Founded in 1807, John Wiley & Sons is the oldest independent publishing company in the United States. With offices in North America, Europe, Asia, and Australia, Wiley is globally committed to developing and marketing print and electronic products and services for our customers’ professional and personal knowledge and understanding.
The Wiley CIO series provides information, tools, and insights to IT executives and managers. The products in this series cover a wide range of topics that supply strategic and implementation guidance on the latest technology trends, leadership, and emerging best practices.
Titles in the Wiley CIO series include:
The Agile Architecture Revolution: How Cloud Computing, REST-Based SOA, and Mobile Computing Are Changing Enterprise IT by Jason Bloomberg
Architecting the Cloud: Design Decisions for Cloud Computing Service Models (SaaS, PaaS, and IaaS) by Michael Kavis
Big Data, Big Analytics: Emerging Business Intelligence and Analytic Trends for Today's Businesses by Michael Minelli, Michele Chambers, and Ambiga Dhiraj
The Chief Information Officer's Body of Knowledge: People, Process, and Technology by Dean Lane
Cloud Computing and Electronic Discovery by James P. Martin and Harry Cendrowski
Confessions of a Successful CIO: How the Best CIOs Tackle Their Toughest Business Challenges by Dan Roberts and Brian Watson
CIO Best Practices: Enabling Strategic Value with Information Technology (Second Edition) by Joe Stenzel, Randy Betancourt, Gary Cokins, Alyssa Farrell, Bill Flemming, Michael H. Hugos, Jonathan Hujsak, and Karl Schubert
The CIO Playbook: Strategies and Best Practices for IT Leaders to Deliver Value by Nicholas R. Colisto
Decoding the IT Value Problem: An Executive Guide for Achieving Optimal ROI on Critical IT Investments by Gregory J. Fell
Enterprise Performance Management Done Right: An Operating System for Your Organization by Ron Dimon
Information Governance: Concepts, Strategies and Best Practices by Robert F. Smallwood
IT Leadership Manual: Roadmap to Becoming a Trusted Business Partner by Alan R. Guibord
Leading the Epic Revolution: How CIOs Drive Innovation and Create Value Across the Enterprise by Hunter Muller
Managing Electronic Records: Methods, Best Practices, and Technologies by Robert F. Smallwood
On Top of the Cloud: How CIOs Leverage New Technologies to Drive Change and Build Value Across the Enterprise by Hunter Muller
Straight to the Top: CIO Leadership in a Mobile, Social, and Cloud-based World (Second Edition) by Gregory S. Smith
Strategic IT: Best Practices for Managers and Executives by Arthur M. Langer and Lyle Yorks
Trust and Partnership: Strategic IT Management for Turbulent Times by Robert Benson, Piet Ribbers, and Ronald Billstein
Transforming IT Culture: How to Use Social Intelligence, Human Factors, and Collaboration to Create an IT Department That Outperforms by Frank Wander
Unleashing the Power of IT: Bringing People, Business, and Technology Together, Second Edition by Dan Roberts
The U.S. Technology Skills Gap: What Every Technology Executive Must Know to Save America's Future by Gary J. Beach
Published by John Wiley & Sons, Inc., Hoboken, New Jersey.
Published simultaneously in Canada.
No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning, or otherwise, except as permitted under Section 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, Inc., 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600, or on the Web at www.copyright.com. Requests to the Publisher for permission should be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201) 748-6011, fax (201) 748-6008, or online at www.wiley.com/go/permissions.
Limit of Liability/Disclaimer of Warranty: While the publisher and author have used their best efforts in preparing this book, they make no representations or warranties with respect to the accuracy or completeness of the contents of this book and specifically disclaim any implied warranties of merchantability or fitness for a particular purpose. No warranty may be created or extended by sales representatives or written sales materials. The advice and strategies contained herein may not be suitable for your situation. You should consult with a professional where appropriate. Neither the publisher nor author shall be liable for any loss of profit or any other commercial damages, including but not limited to special, incidental, consequential, or other damages.
For general information on our other products and services or for technical support, please contact our Customer Care Department within the United States at (800) 762-2974, outside the United States at (317) 572-3993, or fax (317) 572-4002.
Wiley publishes in a variety of print and electronic formats and by print-on-demand. Some material included with standard print versions of this book may not be included in e-books or in print-on-demand. If this book refers to media such as a CD or DVD that is not included in the version you purchased, you may download this material at http://booksupport.wiley.com. For more information about Wiley products, visit www.wiley.com.
Library of Congress Cataloging-in-Publication Data:
Names: Smallwood, Robert F., 1959- author.
Title: Information governance: concepts, strategies, and best practices / Robert F. Smallwood.
Description: Second edition. | Hoboken, New Jersey: John Wiley & Sons, Inc., [2020] | Series: The Wiley CIO series | Includes index. |
Identifiers: LCCN 2019015574 (print) | LCCN 2019017654 (ebook) | ISBN 9781119491415 (Adobe PDF) | ISBN 9781119491408 (ePub) | ISBN 9781119491446 (hardback)
Subjects: LCSH: Information technology—Management. | Management information systems. | Electronic records—Management.
In the five plus years since the first edition of this book was published, information governance (IG) has matured as a discipline, and business executives and managers at leading enterprises now see IG programs as increasingly valuable. A combination of factors have created an imperative for IG programs: new, tightened regulations; the continuing deluge of Big Data; and the realization that new value can be gained from information stores using analytics have all combined to raise the profile of IG programs across the globe.
In particular, new privacy legislation, including the EU General Data Protection Regulation and the California Consumer Privacy Act, helped foster a newfound awareness of data protection issues, and organizations worldwide scrambled to inventory and gain insight into their information stores. This is often a first step in IG programs, and so the realization of IG as a needed and valued undertaking set in. Enterprises began to see IG not only as a cost center and risk reduction activity, but also as one that can add value to the enterprise, in some cases even monetizing information.
This book clarifies and codifies what IG is—and what it is not—and how to launch, control, and manage IG programs. Based on exhaustive research, and with the contributions of a number of industry pioneers and experts, this book lays out IG as a complete discipline, fully updated, including an expanded section on information privacy and new material on managing emerging technologies.
IG is a “super-discipline” of sorts in that it includes components of privacy, cybersecurity, infonomics, law and e-discovery, records management, compliance, risk management, information technology (IT), business operations, and more. This unique blend calls for a new breed of information professional who is competent across these complex disciplines. Training and education are key to IG program success, and this book provides the fundamentals as well as advanced concepts to enable organizations to train a new generation of IG professionals. The book is being used to guide IG programs at major corporations, as well as to educate graduate students in information science, computer science, law, and business.
Practitioners in the component areas of IG will find the book useful in expanding their knowledge and helping them understand the linkages between the various facets of IG. And how breaking down existing siloed approaches and leveraging information as an asset across the enterprise is critical to gaining the full benefits of IG programs.
The book strives to offer clear and concise IG concepts, actionable strategies, and proven best practices in an understandable and digestible way; a concerted effort was made to simplify language and offer examples. There are summaries of key points throughout the book and at the end of each chapter to help the reader retain key points. The text is organized into five parts: (1) IG Concepts, Definitions, and Principles; (2) IG Risk Assessment and Strategic Planning; (3) IG Key Impact Areas; (4) IG for Information Delivery Platforms, including a new section on emerging technologies; and (5) Long-Term Program Issues.
No other book offers comprehensive coverage of the complex and challenging field of IG with such clarity. Use the insights and advice contained in these pages and your IG program will have lower risks and costs, and produce better and more measurable results.
Robert Smallwood
ACKNOWLEDGMENTS
I would like to gratefully thank my colleagues for the support and generous contributions of their expertise and time, which made this updated and comprehensive text possible.
Many thanks to Lori Ashley, Jason R. Baron, Barb Blackburn, Barclay Blair, Robert Bogue, Charmaine Brooks, Baird Brueseke, Ken Chasse, Monica Crocker, Charles Dollar, Mark Driskill, Seth Early, Sam Fossett, Dr. Patricia Franks, Randy Kahn, Dennis Kessler, Darra Hoffman, Doug Laney, Paula Lederman, Reynold Leming, Barry Murphy, Robert Seiner, Teresa Schoch, Andrew Ysasi, and Bassam Zarkout.
I am truly honored to include their insightful work and owe them a great debt of gratitude.
PART ONE Information Governance Concepts, Definitions, and Principles