Showing posts with label information governance. Show all posts
Showing posts with label information governance. Show all posts

May 11, 2011

Information policy... or is it a guideline or standard?

I have found that the meaning and usage of the terms ‘policy’, ‘standard’ and ‘guidelines’ is variable and interchangeable; however Bryson (1) provides the following definitions which give some clarity:

  • Policy: is a high level statement that guides the decision making process and course of action to be taken. Policies usually are mandatory.
  • Policy statement: describes the policy and may be supplemented by additional statements covering: policy objective and scope; responsibility for implementation, review and audit; background issues and implementation strategies.
  • Standard: provides rules about the choice and management of information and its supporting technologies, such as: protocols, data capture and transfer standards; metadata and taxonomy standards; data quality; standards for record keeping; and service levels. Compliance is recommended and often required in the case of legislative standards.
  • Guideline: is usually practice based and address implementation and operational issues associated with policies and standards. Guidelines are an analysis and synthesis of related policies and standards. Guidelines inform the development of processes and procedures.

The following table provides a summary of the various features that distinguish policy, standard and guideline from each other.


Policy
Standard
Guideline
Purpose
High level statement guiding decision making process and course of action (1)
Rules about the choice and management of information and its supporting technologies (1)
Practical guide to addressing implementation and operational issues associated with policies and standards (1)

Informs development of processes and procedures
Document inclusions
Statement covering purpose, objectives,  responsibility, related documents etc. (1)
Statement covering purpose, objectives,  responsibility, related documents etc. (1)
Statement covering purpose, audience, scope, background, related documents.

Implementation and operational practices.
Level of compliance
Mandatory – high level of compliance required (2)
Compliance recommended or required (2, 4)

Can have an associated  performance measurement (1, 3)
Optional but recommended (2, 4)

Flexibility in interpretation (3, 4)
Lifespan
Relatively long life span; i.e. 5 years (3)
Variable life span due to changes environment, such as legislation (2)
Life span depend on associated policies and standards
Example

An information policy can also be guided by an organisation's information principles, for example Queensland Government Enterprise Architecture & Strategy Unit (QGEA) has produced Information principles, which “are a set of ambitions or values that departments should aspire to when making decisions regarding their information and its overall management” (2). Furthermore, information policy is set within an information framework which “is not only concerned with carefully defined legal rights or restrictions on the circulation and dissemination of information… [and] the provision of a legal and regulatory framework within which information can be stored and disseminated”, but takes into consideration technological changes and issues that impact on the development of an information literate society (6).

References:
  1. Bryson, J. (2007). Managing information services: A transformational approach. Burlington, Vt.: Ashgate. [Adobe Digital Editions], pp. 129-130.
  2. Creeson, C. (2005). Information security policies: Distinct from guidelines and standards. Excerpt from Chapter 2 In Information security policies made easy, Version 10 [online]. Retrieved from http://searchsecurity.techtarget.com/feature/Information-security-policies-Distinct-from-guidelines-and-standards
  3. Battista, R., Hodge, M.J., & Vineis, P. (1995). Medicine, practice and guidelines: The uneasy juncture of science and art. Journal of Clinical Epidemilogy, 48(7), 875-880. Retrieved from Science Direct
  4. Hendricks, H.J.M., Bekkering, G.E., van Ettekoven, H., Brandsma, J.W., van der Wees, P.J., & de Bie, R.A. (2000) Development and implementation of national practice guidelines: A prospect for continuous quality improvement in Physiotherapy. Physiotherapy, 86(10), 535-547. Retrieved from Science Direct.
  5. Enterprise Architecture and Strategy Unit. (2009). Information principles. (2009, September, v 1.0.0). Queensland Government Enterprise Architecture Principles. Queensland Government Chief Information Office. Retrieved from http://www.qgcio.qld.gov.au/SiteCollectionDocuments/Architecture%20and%20Standards/QGEA%202.0/Information%20Management/Information%20principles.pdf, p. 4, point 2
  6. Dearnley, J., & Feather, J. (2001). Information policy. The wired world: An introduction to the theory and practice of the information society (pp. 60-93). London: Library Association. [CSU Reserve], p. 85, para. 4

April 15, 2011

Information governance - getting started checklist

On 11 April 2011, I attended a workshop on information governance facilitated by Matt Moore (Innotecture) with support from Keith De La Rue (AcKnowledge Consulting).

Part of the session was run along similar lines to a world cafe. Two main themes discussed were "getting buy-in" and "getting started". Following are the key thoughts from the "getting started" conversations.

Getting started : an information governance checklist

þ Mandate
Ensure that a mandate for information governance is obtained from and endorsed by senior management.

þ Central support team
Create an information management central support team composed  of people with a diversity of expertise and skills across information / data / knowledge / change / project management and subject matter knowledge and expertise.

þ Clearly defined responsibilities
Identify and charting responsibilities and ownership of information and information processes based around the RACI model
        R-responsible
        A-accountable
        C-consulted
        I- informed

þ Management, stewardship and curatorialship of information
Consider information management in the light of stewardship and curatorialship.

þ Identify champions
Identify and nurture early adopters, innovators and enthusiasts of good information practices. These are the people who will help embed good information practices across the organisation.

þ Communications strategy
Develop a robust, but flexible communications strategy based around:
  • audience / stakeholder (message based on segment)
  • format (vary depending on audience)
  • timing/phase (dependent on phase of project). 
Also consider a communication to have three elements:
  • argument (the case) which is based on data, e.g. comparative website traffic stats
  • narratives (the story) which is based on the personal account, e.g. outcome of using quality information
  • reputation (credibility) achieved by using a champion or someone of credible standing to the audience being presented to.
þ Recognition program
Create a program that recognises the achievements of champions or people doing good practice. Add social tools, such as star ratings, to make it easy to engage a broad range of people with the recognition process. (Note: This program should not to be confused with a monetary rewards program.)

þ Align projects
Not only use a project management methodology for management of projects, but ensure that program management is occurring across the organisation and portfolio management is being undertaken by senior management.

þ Scalability and flexibility
Start small, but ensure your projects and programs are scalable and flexible.

þ The user is at the centre
Projects and programs, processes and practices are designed around the user and are modified according to the audience; remembering that not all users are the same (one size does not fit all).

This checklist is not exhaustive; however considering it emerged from two 15-20 minute discussions, it's pretty good!