Information Governance Final Research paper

profilemohan.cark
AnnotedBiblography.docx

Running Head: ANNOTATED BIBLIOGRAPHY AND LITERATURE REVIEW

ANNOTATED BIBLIOGRAPHY AND LITERATURE REVIEW 2

Annotated Bibliography

Mohan Swamy Kadali

002847465

ITS-833-A05 Information Governance

University of the Cumberlands

Annotated bibliography

Smallwood, R. F. (2013). Managing electronic records: Methods, best practices, and technologies (Vol. 592). John Wiley & Sons.

In this book, the author acknowledges Information Governance as a new concept being shaped by the industries adopting its use. IG entails the management of all information records about the business and its operations. Practicing good IG forms robust and legally defensible management of records and documents. The organization must handle its legal business records information systematically by improving how data is stored, accessed, used, shared, audited, and managed. The author covers best practices and methods from new e-records inventory formulas and development of schedule for retention enhancement to order vital records, long-term digital preservation, business process improvement, and taxonomy design. The book is timely and written when electronic records management is a significant concern for most organizations.

Kooper, M. N., Maes, R., & Lindgreen, E. R. (2011). On the governance of information: Introducing a new concept of governance to support the management of information. International journal of information management, 31(3), 195-200.

The authors present a concept of information governance in this paper, expanding the traditional, one-dimensional approach into a more generic declaration. The authors further discuss both knowledge and governance elements, beginning with the well-known foundations of IT governance. The author acknowledges that IT management is inadequate, sighting that the man agent of IT infrastructure suffers from severe limitations. Some of the shortcomings are inherent, while others are self-imposed. In this book, Koiman defines the other two approaches to information governance: co-governance and self-governance. He advocates for further studies on different varieties of information that affects information governance. For instance, with the advancement and use of networks within the organization, doubts have emerged concerning system effectiveness.

Hagmann, J. (2013). Information governance–beyond the buzz. Records Management Journal.

The author's main aim in this article was to discuss the immature concept of information governance about records information management, essential elements and challenges, and drawing on the lesson learned from organizations worldwide. In his findings, he noticed difficulties in balancing the interests of stakeholders and targeting investments that nurture the culture of Information governance. Further, he deduced that critical to success is communications in the organizations that genuinely value information as a crucial asset and would rather endure the lifecycle management of information than adopting information technology. Due to the limitations of drawing the relevance from a single case study, he advocates for further research to broaden understanding of IG programs' impacts on corporates in the world.

Aasi, P. (2018). Information Technology Governance: The Role of Organizational Culture and Structure (Doctoral dissertation, Department of Computer and Systems Sciences, Stockholm University).

In this book, Parisa argues that IG is among the significant challenges facing corporate managers in the contemporary world. He conducted various case studies and literature reviews to understand the relationship between culture and IT governance. He noticed that organizational culture forms the major influences like adopting IT programs and implementing. The studies provide empirical and theoretical contributions to the IG and how primary corporates' cultures hindered the adoption and use of IG programs. He acknowledged that the topic is new, and no research has been conducted on the issue. This was a significant limitation since his study depended on case studies and research to measure corporate culture's influence on IG. Due to the restriction, he proposed that more research is needed to add to his study's findings to understand the extent to which structure and cultural organization influence IG.

Datskovsky, G. (2010). Information governance. In Under Control (pp. 157-181). Apress.

The author used the analogy of ant and grasshopper to showcase the preparedness and lack of preparations among the organization to accept IG's full scope. Many organizations, like the grasshopper, do not prepare and expect the inevitable. They don't handle threats proactively; hope for the best. In the way, they run their business, and they are almost entirely reactive. As a valuable asset, they do not control and manage information. They look forward to the finding (the step of a legal case in which parties can oblige the documentation and other evidence to "discover" essential facts). They do not have formal checks except to not inadvertently occur, losing or divulging information necessary for the enterprise's operation. The author argues that such companies have failed in adopting information governance (IG). 

White, D., McManus, J., & Atherton, A. (2007). Governance and information governance: some ethical considerations within an expanding information society. The International Journal for Quality and Standards, 1(1), 180-192.

In his paper, Don highlights some of the significant issues the manager encounters when dealing with information issues. Some of the compliance and quality concerns related to citizens and various stakeholders are engaged either directly or indirectly with governance. He conducted a literature review on stakeholders, management, and ethics. The study revealed some governance problems such as data protection and suggested data protection implementations since IG's trust is still not developed. He advocated that firms engaging in business on a global level should respect the information society’s-oriented aspect. Individuals involved in IG should be guided by moral consideration of to what use that information is intended.

Hook, S. A. (2017). Information Governance 101

In this document, the author is much concerned with an array of challenges facing IG. The rising stock of data and the ability for profit to be extracted from it is a massive market opportunity. Unmanaged, these knowledge technology complexities will significantly interfere with an enterprise's activity and negate digital infrastructure's advantages. The challenges include; Data explosion, increased storage cost, improved risk/ complexity, cyber-attack, and regulatory scrutiny. Significant elements of IG has also been highlighted. For instance, records management and data analytics. The author has also acknowledged IG's essentials like increased efficiency, business value addition, and risk mitigation. Steps of implementing IG, as well as the challenges involved, have been discussed.

LAINE, S. (2016). Designing information governance with a focus on competence management in a knowledge-intensive project organization.

Laine's publication provides thorough information on designing information governance, focusing on competence-based in a knowledge-intensive project organization. Laine and his co-author analyzed various works of literature on IG to base their arguments. They adopted an action design methodology to understand how Sili PLC adopted IG models to increases efficiency. The study provided evidence of how implementing the design principles that view information's value can significantly benefit a company. The course noticed that various companies like Sili report negative experiences in adopting IG's first phases, but its benefits become vivid with time.

Lomas, E. (2010). Information governance: information security and access within a UK context. Records Management Journal.

Lomas acknowledges in his journal that various developers have been witnessed in the field of IG. Initially, organizations used to keep their information within their boundaries, but they store information through third parties in the cloud. However, accountability issues arise on who owns the data and assurance that a third party can't use your data without knowing. He further hails the importance of implementing the international standard on information security management system requirements (ISO 27001), ensuring accountability in the third party's information management involvement. Organizations are directed by ISO 27001 to know the value of their information before contracting vendors.

Iles, H. R. E. Information Governance: A Brief Introduction–New Zealand Focus.

In this article, Howard recognizes IG as a holistic way to manage their information compared to traditional records management. He argues that businesses rely on data to make rational decisions that foresee the future of its operations; thus, information is a significant asset for corporates. Information security should be enhanced to solve significant challenges that corporates face when their data is hacked, lost, or denied access. Finding and storing data relies on useful classification and metadata tagging of information. He concluded that corporates should use data to their advantage and understand all aspects of IG before its adoption.

Literature Review

The traditional method of information governance is a time-consuming data management method. Time is consumed when filing and arranging the information such that it will be easier to retrieve. In this method, the labeling must be done according to avoid mixing specific files with the wrong ones. According to Rasouli et al. (2019), every organization that understands the critical role of data should adopt modern information governance methods. IG in the contemporary world can in avoiding various challenges that are exhibited in the traditional information governance.

In matters of data privacy and security, organizations should prioritize securing information at all costs. There are at least two types of critically sensitive information that corporates should guard by all means (AlGhamdi & Vlahu-Gjorgievska, 2020). That is employees and customers personally identifiable information and intellectual property. Once there is a data leak or attack, the impact can be so enormous enough to make an organization go bankrupt or ruin its reputation permanently. The majority of organizations with information technology infrastructures have reported a loss due to intellectual property leak. To mitigate this data security and privacy concerns, AlGhamdi & Vlahu-Gjorgievska, (2020) advocates for organizations to invest archiving tools or vendors archiving services like a cloud. In doing so, the solution that is adopted must comply with security and privacy requirements. For example, if the organization seeking to secure its data is a healthcare facility, the Health Insurance Portability and Accountability Act (HIPAA) guidelines must be followed carefully.

Various organizations have faced problems in the management of storage. Such organizations have higher data volumes and velocity generated within a short time (Angst et al., 2017). Most data managers purchase more storage material to answer to the rising demand for data to solve this. However, the velocity and volume of data continue to rise, demanding for other solutions. Demand for storage for data has increased concerns on cost in any organization. To reduce associated storage cost, Angst et al. (2017), firms should invest in information management automation. The automated data management process removes the organization's responsibility to manage their digital data and ensures an organization has enterprise-level data management.

The value of information technology in the private sector has been acknowledged, and companies have been actively searching for solutions for years. Information management is related to the philosophy of knowledge management. The following issues are based on: how does the information travel, who owns the information, and what is the data? In the meantime, the focus is not just on records, but on all flows of company knowledge (Lajara & Maçada, 2013). An organization must have the relevant details at the right time. The absence of such information will contribute to severe and immediate financial losses. This is unique to processing firms in particular. According to Lajara & Maçada (2013), the private sector has discovered that it is not enough to convey the rules alone. Personal responsibility must, therefore, be assigned to all workers. This conduct allows workers to develop a good relationship with information governance standards in addition to delegating responsibilities. Indeed, the act of delegation is not enough, but it must also be supervised. People have to feel that the information they use is the responsibility of the owner. Efficient data mining adds to this, as it encourages you to adjust promptly, not a week later. It indicates that the information influences the activities of the company. In real-time, the use of data also leads to reducing the possibility of data manipulation.

A strong team of IT professionals is essential to ensure that an organization is protected from IG challenges. Principles from corporate governance should guide IG and IT governance. Excellent IG enhances information quality since it ensures corporates operate within the scope of laws, policies, and set regulations. Also, it improves information compliance. According to Kooper, Maes, and Lind green (2011), there is difficulty evaluating and governing information. However, through information governance, the value of information is identified and used to increase its competitive edge. The system's performance for information governance is the equilibrium assessment of both parties in the information value balance; hence, the information value in information governance must not be ignored in the framework of information governance.

References

AlGhamdi, S., & Vlahu-Gjorgievska, E. (2020). Information Security Governance Challenges and Critical Success Factors: Systematic Review. Computers & Security, 102030.

Angst, C. M., Block, E. S., D'arcy, J., & Kelley, K. (2017). When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. Accounting for the Influence of Institutional Factors in the Context of Healthcare Data Breaches (January 24, 2016). Angst, CM, Block, ES, D'Arcy, J., and Kelley, K, 893-916.

Kooper, M. N., Maes, R., & Lindgreen, E. R. (2011). On the governance of information: Introducing a new concept of governance to support the management of information. International journal of information management31(3), 195-200.

Lajara, T. T., & Maçada, A. C. G. (2013). Information governance framework: The defense manufacturing case study.

Rasouli, M. R., Eshuis, R., Grefen, P. W., Trienekens, J. J., & Kusters, R. J. (2016). Information governance in dynamic networked business process management. International Journal of Cooperative Information Systems25(04), 1740004.