A Kaulkin Ginsberg Publication
B-Line
11/22/2009

GARTNER III: Corporate Security Must Include 'Information Governance'

March 7, 2008
 

Information governance a critical but overlooked step in corporate security: Gartner analyst

Digg!
What's this?

More enterprises are spending more money than ever before on security solutions, yet the amount of data lost, stolen or otherwise compromised is on the rise, Gartner Research Vice President Debra Logan told an audience at the Gartner Compliance & Risk Management Conference in Chicago this week.

However, most of the data breaches aren’t from hackers or internal thieves but from bad business processes and policies. “IT security can only go so far,” Logan said.

Interactive Data - Who Are You Searching For?

Social Security Search. Bankruptcy Information. Directory Assistance (EDA). Real Estate Listings. Death Index.

Click here for more information...

Rather than relying on security alone, a company also needs to do a better job of information governance, that is, managing policies and practices regarding company information.

Gartner defines information governance as “… an accountability framework to encourage desirable behavior in the valuation, creation, storage, use, archival and deletion of information.”

Retention policies are particularly critical when it comes to e-mail, which Logan called a company’s biggest risk for information liability. E-mails are subpoenaed in 75 percent of cases dealing with corporate information. There are no legal reasons and few corporate reasons for keeping e-mail longer than three years, Logan added.

"Information retention projects should always involve house counsel or outside counsel” and IT personnel should provide guidance with their technical know-how, Logan explained.

In establishing an information governance framework, companies must determine what information is valuable, who is responsible for what information and how long information should be retained, according to Logan.

Some companies have started to implement information governance, but too often these efforts are on a department-by-department basis rather than across the entire enterprise, Logan said. For better effectiveness, information governance should be handled company wide.

Get Hired - jobsInsideARM.comHiring? Post a job - jobsInsideARM.com

Be the First To Comment

(Please read our comments policy first.)

From:
Show my identity with comment

Leave this field empty
Interested in more stories like this?
Tell us what topics you're interested in and we'll keep you posted. Enter your email address below.
Interrior Concepts
Lariat
DCM Services
TransUnion
  • DAKCS
  • West Asset Management
  • CRS
  • B-Line
  • Interactive Data

Log In

Already registered? Log in here.





Forgot your password?

Register for FREE with insideARM

Create an account with insideARM and get access to our FREE newsletters and industry reports.








 

Check all | Uncheck all

Daily news and analysis
* Recommended *
Credit cards
Healthcare
Government/Municipal
Student loans
Mortgage
Auto finance
Collection agency operations
Collection technology
Debt purchasing
Recovery management
Hiring/Staffing
Job opportunities
Leave this field empty
 

You are already registered!

The email address you've entered is already in our database, meaning you've previously registered on insideARM.com.

All you have to do is log in using the form on the left.