Skip to content
IT Atlas

Governance · IT Governance

IT Governance

Establishing direction, decision rights, accountability and oversight so technology serves organisational objectives.

IntermediateUpdated 2026-09-01

Overview

Governance decides; management executes. It sets strategy and investment priorities, defines who may make which decisions, establishes policy, and holds delivery accountable through reporting and review.

Practical governance produces artefacts people actually use: an approved policy set, a risk register with owners, an architecture review path, a change authority model, and a small set of measures reported consistently.

How it works

  1. 01A governance forum owns the policy set, exception register and risk appetite, with defined membership and cadence.
  2. 02Architecture review checks significant changes against standards and records decisions with rationale.
  3. 03Exceptions are documented, time boxed, risk assessed and owned rather than granted informally.
  4. 04Reporting closes the loop: control effectiveness, risk position, compliance status and delivery performance.

Reference table

Policy hierarchy
ArtefactAnswersCharacterExample
PolicyWhat must happenMandatory, brief, approved by leadershipAll remote access requires multi factor authentication
StandardWhat implementation is requiredMandatory, specific, technicalRemote access uses phishing resistant MFA on the approved gateway platform
ProcedureHow to do it, step by stepMandatory sequence for a taskHow to enrol a security key and grant VPN entitlement
GuidelineWhat is recommendedAdvisory, contextualPreferred patterns for third party contractor access

Security considerations

  • Tie every security control to a policy statement so it can be justified and audited.
  • Review the exception register regularly; permanent exceptions indicate the standard is wrong.

Common misconfigurations

  • Policies copied from templates that describe controls the organisation does not operate.
  • Governance forums that review project status instead of decisions, risk and policy.
  • No exception process, so teams simply deviate silently.