Why enterprises need to think about data governance

Data is increasing at a rate never before witnessed. Exabytes and zettabytes of data are now regularly talked about and organisations need to deal not only with the volume of data, but also data governance.
With GDPR due to come into force in the UK on 25 May 2018 (despite Brexit), there is a real need for organisations to think and actually do something about data governance. But where should firms start?
Issues around data governance include the software costs, management consulting costs and technical implementation costs, and the promise of return on investment from data governance needs to be cast iron.
Another issue is that good data governance looks different for different industries, accrding to Dan Telling, managing partner at data consultancy Bench.
“What is good for a pharmaceutical company may be quite different to what is good for a retailer,” he says.
“It also exposes a failing in traditional approaches to data value management projects as common wisdom would ask an organisation to consider people process and technology.”
One of the biggest challenges organisations face when trying to get a handle on their data is understanding what they have, where it lives, who can access it, who has been accessing it and how has that access been used, says John Hughes, enterprise director at Varonis.
“With the upcoming GDPR regulation, organisations will be tasked with shoring up their data governance, and that includes identifying files containing sensitive data, reducing access on a need-to-know basis, monitoring access and ensuring the data is properly disposed when no longer necessary to operations,” he says.
Hughes says that a data governance strategy first starts by “turning on the lights”.
“Organisations cannot protect what they cannot see. They do this by classifying their data, assessing where it lives, who has access, how they were granted access and what they are doing with that access.”
There should also be a corporate policy in place with named and accountable data owners. “Ownership should be at board level, preferably the CEO. The policy should cover all three sides of the triangle, Availability, Integrity and Confidentiality. This should cascade down to documented procedures and guidelines. All staff should have mandatory data training,” says Manish Trevedy, an ITSM consultant at Soitron. He adds that availability should include critical systems for business to continue functioning, including links to its business continuity and disaster recovery.
Steve Murphy, SVP and general manager EMEA at Informatica says that it’s important to make sure data governance tools are unified across the enterprise so that everyone can get the best out of them.
“A single comprehensive solution will reduce running costs, decrease time-to-value and improve business outcomes. Data governance that combines technical data on the backend with a business lens on the front-end results in programme and business agility,” he says.
When it comes to implementing the newly-created data governance strategy, organisations must get a clear picture of their data landscape. “Next, they need to identify how that data is processed across business systems, where it is stored and how it travels,” says Murphy.


