DRAFT: Governance Standard

Tags Standard

Purpose

This standard establishes governance requirements that provide consistent, accountable, supportable, secure, and compliant technology decision-making across University-managed technology environments.

The standard defines governance requirements supporting architecture review, ownership accountability, standards compliance, lifecycle management, exception management, and continuous governance oversight.

Scope

This standard applies to:

  • Applications
  • Platforms
  • Infrastructure
  • Data products
  • Shared services
  • Cloud environments
  • Software-as-a-Service solutions
  • Integration services
  • Technology products
  • Enterprise-managed technology capabilities

Governance Principles

Accountability

Technology solutions shall have documented ownership and accountability throughout their lifecycle.

Consistency

Technology solutions shall align with approved policies, standards, architecture decisions, patterns, and governance requirements.

Transparency

Technology decisions, ownership assignments, exceptions, and governance activities should be documented and available for review.

Risk-Based Governance

Governance activities should be proportional to workload classification, data classification, operational impact, and applicable obligations.

Ownership Requirements

Technology solutions shall have identified ownership.

Ownership shall include:

  • Business ownership
  • Technical ownership
  • Operational responsibility
  • Support accountability

Ownership information shall remain current throughout the solution lifecycle.

Architecture Governance

Technology solutions shall comply with approved:

  • Policies
  • Architecture controls
  • Standards
  • Architecture decision records
  • Architecture patterns

Governance processes shall support consistent implementation of approved architecture requirements.

Architecture Review

Architecture review shall be performed when required by workload classification, platform requirements, governance requirements, or institutional risk.

Architecture review may include:

  • New regulated workloads
  • Material architecture changes
  • Exception requests
  • New technology adoption
  • Shared service onboarding

Standards Compliance

Technology solutions shall comply with applicable enterprise standards, platform standards, and regulatory standards.

Governance processes shall provide visibility into standards compliance and governance adherence.

Shared Services Governance

Enterprise shared services shall be reviewed and approved through applicable governance processes.

Governance activities shall determine:

  • Approved service classifications
  • Permitted usage scenarios
  • Operational responsibilities
  • Applicable requirements and restrictions

Lifecycle Governance

Technology solutions shall be governed throughout their lifecycle.

Lifecycle governance activities include:

  • Planning
  • Acquisition
  • Design
  • Implementation
  • Operations
  • Modification
  • Retirement

Exception Management

Technology solutions unable to comply with applicable governance requirements shall obtain approved exceptions before implementation.