Text
SNI ISO/IEC TR 38505-2:2018 (ditetapkan oleh BSN tahun 2020) : Teknologi informasi - tata kelola TI - tata kelola data - bagian 2: implikasi dari iso/IEC 38505-1 terhadap manajemen data (ISO/IEC TR 38505-2:2018, IDT, Eng)
This document describes what the governing body of an organization expects and requires from the data management team in order to be assured that the governing principles of IT can be implemented and are being upheld for data and its use by the organization.
As the core business processes of nearly all organizations become much more reliant on data, the strategic use of that data makes its governance a priority for the governing bodies of organizations. This governance of data, as part of the overall governance of IT, aims to help the organization extract business value from the data, while operating at an acceptable level of risk and with an appropriate level of accountability of the data and its use.
The governing body is responsible for the strategy of the organization and as ISO/IEC TR 38502 states: "Managers are responsible for achieving organizational strategic objectives within the strategies and policies for use of IT set by the governing body"
However, management not only accepts the strategy as set by the governing body, it should also provide proposals and plans to assist with the creation of that strategy
The impact of data to the organization can be highlighted through its many potential uses including improving operations, altering the nature of products and services, informing and enabling employees, customers and suppliers.
Management can inform the governing body of the existing and required data management capabilities to support such data uses as well as inform them of technologies that enable new data scenarios that can impact strategic plans.
The governing body evaluates such data use options and forms a strategy regarding the use of data and the associated value, risk and constraints so it aligns to and supports the overall organizational purpose.
Utilizing the framework outlined in ISO/IEC 38505-1, this document examines the data management implications of such strategy, showing how the strategy can inform data policy. processes and controls. Those same controls and processes should also be designed to monitor the implementation of the strategy such that the governing body can be assured of the performance and conformance to the strategy.
Tidak tersedia versi lain