Chapter 3. Policy Management

by Sumner Blount

We have looked at some of the key goals of corporate governance, and some of the associated activities. We've also seen how governance extends into the organization, and some of the key organizational attributes that help support good governance. Let's turn now to the specific activities that are used to define and enforce good governance across the organization.

Governance is an ongoing process composed of the following general responsibilities:

  1. Identifying business requirements.

  2. Creating policies to meet these requirements.

  3. Establishing controls to help ensure compliance with these policies.

  4. Monitoring and remediating compliance controls.

Each of these steps is iterative, and the whole process uses ...

Get Under Control: Governance Across the Enterprise now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.