The principles of a true leader must be integral skills that are adhered to uncompromisingly. Forefront of those discussed in Snedaker’s leadership are governance, risk, and strategy.
Governance is ensuring the outlined policies and procedures for a certain task are followed. The level and complexity of IT governance is dependent on the complexity of the organization. This can be office documents such as spreadsheets going back-and-forth or the faxing between floors that is the lifeline of a healthy bureaucracy.
a custom designed enterprise workflow tool with conditional assignment and routing based on attributes associated with the task/policy The Risk factor should always be controlled by Governance, but it will depend on organizational maturity how effective it is in practice.
Risk is very broad, multi-faceted, yet consensually agreed upon as something to eliminate, if not, minimize. Asking a dozen different people to define the significant risks to an organization will net twenty different answers. The holistic goal of a leader guided by Snedaker’s principles would be performing Enterprise Risk Management, a realistic vision about the capability of a company to
There are many categories of risk, requiring differing policies and procedures, and each will contribute to Enterprise Risk in a different way. A couple examples I can think of off the top of my head are third party risk, regulatory risk, as well as risk introduced via operations, for example Security Incidents.
Businesses need to define their risk tolerance profile and aligned contingency plans. The strategy starts with what level of risk the business can afford vs cost of measures needed to mitigate the risk and resilience. The correct approach to risk is essential to ethical governance and aligning with the principles set out in the King IV Report in any business vertical, especially IT.
Governance and strategy are about putting in the work to take the risk out of the risk.