Transparency improves Governance

Summary:
The article discusses IT governance and compliance, which tends to suggest more formal and rigorous processes. The authors explore how you can agile practices with in the framework of governance and compliance rules and regulations.

IT governance and compliance is about providing transparency to senior management. If you go to the <a href="/%3Ca%20href%3D"http://www.itgi.org/">http://www.itgi.org/ " title="IT Governance Institute">IT Governance Institute</a> you can get lots of information and pointers, including to standards such as COBIT. Areas covered by governance include:</p>

Business continuity and disaster recovery

    • Regulatory compliance
    • Information governance and information security
    • IT Service Management, including ITIL and Service Level Management
    • Knowledge Management, including Intellectual Capital
    • Project governance
    • Risk management

Governance is really about good management - it is not just applicable to industry sectors with high regulatory compliance requirements. Configuration management supports most of these areas.

There are more than a few people who think that Agile processes are not appropriate for situations with strong compliance requirements - we think this view is wrong! Indeed by increasing the transparency of our development process through appropriate use of Agile methods, we can improve governance in all areas. That said, Agile methods are not going to address all of the issues listed above.

Rather than repeat other material, we would like to reference some other articles and pull out some linkages and highlights.

Scott Ambler and Per Kroll have an excellent series of articles, "Best practices for lean development governance"

A key point for us with regards to the difference for Lean or Agile developers is:

Traditional governance often focuses on command-and-control strategies which strive to manage and direct development project teams in an explicit manner. Although this is a valid and effective strategy in some situations, for many organizations this approach is akin to herding cats -- you'll put a lot of work into the governance effort but achieve very little in practice. Lean governance focuses on collaborative strategies that strive to enable and motivate team members implicitly. For example, the traditional approach to coding guidelines would be to create them and then enforce their usage through formal inspections. The lean approach would be to write the guidelines collaboratively with your programmers, explain why it is important for everyone to adopt the guidelines, and then provide tooling and support to make it as easy as possible for developers to follow those guidelines. This lean governance approach is akin to leading cats; if you grab a piece of raw fish, cats will follow you wherever you want to go.

In our article Lean-Agile Traceability: Strategies and Solutions we addressed expanded on the trust and confidence mentioned above:

    • Trustworthy Transparency is more valuable than Tiresome Traceability
    • Agile/Lean Methods do produce documentation (where it is appropriate) - but they don't produce it "by the yard" to sit on a shelf.
    • Traceability should serve the purpose of transparency, visibility and status-accounting rather than being a goal in itself.

Many organizations have found that making business intelligence tools available on people's desktops, allowing them to drill down into data, is much more powerful than producing static reports which are then circulated and that people have to wade through to find the information they need. Static tools lack flexibility and any changes must be developed - with all the lead time that implies. So we need to enable our SCM tools to make this information visible as simply and painlessly as possible. Issues that come up in this area include:

    • Licensing costs for access the tool - can you produce any form of read-only material which is cheaper than full access (and also perhaps easier to use than the full tool)?
    • Security and access control - agile methods lean towards more access rather than less access, and

About the author

Brad Appleton's picture
Brad Appleton

Brad Appleton is a software CM/ALM solution architect and lean/agile development champion at a large telecommunications company. Currently he helps projects and teams adopt and apply lean/agile development and CM/ALM practices and tools. He is coauthor of the bookSoftware Configuration Management Patterns, a columnist in The CM Journal and The Agile Journal at CMCrossroads.com, and a former section editor for The C++ Report. You can read Brad's blog at blog.bradapp.net.

About the author

Steve Berczuk's picture
Steve Berczuk

Steve Berczuk is an engineer and ScrumMaster at Humedica where he's helping to build next-generation SaaS-based clinical informatics applications. The author of Software Configuration Management Patterns: Effective Teamwork, Practical Integration, he is a recognized expert in software configuration management and agile software development. Steve is passionate about helping teams work effectively to produce quality software. He has an M.S. in operations research from Stanford University and an S.B. in Electrical Engineering from MIT, and is a certified, practicing ScrumMaster. Contact Steve at steve@berczuk.com or visit berczuk.com and follow his blog at blog.berczuk.com.

About the author

Robert Cowham's picture
Robert Cowham

Robert Cowham has long been interested in software configuration management while retaining the attitude of a generalist with experience and skills in many aspects of software development. A regular presenter at conferences, he authored the Agile SCM column within the CM Journal together with Brad Appleton and Steve Berczuk. His day job is as Services Director for Square Mile Systems whose main focus is on skills and techniques for infrastructure configuration management and DCIM (Data Center Infrastructure Management) - applying configuration management principles to hardware documentation and implementation as well as mapping ITIL services to the underlying layers.