Time for a chief information stewardship officer

Opinion
Jan 11, 20053 mins

* The argument for the addition of another C-level executive

Thanks to Sarbanes-Oxley, information stewardship now merits attention at the highest levels of a company. Just as many organizations have a “chief compliance officer” who directly reports either to the CEO or to the chief counsel, we predict companies will evolve to a model in which a “chief information stewardship officer” oversees information protection, management, storage and retrieval, and privacy.

This individual will likely be a peer of the CFO, the head of legal, and the head of sales and marketing – in other words, a member of the CEO’s immediate cabinet. 

The operative word, however, is “evolve.” None of the organizations we work with yet have a CISO with that precise definition. In most companies, information stewardship responsibility is still fragmented among several disparate groups, including IT, legal, finance, compliance, and lines of business. This fragmentation increases the overhead – both time and cost – of responding to information requests and virtually guarantees the absence of a consistent company-wide information policy clarifying which individuals have access to what information, and under which circumstances. Finally, it increases the difficulty of legal and regulatory compliance, since there are organizational silos between those who define compliance requirements and those who implement the systems enabling compliance.

In many respects, it’s analogous to the situation of the early 1990s before IT departments began to recognize the need for a chief security officer: Most companies had an individual responsible for securing the facilities, and IT departments focused on building and managing IT infrastructure and applications. But early on, no companies had chief security officers whose responsibilities spanned facilities, infrastructure, and application security. In the mid 1990s, leading companies began appointing such individuals. It took several years for the emergence of the CSO to become widespread, and several more to determine the appropriate organizational structure, staffing, and budget for this individual.

We believe the chief information stewardship officer is emerging in the same way. Today, as noted, responsibility for information stewardship is fragmented among several groups, with no single organization assuming overall responsibility. Over time, this role and responsibilities will become more defined.

For organizations that are not yet ready or able to create a chief information stewardship officer, we recommend they establish an independent organization with representatives from multiple groups within IT (storage and security key among them), finance, legal, and compliance. Ideally this group will not be within any single group but will be actively sponsored by at least two of them (e.g. corporate IT and legal). This group should ensure both the integrity of stored data and its accessibility to authorized users, and should focus on aligning disparate efforts within various organizations (e.g. ensuring that finance and IT are aware of each others’ efforts in records retention).

For more information on information stewardship, see:

The emerging age of information stewardship

Network World Data Center Newsletter, 08/24/04

Opinion: Figuring out information stewardship

Network World, 08/09/04