« Application Lifecycle Management Tool | Main| Don't Ask a Question You Don't Want to Know the Answer To »

IT Governance – When is “Just Enough” Good Enough?

This morning I had an opportunity to view an on demand Webinar by Chris Byrne, IT Governance in an IBM Lotus Software Environment. Chris does a nice job presenting an overview of IT Governance and how it can help you with your compliance requirements. If you haven’t already seen it, you should check it out.

Chris uses the phrase: “Just good enough”, which seems awfully close to Teamstudio’s tagline, “Just Enough Governance for Notes”. Intentional or not, I think Chris misses the point we are trying to make with “just enough governance”. He says that “Just good enough can and will put you at risk.” But isn’t “just good enough” by definition, good enough??? If you are doing something that will put you at risk, then I would say that’s NOT good enough.

I do think there is an immediate reaction to the phrase “just enough” (or “just good enough”) to mean the absolute bare minimum required. Much to my chagrin, my step daughter attended just enough phys-ed classes in high school to receive a passing grade. To her, this was good enough. (Can you tell she hated this class?)

(read more)
While it’s sometimes harder to quantify what “just enough” means, this is probably the easiest to think about in light of what it might mean to do way too much. Care must be taken to strike the right balance. Consider….
  • Taking a friend’s word for what you need to stay SOX compliant – NOT good enough.
  • Ensuring that 50 “in-scope” applications in your company are under tight IT Governance control, out of a possible 2,000 applications – Good enough. After all, do you really need to have the softball roster under IT Governance?
Goal: I have a 100 mile round trip commute. I am looking for the safest vehicle for my commute. I can:
  • Buy a Smart Car – Good enough?
  • Buy a 4-Runner (My current choice.) – Good enough?
  • Buy a Volvo – Good enough?
  • Buy an armored tank – Good enough?
Clearly the armored tank would be the safest, but it seems to be a bit much. However any of these choices COULD be the right choice for a particular individual and situation.

The reality is that the goals are, generally speaking, not so simple. The set of goals here would probably be more like, “Safest vehicle, best gas mileage, least costly vehicle and passes all regulations for the roads I have to travel. This sounds like the big four IT objectives, doesn’t it? (Managing risk, increased efficiencies and compliance – I’m sure aligning with the business is somewhere in there.)

So how much is enough? Unfortunately, I don’t think it’s possible to provide a single answer to this question. How much risk can your organization take on? What compliance requirements apply to your company? What is the down side of failing to comply? There are another bazillion (round numbers of course) questions that need to be answered before you really know how much governance is enough.

Figuring out how much is enough is not an easy task for sure. But once you’ve achieved “just good enough”, I’d say you’ve figured it out.

Category

Post A Comment

Feeds

Custom Button Custom Button

Category Cloud

Disclaimer

The views expressed by the authors on this blog do not necessarily reflect the views of Teamstudio, those who link to this blog, or even the author’s mother, father, sister, brother, uncle, aunt, grandparents, cousins, step relations, any other blood relative - and sometimes not even the author himself or herself.

Comments on this website are the sole responsibility of their writers and it is assumed those writers will take full responsibility, liability, and blame for any libel or litigation that results from something written in, or as a direct result of something written in, a comment. The accuracy, completeness, veracity, honesty, exactitude, factuality and politeness of comments are not guaranteed. Oh, how they are SO not guaranteed.
en-us,en;q=0.5OFFCCBot/1.0 (+http://www.commoncrawl.org/bot.html)38.107.179.213www.getthemostfromnotes.comHTTP/1.180Lotus-Domino/tsblog.nsf/D6Plinks/TBAN-7GYNPX-JustEnough