About
Subscribe

Absolute governance not achievable

By Nadine Arendse
Johannesburg, 22 Feb 2012

Organisations need to understand what legislation is relevant to them and the industry within which they operate, then get expert advice to ensure .

This was the common message at the ITWeb , and Compliance summit, which was held yesterday at The Forum, in Bryanston.

Absolute governance, risk and control (GRC) is not possible, according to John Giles from Michalsons Attorneys, who highlighted that organisations should first assess what the risks are and then get advice to mitigate those risks. He added that organisations must look at the King codes for good business governance, and get a legal framework to further assist in ensuring compliance.

An information overload exists today that never did before, according to Deloitte and Touche's Daniella Kafouris. This leads to two definitions of the term 'information'. The first includes the legal and regulatory compliance issues, and the other relates to information security, Kafouris said. The reason this happens is because information can be used to identify individuals or entities, she explained.

The Protection of Personal Information Bill (POPI) forces a single view of what information is, Kafouris said. She also highlighted that, within the legislation, it's important to check what the requirements are for the industry the organisation operates in.

Organisations need to understand their industry in order to comply with legislation, before simply transacting, she said. She echoed Giles' sentiments that organisations would not be able to comply fully with legislation, but that risks can be mitigated.

Organisations need to have a tactical approach to legislation, according to Pria Chetty from PricewaterhouseCoopers (PwC). RSA's Chris Bridgland agreed, adding that there needs to be business context in everything that the organisation does.

Bridgland also noted that the problem organisations face is how to choose a GRC tool, and that this can be addressed by talking to people in a language that they understand and empowering them by asking the right questions to get a solution that works for the organisation and the environment it operates in.

Chetty added that there is a relationship between integrity and security, especially where information may be used for evidence admissibility. Speakers emphasised that although it is important to have controls in place to mitigate risks, users within organisations also need to be aware of what their rights are if they are being monitored. They noted that users must know what information is being monitored and must also give consent to their information being monitored.

Chetty emphasised that it's critical for organisations to take a bold step away from generalised and vague approaches to compliance.

For more information about ITWeb events, click here.

Share