Skip to article sections

Information Governance and Assurance: Reducing Risk, Promoting Policy presents an overview of information governance and assurance, explaining its complex concepts in an accessible manner and providing useful recommendations on its possible applications, implementations and integrations into most organizations. Although the book is intended for information professions and services, it would also be of interest to other parties that have interests and stakes in various information matters.

The book is divided into six main chapters. The arrangement and structure of each chapter permit the reader some flexibility in their approach and use of the book; the reader, for example, could select a specific chapter or particular parts of a chapter or a combination of chapters or their parts, on which to concentrate. But, it is advisable to read the book in its entirety because each chapter’s content is intimately interweaved with that of its predecessor, requiring the reader be familiar with the preceding details. While each chapter could be tackled selectively and separately, each functions better when taken together as a whole.

The first chapter introduces information governance and assurance, beginning with a brief but useful rationale of the important need for such policies, programs and practices. The author presents the book’s major aim of illuminating information governance and assurance “as the key to the successful integration of the information professions with the organizations which they serve, with the interests of the individual and with society at large” (p. 2). This first chapter includes short descriptions about major features, including information assets and values, locations, threats, standards, frameworks, policies and assurance. It also provides short mentions of some basic conceptual underpinnings of information governance and assurance such as distinctions between different kinds of data and information. Although the book is not intended to be a theoretical approach to the topic, these mentions can direct the reader to some of the more fundamental conceptual scaffolding and ideas upon which information governance and assurance, and its umbrella discipline of Library and Information Science, depends.

The second chapter presents the British laws and regulations of direct consequence for information governance and assurance. This focus on the UK, however, does not reduce its importance or impact. The author notes that “space does not permit discussion of equivalent legislation in other legislatures, but it will be found that similar legislation exists in a large number of countries” (p. 9), providing a short but informative list of some places with similar legal rules dealing with information governance and assurance and its various dimensions. This second chapter gives a detailed examination of the Freedom of Information Act, Data Protection Act and the Environmental Information Regulations and their major components and implications. There is also a helpful overview of the roles and responsibilities of the Information Commissioner’s Office which helps to situate the discussion on the relevant laws and regulations.

The third chapter presents a robust discussion of data quality management, outlining data quality dimensions of accuracy, completeness, consistency, timeliness and reasonability, in addition to data quality management tools of profiling, parsing and standardization, generalized cleansing, matching, enrichment, monitoring, scrubbing and integration. It also explores products and processes, data silos, master data management and data quality policies and strategies.

The fourth and fifth chapters deal with threats, risks and challenges, including security and business continuity, confronting information governance and assurance. The fourth chapter examines the internal and external threats to an organization’s information and overall information governance and assurance mandate, explaining how an organization can address such threats through legal compliance and policies. The fifth chapter examines security, risk management and business continuity management policies and strategies that could be used to combat, prevent, mitigate or minimize the challenges, risks and threats.

The final chapter, entitled Frameworks, Policies, Ethics and How It All Fits Together, presents an overarching, or meta, framework comprising separate but connected frameworks for records management, information security, business continuity, risk management and information technology management. But, it only provides a cursory examination of ethics. Information ethics is of vital concern for information governance and assurance to help understand and approach important issues, such as personal data, confidentiality, privacy, anonymity and appropriate and legitimate information behavior and use. Although the ethical principles of the UK’s Chartered Institute of Library and Information Professionals are listed, there is only a simple explanation of their meanings, goals and implications. The absence of a substantial discussion about this essential element is in marked contrast to the more detailed exploration of other main elements. The reader would benefit from, and the book would be strengthened by, a more detailed look at information ethics and their centrality for information governance and assurance with a separate and more substantial chapter of its own.

The book presents some navigational aids such as a section for acronyms and abbreviations describing those used throughout the book, and a detailed index at its end. Each chapter features its own bibliography listing cited references. There are discussion points concluding each chapter to help facilitate further reflection on the various questions and concerns raised within each chapter. Additionally, there is an entire post-chapter, entitled Discussion Points and Exercises, that provide the author’s answers to these preceding questions. This post-chapter is somewhat repetitive, and the proposed answers do not provide much new insight to these important questions.

The book provides a solid foundation on which to build practical knowledge on information governance and assurance. Although it focuses on the UK context, and would benefit by a more serious examination of information ethics, it is a useful instrument for information professionals and students interested in understanding, getting started on or strengthening information governance and assurance endeavors.

Data & Figures

Contents

Supplements

References

Languages

or Create an Account

Close Modal
Close Modal