SlideShare une entreprise Scribd logo
1  sur  18
Télécharger pour lire hors ligne
DGIQ 2018
JUNE 13, 2018
How to be Successful in the Post GDPR Landscape –
Building a Strategy Customers & Auditors Love
Confidential and Proprietary. Copyright© 2018. DATUM LLC
2
Agenda
• Who we are
• Compliance
Being Compliant AND being Audit Resilient
The Data Control Model; Control Elements
4 Steps to a Governance Framework
• Building the Governance Framework in Information Value
Management
Confidential and Proprietary. Copyright© 2018. DATUM LLC
We help the world’s
leading organizations
identify, organize and use
data to solve problems
and create opportunities.
Confidential and Proprietary. Copyright© 2018. DATUM LLC3
4
Compliance evolves with capabilities
Confidential and Proprietary. Copyright© 2018. DATUM LLC
Compliance is the goal, but over time what you want is
Audit Resilience
Easy, Stress Free, Repeatable,
Transparent, Extensible
Compliance is about defining the Data Control Model
that reduces risk, and creates “Audit Resilience”
Data Control Model
5 Confidential and Proprietary. Copyright© 2018. DATUM LLC
Control System Defined:
Control Environment
• Sets the tone for the organization
Risk Assessment
• Identification and analysis of relevant
risks to the achievement of objectives
Information and Communication
• Systems or processes that support the
identification, capture, and exchange
of information
Control Activities
• Policies and procedures that help
ensure management directives are
carried out
Monitoring-processes
• Assess the quality of internal control
performance over time.
The configuration of
the Governance
Framework to align
impacted data with
compliance
requirements
An Operating Model
that ensures
accountability and
minimizes risk
For DATUM a Data Control Model sits within
the Control System, and is always:
https://www.aicpa.org/
Data Control Model
6 Confidential and Proprietary. Copyright© 2018. DATUM LLC
Control Elements:
Data is labelled with sufficient metadata to
support risk analysis and alignment to
larger Control System Elements
• Data Catalog / Dictionary have been
configured with appropriate metadata
labelling to support risk processes
Control activities are completely defined
• All data in scope is controlled via Rule(s)
that are supported by Standards
• All Composers have Owners, and Rules
have execution Owners (Roles)
The controls are exposed and
communicated
• Reports are configured in Information
Value Management
Monitoring process exists
• Data Quality feature is activated and are
monitoring Control Rules
1. Configure Governance Framework
2. Configure Operating Model
3. Identify Control Points
4. Ensure that the Control Points have
all control elements implemented
Steps to setting up Control Model:
7
Four Steps to a Governance Framework
Confidential and Proprietary. Copyright© 2017. DATUM LLC
What are Value
Driver Goals ?
What Objectives
Support Goals?
How do I
Recognize
Success?
Start with Business Value!
8
1. Build out the Goals, Objectives &
Metrics to align Value
Confidential and Proprietary. Copyright© 2017. DATUM LLC
StrategyAction
9
2. Build the Catalog
Confidential and Proprietary. Copyright© 2017. DATUM LLC
2 Catalog Data: Foundational to Managing Data
3 Describe Data: Tag to align with value drivers
Identify Data: What are my sources?1
What is the data that matters?
If data is not cataloged, it is not governed!
10
Value emerges…
Confidential and Proprietary. Copyright© 2017. DATUM LLC
Data Asset:
Transaction File dd/mm/yy
Purchase $
Purchase Date
Purchase SKU
Customer Metric Tags
Purchase Activity
PI Collected
Channel = Web
Product Category
All business processes
where customers
present must have 95%
completion of
Customer Metrics
StrategyData
• Data’s role in supporting
business strategies is
established
• Provides the basis for data’s
value as an “Asset”
11
3. Define Processes
Confidential and Proprietary. Copyright© 2017. DATUM LLC
Where Is the data; how Is It Used?
• E-commerce sites
• Marketing functions
• Shipping fulfillment
• CRM
Start with known
Business
Functions
Focus on Core
Requirements
• What data is where?
• What are value drivers?
• Who gets the value?
• What are standards, controls
& metrics
12
Processes complete alignment of data,
people & processes
Confidential and Proprietary. Copyright© 2017. DATUM LLC
• Identifies business
function & Owner
• Ensures business
alignment to “value”
• Addresses order &
efficiency objectives
StrategyPeople
13
4. Add Standards & Rules to address control
objectives
Confidential and Proprietary. Copyright© 2017. DATUM LLC
• Standards provide
enterprise wide
guidance on the
implementation of
policy
• Rules implement
Standards at the
data level
StrategyGovernance
14
The “Managed” Data Ecosystem
Confidential and Proprietary. Copyright© 2017. DATUM LLC
Data Aligned
• The data required to meet
objectives
Strategy Driven
Business Focused
• Measurable Objectives
Action Oriented
• What people do
Managed
• The observable, measurable
“controls” and metrics;
evidence of business impact
15
Example: GDPR Obligation Management
Confidential and Proprietary. Copyright© 2017. DATUM LLC
GDPR
Compliance
Goals
Remediation
Management
Objectives
GDPR Obligation
Management
Processes
GDPR Remediation Standard
GDPR Risk Management
Communication Standards
Standards
GDPR Task Management
GDPR PI Owner Identification
GDPR Remediation Log Detail
GDPR Communication Template
Rules
Metrics GDPR Article 12
GDPR Article 18
GDPR Article 19
GDPR Article 16
POLICY
16
Multiple Frameworks may exist
Confidential and Proprietary. Copyright© 2018. DATUM LLC
GDPR Case Study
For GDPR, a Framework
exists for each of the
Capability Areas
specified in the Best
Practices Model
Each Framework
answers a key question
required for Audit
Resilience
Benefits of a
Governance Framework
17 Confidential and Proprietary. Copyright© 2017. DATUM LLC
Clear Line of Site between
Compliance & Controls
Business Aligned
Accountability
Easy to Communicate
Easy to Defend
Audit Defensibility
The degree to which
the organization is
ready to address the
demands of an
auditor:
• Observable
• Measureable
• Repeatable
• Robust
• Transparent
• Defensible
18
Information Value Management®
01| Discover where GDPR personal information data lives, who uses it and how it is used.
02| Connect that information to data governance processes.
03| Enable collaboration with all stakeholders across the organization.
Confidential and Proprietary. Copyright© 2018. DATUM LLC

Contenu connexe

Tendances

2 -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke
2  -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke2  -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke
2 -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke
Mayk Campelo
 
IT Governance Concept
IT Governance ConceptIT Governance Concept
IT Governance Concept
itgproduct
 

Tendances (18)

Evolution of Records Management in Law Firms
Evolution of Records Management in Law FirmsEvolution of Records Management in Law Firms
Evolution of Records Management in Law Firms
 
Privacy Operations (PrivacyOps) Framework - Feroot Privacy
Privacy Operations (PrivacyOps) Framework - Feroot PrivacyPrivacy Operations (PrivacyOps) Framework - Feroot Privacy
Privacy Operations (PrivacyOps) Framework - Feroot Privacy
 
Data governance
Data governanceData governance
Data governance
 
What CDOs Need to Know: Foundations of Data Governance
What CDOs Need to Know: Foundations of Data GovernanceWhat CDOs Need to Know: Foundations of Data Governance
What CDOs Need to Know: Foundations of Data Governance
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
Advantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environmentAdvantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environment
 
2 -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke
2  -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke2  -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke
2 -governanca_de_tic_-_uma_visao_do_mercado_gartner_-_claudio_chauke
 
Fusion Q
Fusion QFusion Q
Fusion Q
 
GRC-Xrev
GRC-XrevGRC-Xrev
GRC-Xrev
 
It governance
It governanceIt governance
It governance
 
IT Governance Presentation
IT Governance PresentationIT Governance Presentation
IT Governance Presentation
 
Article in Techsmart
Article in TechsmartArticle in Techsmart
Article in Techsmart
 
Data Governance Brochure
Data Governance BrochureData Governance Brochure
Data Governance Brochure
 
Importance of Data Governance
Importance of Data GovernanceImportance of Data Governance
Importance of Data Governance
 
Ttss consulting(1)
Ttss consulting(1)Ttss consulting(1)
Ttss consulting(1)
 
The best of data governance
The best of data governance The best of data governance
The best of data governance
 
IT Governance Concept
IT Governance ConceptIT Governance Concept
IT Governance Concept
 

Similaire à Building a Strategy customers and Auditors Love

Strata NYC 2015 - Transamerica and INFA v1
Strata NYC 2015 - Transamerica and INFA v1Strata NYC 2015 - Transamerica and INFA v1
Strata NYC 2015 - Transamerica and INFA v1
Vishal Bamba
 
Workable Enteprise Data Governance
Workable Enteprise Data GovernanceWorkable Enteprise Data Governance
Workable Enteprise Data Governance
Bhavendra Chavan
 

Similaire à Building a Strategy customers and Auditors Love (20)

Introduction to Data Governance
Introduction to Data GovernanceIntroduction to Data Governance
Introduction to Data Governance
 
Building Rules for Data Governance
Building Rules for Data GovernanceBuilding Rules for Data Governance
Building Rules for Data Governance
 
Introduction to DCAM, the Data Management Capability Assessment Model - Editi...
Introduction to DCAM, the Data Management Capability Assessment Model - Editi...Introduction to DCAM, the Data Management Capability Assessment Model - Editi...
Introduction to DCAM, the Data Management Capability Assessment Model - Editi...
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
 
How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
Is Your Agency Data Challenged?
Is Your Agency Data Challenged?Is Your Agency Data Challenged?
Is Your Agency Data Challenged?
 
Strata NYC 2015 - Transamerica and INFA v1
Strata NYC 2015 - Transamerica and INFA v1Strata NYC 2015 - Transamerica and INFA v1
Strata NYC 2015 - Transamerica and INFA v1
 
Practical Guide to Data Governance Success
Practical Guide to Data Governance SuccessPractical Guide to Data Governance Success
Practical Guide to Data Governance Success
 
Why data governance is the new buzz?
Why data governance is the new buzz?Why data governance is the new buzz?
Why data governance is the new buzz?
 
Workable Enteprise Data Governance
Workable Enteprise Data GovernanceWorkable Enteprise Data Governance
Workable Enteprise Data Governance
 
How Ally Financial Achieved Regulatory Compliance with the Data Management Ma...
How Ally Financial Achieved Regulatory Compliance with the Data Management Ma...How Ally Financial Achieved Regulatory Compliance with the Data Management Ma...
How Ally Financial Achieved Regulatory Compliance with the Data Management Ma...
 
Data Governance for Enterprises
Data Governance for EnterprisesData Governance for Enterprises
Data Governance for Enterprises
 
The Key Reason Why Your DG Program is Failing
The Key Reason Why Your DG Program is FailingThe Key Reason Why Your DG Program is Failing
The Key Reason Why Your DG Program is Failing
 
Best Practices of Data Governance.pptx
Best Practices of Data Governance.pptxBest Practices of Data Governance.pptx
Best Practices of Data Governance.pptx
 
CDMP SLIDE TRAINER .pptx
CDMP SLIDE TRAINER .pptxCDMP SLIDE TRAINER .pptx
CDMP SLIDE TRAINER .pptx
 
Data Governance: From speed dating to lifelong partnership
Data Governance: From speed dating to lifelong partnershipData Governance: From speed dating to lifelong partnership
Data Governance: From speed dating to lifelong partnership
 
Data Virtualization for Business Consumption (Australia)
Data Virtualization for Business Consumption (Australia)Data Virtualization for Business Consumption (Australia)
Data Virtualization for Business Consumption (Australia)
 
Data Governance Strategies for Public Sector
Data Governance Strategies for Public SectorData Governance Strategies for Public Sector
Data Governance Strategies for Public Sector
 
Data Governance in the Cloud: Managing Quality and Compliance
Data Governance in the Cloud: Managing Quality and ComplianceData Governance in the Cloud: Managing Quality and Compliance
Data Governance in the Cloud: Managing Quality and Compliance
 

Dernier

FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
MarinCaroMartnezBerg
 
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
amitlee9823
 
Schema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfSchema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdf
Lars Albertsson
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
shivangimorya083
 

Dernier (20)

VIP Model Call Girls Hinjewadi ( Pune ) Call ON 8005736733 Starting From 5K t...
VIP Model Call Girls Hinjewadi ( Pune ) Call ON 8005736733 Starting From 5K t...VIP Model Call Girls Hinjewadi ( Pune ) Call ON 8005736733 Starting From 5K t...
VIP Model Call Girls Hinjewadi ( Pune ) Call ON 8005736733 Starting From 5K t...
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptx
 
Zuja dropshipping via API with DroFx.pptx
Zuja dropshipping via API with DroFx.pptxZuja dropshipping via API with DroFx.pptx
Zuja dropshipping via API with DroFx.pptx
 
Carero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxCarero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptx
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
 
CebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxCebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptx
 
Smarteg dropshipping via API with DroFx.pptx
Smarteg dropshipping via API with DroFx.pptxSmarteg dropshipping via API with DroFx.pptx
Smarteg dropshipping via API with DroFx.pptx
 
(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7
(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7
(NEHA) Call Girls Katra Call Now 8617697112 Katra Escorts 24x7
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
 
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
Call Girls Hsr Layout Just Call 👗 7737669865 👗 Top Class Call Girl Service Ba...
 
Mature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxMature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptx
 
Sampling (random) method and Non random.ppt
Sampling (random) method and Non random.pptSampling (random) method and Non random.ppt
Sampling (random) method and Non random.ppt
 
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
 
Schema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfSchema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdf
 
Introduction-to-Machine-Learning (1).pptx
Introduction-to-Machine-Learning (1).pptxIntroduction-to-Machine-Learning (1).pptx
Introduction-to-Machine-Learning (1).pptx
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
100-Concepts-of-AI by Anupama Kate .pptx
100-Concepts-of-AI by Anupama Kate .pptx100-Concepts-of-AI by Anupama Kate .pptx
100-Concepts-of-AI by Anupama Kate .pptx
 
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
 
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls CP 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 

Building a Strategy customers and Auditors Love

  • 1. DGIQ 2018 JUNE 13, 2018 How to be Successful in the Post GDPR Landscape – Building a Strategy Customers & Auditors Love Confidential and Proprietary. Copyright© 2018. DATUM LLC
  • 2. 2 Agenda • Who we are • Compliance Being Compliant AND being Audit Resilient The Data Control Model; Control Elements 4 Steps to a Governance Framework • Building the Governance Framework in Information Value Management Confidential and Proprietary. Copyright© 2018. DATUM LLC
  • 3. We help the world’s leading organizations identify, organize and use data to solve problems and create opportunities. Confidential and Proprietary. Copyright© 2018. DATUM LLC3
  • 4. 4 Compliance evolves with capabilities Confidential and Proprietary. Copyright© 2018. DATUM LLC Compliance is the goal, but over time what you want is Audit Resilience Easy, Stress Free, Repeatable, Transparent, Extensible Compliance is about defining the Data Control Model that reduces risk, and creates “Audit Resilience”
  • 5. Data Control Model 5 Confidential and Proprietary. Copyright© 2018. DATUM LLC Control System Defined: Control Environment • Sets the tone for the organization Risk Assessment • Identification and analysis of relevant risks to the achievement of objectives Information and Communication • Systems or processes that support the identification, capture, and exchange of information Control Activities • Policies and procedures that help ensure management directives are carried out Monitoring-processes • Assess the quality of internal control performance over time. The configuration of the Governance Framework to align impacted data with compliance requirements An Operating Model that ensures accountability and minimizes risk For DATUM a Data Control Model sits within the Control System, and is always: https://www.aicpa.org/
  • 6. Data Control Model 6 Confidential and Proprietary. Copyright© 2018. DATUM LLC Control Elements: Data is labelled with sufficient metadata to support risk analysis and alignment to larger Control System Elements • Data Catalog / Dictionary have been configured with appropriate metadata labelling to support risk processes Control activities are completely defined • All data in scope is controlled via Rule(s) that are supported by Standards • All Composers have Owners, and Rules have execution Owners (Roles) The controls are exposed and communicated • Reports are configured in Information Value Management Monitoring process exists • Data Quality feature is activated and are monitoring Control Rules 1. Configure Governance Framework 2. Configure Operating Model 3. Identify Control Points 4. Ensure that the Control Points have all control elements implemented Steps to setting up Control Model:
  • 7. 7 Four Steps to a Governance Framework Confidential and Proprietary. Copyright© 2017. DATUM LLC What are Value Driver Goals ? What Objectives Support Goals? How do I Recognize Success? Start with Business Value!
  • 8. 8 1. Build out the Goals, Objectives & Metrics to align Value Confidential and Proprietary. Copyright© 2017. DATUM LLC StrategyAction
  • 9. 9 2. Build the Catalog Confidential and Proprietary. Copyright© 2017. DATUM LLC 2 Catalog Data: Foundational to Managing Data 3 Describe Data: Tag to align with value drivers Identify Data: What are my sources?1 What is the data that matters? If data is not cataloged, it is not governed!
  • 10. 10 Value emerges… Confidential and Proprietary. Copyright© 2017. DATUM LLC Data Asset: Transaction File dd/mm/yy Purchase $ Purchase Date Purchase SKU Customer Metric Tags Purchase Activity PI Collected Channel = Web Product Category All business processes where customers present must have 95% completion of Customer Metrics StrategyData • Data’s role in supporting business strategies is established • Provides the basis for data’s value as an “Asset”
  • 11. 11 3. Define Processes Confidential and Proprietary. Copyright© 2017. DATUM LLC Where Is the data; how Is It Used? • E-commerce sites • Marketing functions • Shipping fulfillment • CRM Start with known Business Functions Focus on Core Requirements • What data is where? • What are value drivers? • Who gets the value? • What are standards, controls & metrics
  • 12. 12 Processes complete alignment of data, people & processes Confidential and Proprietary. Copyright© 2017. DATUM LLC • Identifies business function & Owner • Ensures business alignment to “value” • Addresses order & efficiency objectives StrategyPeople
  • 13. 13 4. Add Standards & Rules to address control objectives Confidential and Proprietary. Copyright© 2017. DATUM LLC • Standards provide enterprise wide guidance on the implementation of policy • Rules implement Standards at the data level StrategyGovernance
  • 14. 14 The “Managed” Data Ecosystem Confidential and Proprietary. Copyright© 2017. DATUM LLC Data Aligned • The data required to meet objectives Strategy Driven Business Focused • Measurable Objectives Action Oriented • What people do Managed • The observable, measurable “controls” and metrics; evidence of business impact
  • 15. 15 Example: GDPR Obligation Management Confidential and Proprietary. Copyright© 2017. DATUM LLC GDPR Compliance Goals Remediation Management Objectives GDPR Obligation Management Processes GDPR Remediation Standard GDPR Risk Management Communication Standards Standards GDPR Task Management GDPR PI Owner Identification GDPR Remediation Log Detail GDPR Communication Template Rules Metrics GDPR Article 12 GDPR Article 18 GDPR Article 19 GDPR Article 16 POLICY
  • 16. 16 Multiple Frameworks may exist Confidential and Proprietary. Copyright© 2018. DATUM LLC GDPR Case Study For GDPR, a Framework exists for each of the Capability Areas specified in the Best Practices Model Each Framework answers a key question required for Audit Resilience
  • 17. Benefits of a Governance Framework 17 Confidential and Proprietary. Copyright© 2017. DATUM LLC Clear Line of Site between Compliance & Controls Business Aligned Accountability Easy to Communicate Easy to Defend Audit Defensibility The degree to which the organization is ready to address the demands of an auditor: • Observable • Measureable • Repeatable • Robust • Transparent • Defensible
  • 18. 18 Information Value Management® 01| Discover where GDPR personal information data lives, who uses it and how it is used. 02| Connect that information to data governance processes. 03| Enable collaboration with all stakeholders across the organization. Confidential and Proprietary. Copyright© 2018. DATUM LLC