Governance · IT Governance
IT Governance
Establishing direction, decision rights, accountability and oversight so technology serves organisational objectives.
IntermediateUpdated 2026-09-01
Overview
Governance decides; management executes. It sets strategy and investment priorities, defines who may make which decisions, establishes policy, and holds delivery accountable through reporting and review.
Practical governance produces artefacts people actually use: an approved policy set, a risk register with owners, an architecture review path, a change authority model, and a small set of measures reported consistently.
How it works
- 01A governance forum owns the policy set, exception register and risk appetite, with defined membership and cadence.
- 02Architecture review checks significant changes against standards and records decisions with rationale.
- 03Exceptions are documented, time boxed, risk assessed and owned rather than granted informally.
- 04Reporting closes the loop: control effectiveness, risk position, compliance status and delivery performance.
Reference table
| Artefact | Answers | Character | Example |
|---|---|---|---|
| Policy | What must happen | Mandatory, brief, approved by leadership | All remote access requires multi factor authentication |
| Standard | What implementation is required | Mandatory, specific, technical | Remote access uses phishing resistant MFA on the approved gateway platform |
| Procedure | How to do it, step by step | Mandatory sequence for a task | How to enrol a security key and grant VPN entitlement |
| Guideline | What is recommended | Advisory, contextual | Preferred patterns for third party contractor access |
Security considerations
- Tie every security control to a policy statement so it can be justified and audited.
- Review the exception register regularly; permanent exceptions indicate the standard is wrong.
Common misconfigurations
- Policies copied from templates that describe controls the organisation does not operate.
- Governance forums that review project status instead of decisions, risk and policy.
- No exception process, so teams simply deviate silently.
