Archistry

Survivability by Design™ since 2006

  • Home
  • About
    • Who Is Andrew?
    • C2T System™
    • The Agile Security System™
  • Contact
You are here: Home / Archistry Daily / When the “gold standard” turns out to be the foil wrapper off a 25¢ piece of chocolate

December 4, 2019

When the “gold standard” turns out to be the foil wrapper off a 25¢ piece of chocolate

Funnily enough, just like with governance itself, there’s both good and bad guidance about governance. Now, “bad” may be in the eye of the beholder for sure, so on this Turkey-day in the US, I’m going to briefly go hunting some sacred cows instead of flightless birds.

When I was a kid, my parents used to watch a country music show called Hee Haw. Now, as you might imagine, there was a pretty severe hillbilly vibe running through the whole show, but it was pretty highly rated, and it also happened to feature many of the hottest Country & Western music stars of the time.

And, actually…I remember it was often quite funny too.

One of the segments they used to have was 4 guys sitting around in overalls on empty milk jugs holding those old porcelain “moonshine” jugs. They’d basically do this skit where the main lyrics of the song were the same, but the main joke of the week in the middle of the song was always different. And each one of them would get a line of the weekly joke, and take a sip of mash in turn to soften the blow of the situation they were describing.

The chorus goes like this, in typical Country music fashion:

Gloom, despair, and agony on me
Deep, dark depression, excessive misery.
If it weren’t for bad luck, I’d have no luck at all.
Gloom, despair, and agony on me!

And I have to admit, when I was revisiting the hallowed references and gold standards for “good governance” when it comes to IT – and, by extension, cybersecurity – COBIT5 and the Code of Good Practice…

…I couldn’t help but hear this song run through my head.

I’d be remiss in saying there’s nothing good in COBIT5. There’s good stuff there for sure. The problem is that while it has some great raw material, it’s based on a fundamentally flawed premise that there’s a fundamental difference between management and governance, leading to lots of Railway Act, collective bargaining influence in the governance structures they describe.

While you can have good governance in spite of the general tendencies of the structures they describe, it won’t happen easily—because when they try to make things clear and easy with their suggested governance processes and role and responsibility enablers, all they really do is introduce way too many people off the street, give them chef’s whites…

…and end up with a far more cooks in the kitchen than is good for anybody.

Because the real governance relationships that are required for effective decisions are left as an exercise for the reader to untangle—not to mention the random flip-flops between the perspectives of the accountable and responsible parties with the naming conventions of the activities and outcomes.

Now on the show, they’d sing the chorus, then they’d have each of the 4 guys tell some terrible story as a verse in the middle, and then they’d finish with the chorus again. So, as the last email I’ll send about the upcoming deadline to get the December edition of the print, shipped-to-your-door Security Sanity™ newsletter that talks about a much more fundamental (and reliable) way to identify the real governance roles and responsibilities crucial to the success of your security program, I thought I’d bring the memory of my Dad along to the Thanksgiving party with my own take on the Hee Haw skit we used to watch long ago:

[Chorus]

Governance is hard, and every day’s a struggle to survive,
But never fear, help is here, in the form of COBIT5,
Yet all I find are RACI charts with lots of C’s and R’s
So when someone asks, “Who does what?” I just run and hide!

[Chorus]

Soooo…if you’d prefer to avoid the gloom, despair and agony of bloated, convoluted and committee-based governance models and make your own evaluation of a simpler alternative described in the pages of the December newsletter, then this is basically your last chance to make sure you subscribe using this link before the deadline:

https://securitysanity.com

You might not agree, or you might think I’m crazy, and all of the above are more than OK with me. But remember this: even if you don’t agree, the world needs far fewer security sheep, so sometimes even perspectives you don’t agree with will give you insight to something unique you can call your own.

Happy Thanksgiving to my friends in the US, and to all of you:

Stay safe,

ast
—
Andrew S. Townley
Archistry Chief Executive

Article by Andrew Townley / Archistry Daily / Agile Security, COBIT, Governance, RACI, Security Decisions, Security Governance

  • Email
  • LinkedIn
  • Twitter
  • YouTube

EMAIL NEWSLETTER

Want to get DAILY email tips on how to build a more effective security program so you can prove your security investments deliver value to the business?

You can always unsubscribe at any time, and we won't sell your data to third parties.

About Us

Archistry works with you to ensure what you want to achieve actually gets done, linking strategy, risk, governance and compliance to enable sustained exceptional performance Read More…

Testimonials

Andrew is a highly skilled and experienced information systems architect and consultant, which in my view is a rare thing. He is innovative in his thinking and merits the title of 'thought leader' in his specialist domains of knowledge—in particular the management of risk. Andrew has embraced SABSA as a framework and, in doing so, has been a significant contributor to extending the SABSA body of knowledge."

— John Sherwood, Chief SABSA Architect

"Fabulous person to work with. Very engaging and insightful. Extremely good technical knowledge with ability to relate concepts together and overcome differing opinions. Makes things work."

— Kevin Howe-Patterson, Chief Architect, Nortel - Wireless Data Services

"Andrew was able to bring clarity and great depth of knowledge to the table. His breadth of thinking and understanding of the business and technical issues along with a clear and effective communication style were of great benefit in moving the process forward towards a successful conclusion."

— Doug Reynolds, Product Manager, MobileAware

"Andrew is a fabulous consultant and presenter that you simply enjoy listening to, as he manages to develop highly sophisticated subjects in very understandable way. His experience is actually surprising and his thoughts leave you without considerable arguments for any doubts in the subjects he covers."

— Biljana Cerin, Director, Information Security and Compliance

Recent Posts

  • If you want better security, you’d better have a better security architecture
  • The ultimate security song to keep you focused on what you’re doing
  • Security heroes
  • There’s always a people problem
  • Putting your data flow diagrams out to pasture…for good

Looking for something else?

  • Home
  • About
  • Contact

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Copyright © 2006-2025 Archistry Incorporated or its affiliates

"Archistry", the stained glass window logo, "Pragmantix" and the Pragmantix™ logo, "Archistry Execution Framework (AEF)", "Archistry Execution Framework, Cybersecurity Edition (ACS)", "The Agile Security System", "The Agile Business System", "Baseline Perspectives", "Architecture Wall", "Archistry Execution Engine", "Renegade Security", "Renegade Security System", "Security Value Delivery System (SVDS)" "Collapse-to-Traction", "Collapse-to-Traction System", "Adaptive Trust & Governance Model (ATGM)", and "Adaptive Trust & Governance Model for Organizations (ATGM4O)" are trademarks of Archistry Incorporated or its affiliates.