CIO · IT Director

Yönetim kuruluna "veritabanı tarafında kontrol var" derken neye dayanıyorsunuz? What are you relying on when you tell the board the database side is under control?

Cevap büyük ihtimalle doğru. Sorun cevabın doğruluğu değil, neye dayandığı. The answer is probably correct. The question is not whether it is true, but what it rests on.

Bugün bu soru nasıl cevaplanıyorHow this question is answered today

Ekibinize soruyorsunuz. "Kontrol var" cevabını alıyorsunuz. Bu cevap dürüst ve büyük olasılıkla doğru.

You ask your team. You get the answer "it is under control". That answer is honest and most likely correct.

Ama o cevap bir sistemin çıktısı değil, bir kişinin bilgisidir. Aynı soruyu altı ay sonra, o kişi ekipte değilken sorduğunuzda aynı güveni alamazsınız.

But that answer is the knowledge of a person, not the output of a system. Ask the same question six months from now, when that person has moved on, and you will not get the same confidence.

Yönetim kuruluna verdiğiniz taahhüt, sizin göremediğiniz bir yerde duruyor.

The commitment you gave the board rests somewhere you cannot see.

Bu cevabın maliyetiWhat that answer costs

Her denetim öncesi kaybedilen iki hafta. Bu süre hiçbir projeye yazılmaz, hiçbir raporda görünmez.Two weeks lost before every audit. That time is charged to no project and appears in no report.
Kilit bir kişinin ayrılmasıyla kaybolan güven. Yeni kişi aynı cevabı veremez, çünkü cevap sistemde değildi.Confidence lost when a key person leaves. The new person cannot give the same answer, because the answer was never in the system.
Bir olay yaşandığında, kontrolün o gün çalıştığını gösterememek. Kontrol çalışmış olabilir; kanıtı yoktur.After an incident, being unable to show the control was working that day. It may well have been. There is no proof.
Aynı riskin farklı kişilerce farklı değerlendirilmesi. İkisi de savunulabilir, ikisi de kayıtsız.The same risk assessed differently by different people. Both defensible, neither recorded.

Yönetişim bunu nasıl değiştirirWhat governance changes

Yönetişim yeni bir süreç eklemez. Var olan iyi süreçleri kişilere bağımlı olmaktan çıkarır.

Governance does not add a process. It takes the good processes you already have out of personal dependency.

Bir değişikliğin hangi kurala göre onaylandığı, o günün kuralıyla birlikte kaydın içinde durur. Kural sonradan değişse bile eski kayıt kendi günündeki kuralla okunur.

The rule a change was approved under sits inside the record, together with the rule as it stood that day. Even after the rules change, an old record is still read against the rules of its own day.

Böylece yönetim kuruluna verdiğiniz cevap bir kişinin hafızasına değil, doğrulanabilir bir kayda dayanır.

The answer you give the board then rests on a verifiable record rather than on someone's memory.

Yönetim kuruluna "veritabanı tarafında kontrol var" derken neye dayandığınız belli olur. You know exactly what you are relying on when you tell the board the database side is under control.