Governance is ...


... "strategic frameworks, organisational structures, policies and processes used
to guide/direct, oversee/monitor and to some extent control the organisation, ensuring that it fulfils its strategic objectives and complies with internal and external obligations" [source: SecAware glossary]

... applicable to corporations, organisations, nations, the globe, industries, business units, finance, the environment, governments, projects, land, health,
steam engines, watches, IT, information, information risk and security ...

... for the benefit of stakeholders, owners, regulators, authorities, society

... designing and implementing appropriate corporate structures

... rigidly defining areas of doubt and uncertainty

... reassuring the organisation's stakeholders

... the system of corporate control

... right and proper management

... the plane above management

... the broadest integrity control

... conformance and compliance

... key roles and responsibilities

... applicable at different levels

... a blueprint for management

... encouraging whistleblowers

... organising the organisation

... a fine pair of spinning balls

... catering for whistleblowers

... how the enterprise is run

... assurance arrangements

... internal communications

... keeping things in check

... painting the big picture

... intalling back-channels

... the top of the cascade

... what a governor does

... easily misunderstood

... preventing runaways

... part of management

... the board's bailiwick

... a dynamic challenge

... an evolving concept

... proportional control

... negative feedback

... not management

... part of the fabric

... a misused word

... accountability

... fundamental

... coordination

... no surprises

... conscience

... alignment

... oversight

... direction

... complex

... rational

... critical

... ethics

... key

...

You may have missed these other rambles:
Go ahead, pickuppappencil and comment away.

Popular posts from this blog

Pragmatic ISMS implementation guide (FREE!)

Two dozen information risks that ISO forgot

Philosophical phriday - compliance risk

ISMS internal audit priorities

Reading between the lines of ISO27001 [L O N G]

Passionate dispassion

45 ISO Management Systems Standards

Philosophical phriday - a noncompliance ramble

Adaptive SME security Crowdstrike special