercussions of massive data breaches, the evolving scope of e-discovery, and allocation of responsibility for the retention and protection of information.\u00a0 Shortcomings of the traditional practices used by organizations to deal with information are becoming clear, as is the need for a new, comprehensive approach.\u00a0 And that fresh approach has been dubbed \u201cInformation Governance.\u201d<\/p>\n<p>But what exactly is Information Governance?\u00a0 Despite widespread use of the term,<a title=\"\" href=\"#_ftn1\">[1]<\/a> few definitions have been offered.\u00a0 With due deference to Shakespeare\u2019s Juliet,<a title=\"\" href=\"#_ftn2\">[2]<\/a> and also to Justice Stewart,<a title=\"\" href=\"#_ftn3\">[3]<\/a> names and definitions matter. They are particularly important when the subject, unlike roses and pornography, has not been with us for a very long time.\u00a0 And Information Governance indeed is a new approach for addressing information issues.\u00a0 To be more precise, Information Governance involves a new reconciliation of departmental interests (such as those of IT, Legal, Compliance, Records Management, and lines of business) and of traditional information disciplines (such as records &amp; information management, privacy &amp; data security, and litigation preservation &amp; discovery)\u2014in essence, connecting familiar building blocks in a new, different, and more effective way, to better serve the organization as a whole.\u00a0 So, definitional clarity is essential here, precisely because Information Governance involves a fundamental change in established perspectives and practices.<\/p>\n<p>What definitions have been proffered for Information Governance?\u00a0 According to Gartner, the global information technology research and advisory company, Information Governance is \u201cthe specification of decision rights and an accountability framework to ensure appropriate behavior in the valuation, creation, storage, use, archiving and deletion of information.\u00a0 It includes the processes, roles and policies, standards and metrics that ensure the effective and efficient use of information in enabling an organization to achieve its goals.\u201d<a title=\"\" href=\"#_ftn4\">[4]<\/a>\u00a0 ARMA International similarly defines Information Governance as \u201ca strategic framework composed of standards, processes, roles and metrics that hold organizations and individuals accountable to create, organize, secure, maintain, use, and dispose of information in ways that align and contribute to the organization\u2019s goals.\u201d<a title=\"\" href=\"#_ftn5\">[5]<\/a><\/p>\n<p>The Compliance, Governance, and Oversight Council (\u201cCGOC\u201d) has defined Information Governance as \u201cthe discipline of managing information according to its legal obligations and its business value, which enables defensible disposal of data and lowers the cost of legal compliance.\u201d<a title=\"\" href=\"#_ftn6\">[6]<\/a>\u00a0<\/p>\n<p>Most recently, the Sedona Conference has defined Information Governance as \u201can organization\u2019s coordinated, inter-disciplinary approach to satisfying information compliance requirements and managing information risks while optimizing information value.\u201d<a title=\"\" href=\"#_ftn7\">[7]<\/a>\u00a0<\/p>\n<p>While each of these definitions has its strengths, here\u2019s what I like about the Sedona Conference definition:<a title=\"\" href=\"#_ftn8\">[8]<\/a>\u00a0<\/p>\n<ul>\n<li>Success with Information Governance requires strategic commitment by the organization\u2019s leadership, which is best accomplished when clear benefits accrue to the organization.\u00a0 Embedding compliance, risk management, and value into the definition communicates a clear \u201cwhy\u201d for pursuing Information Governance.\u00a0 These words articulate concrete, strategic benefits for the organization as a whole, and they also anchor the endeavor\u2019s purpose.\u00a0<\/li>\n<li>The terms \u201ccoordinated\u2019 and \u201cinter-disciplinary\u201d succinctly capture the essence of Information Governance, addressing the strategic \u201cwhat\u201d that is being accomplished.\u00a0 The most challenging aspect of adopting Information Governance is bridging across traditional information silos.\u00a0 To be successful with Information Governance, the organization\u2019s individual departments and functions such as Legal, IT, Records, Compliance, and lines of business must <span style=\"text-decoration: underline\">coordinate<\/span> so that decisions about the organization\u2019s information will reflect the needs of the organization as a whole, rather than parochial interests.\u00a0 And success with Information Governance also requires <span style=\"text-decoration: underline\">inter-disciplinary<\/span> assessment and decision-making, so that information decisions are not based solely on the limited perspectives of traditional disciplines such as records &amp; information management, privacy &amp; data security, and litigation preservation &amp; discovery.\u00a0 This is the essential feature of Information Governance, through which the organization expands its perspective to consider all aspects and angles of information compliance, risk, and value.<\/li>\n<\/ul>\n<p>The Sedona definition does not prescribe the particulars of how Information Governance is implemented, referring instead to the organization\u2019s \u201capproach\u201d to accomplishing this coordinated, inter-disciplinary effort, and leaving the specifics of the implementation \u201chow\u201d to supporting guidance.\u00a0 I think that\u2019s prudent, because there will be various approaches for implementing Information Governance, and the definition should not be too limiting.\u00a0 Reality suggests that different organizations adopting the Information Governance approach will operate at different points on a maturity continuum.\u00a0 Some, frankly, will begin by simply getting the right people together in the room to thoroughly explore all angles to information-related decisions at the organization before they are made.\u00a0 Others will put in place elements of structure, direction, and resources to support Information Governance efforts, along with mechanisms for accountability.\u00a0 Yet others will establish robust control systems for Information Governance, based upon applicable information-related standards<a title=\"\" href=\"#_ftn9\">[9]<\/a> or modeled upon standards for internal control systems generally.<a title=\"\" href=\"#_ftn10\">[10]<\/a>\u00a0<\/p>\n<p>Years from now, perhaps most organizations will be well along the path of this maturity continuum, and hopefully so.\u00a0 And yes, organizations certainly will need authoritative guidance on implementation frameworks, strategies, and options for building Information Governance programs. But my hunch is that, at least in the short term, different organizations will pursue Information Governance programming in a wide variety of ways.\u00a0 While I may feel strongly about the importance of conducting Information Governance assessments and setting program objectives, followed by establishing structure, direction, resources, and accountability for an effective Information Governance program, these are specifics of implementation &#8212; the How, rather than the definitional What and Why.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<hr align=\"left\" size=\"1\" width=\"33%\" \/>\n<div>\n<p><a title=\"\" href=\"#_ftnref1\">[1]<\/a>\u00a0 A simple Google search for \u201cInformation Governance\u201d on February 3, 2014 yielded 1,250,000 search results.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref2\">[2]<\/a>\u00a0 \u201cWhat\u2019s in a name?\u00a0 That which we call a rose by any other name would smell as sweet \u2026.\u201d\u00a0 Shakespeare, <i>Romeo and Jul<br \/>\niet<\/i>, Act 2, Scene 2.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref3\">[3]<\/a>\u00a0 \u201cI shall not today attempt further to define the kinds of material I understand to be embraced within that shorthand description; and perhaps I could never succeed in intelligibly doing so.\u00a0 But I know it when I see it, and the motion picture involved in this case is not that.\u201d\u00a0 <i>Jacobellis v. Ohio<\/i>, 378 U.S. 184, 197 (1964) (Stewart, J., concurring).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref4\">[4]<\/a>\u00a0 <i> See<\/i> Gartner IT Glossary, <a href=\"http:\/\/www.gartner.com\/IT-Glossary\/information\/governance\">http:\/\/www.gartner.com\/IT-Glossary\/information\/governance<\/a> (last visited January 29, 2014).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref5\">[5]<\/a>\u00a0 <i>See<\/i> <i>Glossary of Records and Information Management Terms<\/i>, 4<sup>th<\/sup> Ed. (ARMA TR 22-2012).\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref6\">[6]<\/a>\u00a0 \u00a0 The CGOC\u2019s definition of information governance is found <i>Information Governance Benchmark Report in Global 1000 Companies<\/i>, CGOC 1, 8 (2010).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref7\">[7]<\/a>\u00a0 The Sedona Conference, <i>the Sedona Conference Commentary on Information Governance<\/i> (Public Comment Version) (2013), <i>Available at <\/i><a href=\"https:\/\/thesedonaconference.org\/publications\"><i>https:\/\/thesedonaconference.org\/publications<\/i><\/a><i>.<\/i><\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref8\">[8]<\/a>\u00a0 Full disclosure \u2014 I am a Sedona Conference Working Group 1 participant and contributed to its <i>Commentary on Information Governance<\/i>.\u00a0 I am also a member of ARMA International and have participated in the CGOC.\u00a0 Obviously, my views are my own and are not attributable to these fine organizations.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref9\">[9]<\/a>\u00a0 Various standards provide organizations guidance on assessing information practices and providing structure, direction, resources, and accountability for information governance.\u00a0 <i>See<\/i> International Standard ISO 15489\u20111, <i>Records Management; <\/i>International Standard ISO 30301, <i>Management Systems for Records; <\/i>International Standard ISO\/IEC 27001, <i>Information Security Management Systems<\/i>; and ISO\/IEC 27001:2005(E). \u00a0<i>See<\/i> <i>also<\/i> <i>The Generally Accepted Recordkeeping Principles<\/i>, ARMA (Feb. 17, 2013).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"#_ftnref10\">[10]<\/a> <i>See<\/i> COSO, <i>Internal Control-Integrated Framework<\/i>, Executive Summary (May\u00a02012).\u00a0 A COSO-based internal control system is the combination of five integrated components, including a control environment, risk assessment, control activities, information and communication, and monitoring activities.\u00a0 <i>Id. <\/i>at 4-5<i>.<\/i><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0\u00a0\u00a0\u00a0\u00a0by Peter Sloan, Husch Blackwell LLP February 5, 2014 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 If anything cries out for organizational governance today, surely it is information.\u00a0\u00a0 Data volumes are rising relentlessly; information is flowing in and out of organizations more pervasively than ever; and mobile computing, cloud services, big data analytics, and social networking are fundamentally transforming the organization\u2019s [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366,61850],"tags":[],"class_list":["post-1809","post","type-post","status-publish","format-standard","hentry","category-blog-post","category-symposium"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-tb","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/1809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=1809"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/1809\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=1809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=1809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=1809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}