Information Governance

Identifying Records for Preservation

Identifying Records for Preservation: A Practical Guide for Organisations Information is created at unprecedented scale, so organisations face a paradox. On one hand, they must retain certain records for legal, operational, or historical reasons. On the other, they must avoid excessive retention that increases risk, cost, and complexity. The ability

Read more
Who Owns Data and Information

Why the Data and Information You Use at Work Is Not Your Property In modern workplaces, information is created, shared, stored, and reused at extraordinary speed. Emails, documents, spreadsheets, instant messages, and reports flow continuously through corporate systems. Yet a lot of people seem to believe that information handled by

Read more
The Accountability Principle in DMBOK

The Accountability Principle in DMBOK: A Cornerstone of Effective Data and Information Management Accountability sits at the heart of mature data and information management. Within the DAMA-DMBOK (Data Management Body of Knowledge) framework, accountability is not an abstract ideal; it is a practical principle that underpins governance, quality, security, and

Read more
An Introduction to ISO 27001

An Introduction to ISO 27001: Strengthening Information Governance and Supporting GDPR Compliance In a data-driven world, and one where AI has been the focus of much speculation, organisations of all sizes face growing pressure to protect information, manage risk, and demonstrate accountability. Cyber threats, regulatory scrutiny, and customer expectations have

Read more
Is Your Data ROTten?

Understanding “ROT” Data: Redundant, Obsolete, and Trivial Information Organisations create, collect, and store extraordinary volumes of information every day. While some of that information is mission-critical and legally required, a significant proportion has little or no ongoing value. This unnecessary content is widely known as ROT data — information that

Read more
How to Do an Information Audit

An information audit systematically inventories, assesses and scores the information assets, flows, controls and risks in an organisation. The objective is to understand what information exists, where it lives, how it is used, and whether it is fit for purpose and subject to appropriate protection and governance. The plan below

Read more
Key Performance Indicators for Information Governance

Here is a structured set of Key Performance Indicators (KPIs) for Information Governance that cover the full information lifecycle—from creation and use to retention and destruction. Each KPI is designed to provide measurable assurance that information governance risks are being mitigated effectively.   An example of an information governance control

Read more
The Role of An Information Asset Owner

The Role of an Information Asset Owner An information asset is a body of data and information of value to the organisation. It is defined and managed as a single unit so it can be understood, shared, protected and used effectively. Grouping information into function-specific information assets can help organisations

Read more
Business Critical Data and Information

Business critical data and information is more valuable—and more vulnerable—than ever before. Yet many organisations still struggle to identify what constitutes business-critical information, let alone put the right controls in place to protect it. Without a structured approach, organisations risk reputational damage, operational disruption, and financial loss. This article outlines

Read more
What is Data Governance?

The terms data governance and information governance are often used interchangeably. However, while they are interrelated, they are not synonymous. Understanding their distinctions—and how frameworks like DAMA (Data Management Association) define and support data governance—can enable organisations to establish robust controls, reduce risk, and derive maximum value from their information

Read more
How to Improve Information and Cyber Security

Cyber security threats have grown not only in number but in complexity and precision. Ransomware, phishing, an external cyber attack and insider threats now form a persistent danger to organisations of all sizes. As digital transformation accelerates, so too must the defences that protect critical information assets. Recent cyberattacks that

Read more
Records Management: The Medium Doesn’t Matter

When it comes to records management the medium in which records are created or stored is irrelevant. This is trye for the purposes of both the UK GDPR and effective Information Governance. The core principles and obligations apply equally to all information. This is true if held in digital formats

Read more