Kategori tanımıCategory definition

Database Operations Governance

Üretim veritabanı operasyonlarının yönetişim disiplini. Tanım, kapsam, olgunluk seviyeleri ve komşu disiplinlerle ilişkisi. The governance discipline for production database operations. Definition, scope, maturity levels and how it relates to adjacent disciplines.

Sürüm 1.0 · Okuma süresi 8 dakika · Form yok Version 1.0 · 8 minute read · No form

TanımDefinition

Database Operations Governance, üretim veritabanındaki her işlemin bilinen bir kurala göre kararlaştırıldığı, istisnasız uygulandığı ve sonradan insan emeği harcanmadan kanıtlanabildiği disiplindir.

Database Operations Governance is the discipline of making every production database action decided under a known rule, enforced without exception, and provable afterwards without human effort.

Tanım sürümü 1.0. Serbestçe alıntılanabilir. Kaynak göstermeniz yeterlidir. Definition version 1.0. Free to quote. Attribution is enough.

Tanımdaki üç ifade birbirinin yerine geçmez.

The three parts of the definition are not interchangeable.

Kararlaştırma, işlemin bir kurala bağlı olmasıdır. Onay tek başına karar değildir; onay bir imzadır, karar o imzanın hangi kurala dayandığıdır.

Deciding means the action is tied to a rule. An approval on its own is not a decision. An approval is a signature. The decision is the rule that signature rests on.

Uygulama, kuralın acele edildiğinde de geçerli olmasıdır. Kural atlanabiliyorsa kural değil, tavsiyedir.

Enforcement means the rule holds when people are in a hurry. If a rule can be skipped, it is not a rule. It is advice.

Kanıtlanabilirlik, işlemin izinin sonradan toplanmasına gerek kalmadan var olmasıdır. Sonradan toplanan kanıt, toplayan kişinin dikkatine bağlıdır.

Provability means the trail exists without anyone gathering it afterwards. Evidence gathered later depends on the attention of whoever gathers it.

Bu terim neden gerekliWhy the term is needed

Kimlik, ağ, kod ve bulut yapılandırması için yönetişim kelimesi yerleşti. Üretim veritabanı için yerleşmedi.

The word governance has settled for identity, network, code and cloud configuration. It has not settled for the production database.

Sebebi araç eksikliği değil. Veritabanı tarafında araç boldur. Eksik olan, bu araçların üstünde duran sorumluluk katmanıdır ve bu katmanı tarif eden bir kelime yoktu.

The reason is not a shortage of tools. There are plenty of tools on the database side. What is missing is the accountability layer above them, and there was no word describing that layer.

Mevcut terimExisting term Neyi kapsarWhat it covers Neyi kapsamazWhat it does not cover
Change Management Değişikliğin onayı ve takibiApproval and tracking of a change Veri erişimi, kanıt üretimi, hat dışı işlemData access, evidence generation, work outside the pipeline
Database DevOps Değişikliğin üretime taşınmasıMoving a change into production Kararın kuralı, sorumluluk, denetim kanıtıThe rule behind the decision, accountability, audit evidence
Data Governance Verinin anlamı, sahipliği, kalitesiMeaning, ownership and quality of data Veritabanı üzerindeki operasyonel işlemlerOperational actions performed on the database
GRC Kurumsal risk ve uyum çerçevesiThe enterprise risk and compliance framework Veritabanı seviyesinde uygulanabilir kuralA rule that is enforceable at database level
Database Security Yetki, şifreleme, saldırı yüzeyiPrivileges, encryption, attack surface Yetkili kişinin yaptığı işlemin yönetişimiGovernance of actions taken by an authorised person
Boşluk şurada: yetkili birinin, izinli bir işlemi, kuralsız yapması. Bu bir güvenlik ihlali değildir. Yönetişim ihlalidir. Adı yoktu. The gap sits here: an authorised person performing a permitted action without a rule. That is not a security breach. It is a governance breach. It did not have a name.

Yönetişimi ayakta tutan dört soruThe four questions that hold governance up

Bir kurumun yönetişim seviyesi, bu dört soruya ne kadar hızlı cevap verebildiğiyle ölçülür. The governance level of an organisation is measured by how quickly it can answer these four questions.

SoruQuestion Kısa adıShort name Cevap nerede olmalıWhere the answer should live
Bu işlemi kim, hangi kurala göre kararlaştırdı?Who decided this action, and under which rule? KararDecision Kaydın kendisindeIn the record itself
Kural acele edildiğinde de uygulandı mı?Was the rule enforced even when people were in a hurry? UygulamaEnforcement Sistemde, kişide değilIn the system, not in a person
Altı ay sonra bunu ne kanıtlıyor?What proves this six months from now? KanıtEvidence Bağımsız doğrulanabilir bir kayıttaIn an independently verifiable record
Üretime giden bütün yollar kapsamda mı?Are all paths into production in scope? KapsamScope Kapsam listesindeIn the scope list

Olgunluk modeliMaturity model

Beş seviye. Bir kurum aynı anda tek bir seviyededir; en zayıf halkası seviyesini belirler. Five levels. An organisation sits at one level at a time. The weakest link sets the level.

1

DoğaçlamaImprovised

Kural insanların kafasında. İşler kıdemle yürür.The rule lives in people's heads. Work moves with seniority.

Bu seviyedeysenizIf you are here
Bir işin nasıl yapılacağını sormak için belirli bir kişiyi aramanız gerekir.You have to call a specific person to learn how something is done.
Bir üst seviye içinTo move up
Kuralı yazmak değil, işleri tek bir yerden geçirmek gerekir.Not writing the rule down, but routing the work through one place.
Denetçi sorusuna cevapAnswer to the auditor
Hafızadan.From memory.
2

KoordineCoordinated

Bilet, hat ve log var ama ayrı sistemlerde.Tickets, pipelines and logs exist, in separate systems.

Bu seviyedeysenizIf you are here
Her parça çalışır, hiçbiri diğerini bilmez.Every part works and none of them knows about the others.
Bir üst seviye içinTo move up
Parçaları birbirine bağlayan ortak bir kayıt gerekir.A shared record that connects the parts.
Denetçi sorusuna cevapAnswer to the auditor
Altı sistemden ekran görüntüsü.Screenshots from six systems.
3

TanımlıDocumented

Kural yazılı ama sistem zorlamıyor. Acele edilince atlanıyor.The rule is written down but the system does not enforce it. It gets skipped under pressure.

Bu seviyedeysenizIf you are here
Süreç belgeniz var ve gerçekle arasında fark olduğunu biliyorsunuz.You have a process document and you know it differs from reality.
Bir üst seviye içinTo move up
Kuralın uygulanmasının insan iradesinden çıkması gerekir.Enforcement has to stop depending on human willingness.
Denetçi sorusuna cevapAnswer to the auditor
Yazılı süreç belgesi, uygulandığının kanıtı yok.A written process, with no proof it was followed.
4

ZorlananEnforced

Kural sistemde. İstisna gerekçesiyle kayda geçiyor.The rule lives in the system. Exceptions are recorded with their reason.

Bu seviyedeysenizIf you are here
Acil durumda bile ne olduğu kayıtlıdır.Even an emergency leaves a record of what happened.
Bir üst seviye içinTo move up
Kanıtın kaydı tutan sistemden bağımsız doğrulanabilmesi ve kapsamın tamamlanması gerekir.Evidence must be verifiable independently of the system that keeps it, and scope must be complete.
Denetçi sorusuna cevapAnswer to the auditor
Sistem kaydı.A system record.
5

KanıtlanabilirProvable

Kanıt işlemin kendisi tarafından üretiliyor ve bağımsız doğrulanabiliyor. Kapsam üretime giden bütün yolları içeriyor.Evidence is produced by the action itself and can be verified independently. Scope covers every path into production.

Bu seviyedeysenizIf you are here
Denetim hazırlığı diye bir iş kalmamıştır.Audit preparation is no longer a task.
Bu seviyede kalmak içinTo stay here
Kural seti sürümlenir, her kayıt kendi günündeki kuralı taşır.The rule set is versioned and every record carries the rule of its own day.
Denetçi sorusuna cevapAnswer to the auditor
Doğrulanabilir kanıt dosyası.A verifiable evidence file.

Seviye atlanmaz. Üç ile beş arasındaki fark yazılı kural ile zorlanan kural farkıdır ve bu fark bir belge ile kapanmaz. Levels are not skipped. The distance between three and five is the distance between a written rule and an enforced one, and no document closes it.

Kapsam: üretime giden yollarScope: the paths into production

Yönetişim kapsamının eksik kaldığı yer genelde şudur: kurumlar sadece hattı yönetir. Kapsam sekiz yoldan oluşur. Scope usually falls short in the same place: organisations govern only the pipeline. There are eight paths.

  1. 1Planlı şema değişikliğiPlanned schema change
  2. 2Planlı veri değişikliğiPlanned data change
  3. 3Üretim verisi okuma (raporlama dışı, insan talebi)Reading production data (outside reporting, on human request)
  4. 4Acil durum müdahalesiEmergency intervention
  5. 5Hat dışı elle müdahaleManual work outside the pipeline
  6. 6Geri alma işlemiRollback
  7. 7Yetki ve rol değişikliğiPrivilege and role change
  8. 8Bakım işleriMaintenance work
Bir kurum bu sekiz yoldan üçünü yönetiyorsa yönetişimi yüzde 37 değil, yok demektir. Kapsam kısmi olduğunda kanıt da kısmi olur, kısmi kanıt denetimde kanıt sayılmaz. If an organisation governs three of these eight paths, its governance is not 37 per cent. It is absent. Partial scope produces partial evidence, and partial evidence does not count as evidence in an audit.

Ne değildirWhat it is not

SözlükGlossary

Karar kuralı.Decision rule. Bir işlemin onaylanıp onaylanmayacağını belirleyen, önceden tanımlı koşul. Onaydan farkı: onay bir imzadır, karar kuralı o imzanın dayanağıdır. The predefined condition that determines whether an action is approved. Different from an approval: an approval is a signature, the decision rule is what that signature rests on.

Kural seti sürümü.Rule set version. Bir işlemin değerlendirildiği andaki kuralların bütünü. Kurallar sonradan değişse bile o işlem kendi günündeki kuralla okunur. The complete set of rules in force at the moment an action was evaluated. Even if the rules change later, that action is read against the rules of its own day.

Kanıt.Evidence. İşlemin kendisi tarafından üretilen, sonradan toplanmayan iz. Kanıtın ölçütü, üretenden bağımsız doğrulanabilmesidir. A trail produced by the action itself rather than gathered afterwards. The test of evidence is whether it can be verified independently of whoever produced it.

Kapsam.Scope. Üretim verisine ulaşan yolların tamamı. Kapsam dışı bırakılan her yol, yönetişimin tamamını geçersiz kılar. All paths that reach production data. Every path left out invalidates the governance as a whole.

Acil durum kısaltması.Emergency shortening. Kuralın kaldırılması değil, kısaltılması. Atlanan adım gerekçesiyle kayda geçer. Not the removal of the rule but its shortening. The skipped step is recorded with its reason.

Hat dışı işlem.Out of pipeline action. Otomatik hattın dışından üretime yapılan müdahale. Yaygındır, kusur değildir, kapsam dışı kalması kusurdur. An intervention made into production outside the automated pipeline. It is common and it is not a fault. Leaving it out of scope is the fault.

Bağımsız doğrulama.Independent verification. Bir kaydın, o kaydı tutan sistemin dışından kontrol edilebilmesi. The ability to check a record from outside the system that keeps it.

Sık sorulan sorularFrequently asked questions

Database Operations Governance ile Database DevOps arasındaki fark nedir?What is the difference between Database Operations Governance and Database DevOps?

Database DevOps değişikliğin üretime nasıl taşınacağını çözer. Database Operations Governance, o değişikliğin taşınmasına kimin hangi kurala göre karar verdiğini, kuralın uygulandığını ve bunun kanıtını çözer. Biri akışla, diğeri sorumlulukla ilgilidir. Aynı kurumda ikisi birlikte bulunur.Database DevOps solves how a change reaches production. Database Operations Governance solves who decided it should, under which rule, whether the rule was enforced, and what proves it. One is about flow, the other about accountability. They coexist in the same organisation.

Bu bir araç mı, bir çerçeve mi?Is this a tool or a framework?

Bir disiplindir. Araçlarla uygulanır, çerçevelerle denetlenir, ama kendisi ikisi de değildir. Bir kurum hiçbir yeni araç almadan da bu disiplinin bazı seviyelerine çıkabilir; kapsam ve bağımsız doğrulama seviyelerinde araç gerekir.It is a discipline. Tools implement it and frameworks audit it, but it is neither. An organisation can reach some levels of it without buying anything. The scope and independent verification levels require tooling.

Mevcut değişiklik yönetimi sürecimizi değiştirmemiz gerekir mi?Do we have to change our existing change management process?

Hayır. Yönetişim katmanı mevcut sürecin yerine geçmez, üstüne oturur. Bilet sisteminiz, hattınız ve log platformunuz yerinde kalır. Değişen tek şey, bunların tek bir karar ve kanıt modeline bağlanmasıdır.No. The governance layer does not replace your process, it sits above it. Your ticketing, your pipeline and your log platform stay where they are. The only change is that they now report into a single decision and evidence model.

Bunu kim sahiplenmeli?Who should own this?

Uygulamada üç aday vardır: veritabanı yönetimi, altyapı ve bilgi güvenliği. Doğru cevap kurumdan kuruma değişir, ancak sahibi olmayan yönetişim yoktur. Sahiplik belirsizse mevcut durum seviye iki veya altıdır.In practice there are three candidates: database management, infrastructure and information security. The right answer varies by organisation, but governance without an owner does not exist. If ownership is unclear, the current state is level two or below.

Küçük ekipler için de geçerli mi?Does this apply to small teams?

Evet, hatta daha kritiktir. Küçük ekipte kural genellikle tek bir kişinin kafasındadır ve o kişi ayrıldığında kural da gider. Yönetişim, ekip büyüklüğüyle değil, bilginin nerede durduğuyla ilgilidir.Yes, and arguably more so. In a small team the rule usually lives in one person's head, and it leaves when they do. Governance is not about team size. It is about where the knowledge sits.

UygulamadaIn practice

Bu boşluk kurumda nasıl görünürWhat the gap looks like inside an organisation

Aşağıdaki bölümler tanımın soyut kaldığı yerde ne olduğunu anlatır: sahadan cümleler, görünmeyen bedel, mevcut araçların sınırı ve bir ekibin sıradan günü.The sections below show what happens where the definition stays abstract: sentences from the field, the hidden cost, the limits of existing tools and an ordinary day in a team.

Görüşmelerde en çok duyduğumuz cümlelerWhat we hear most in these conversations

Hiçbir yönetici "bizde süreç yok" demiyor. Söylenen tam tersi.No executive says they have no process. What we hear is the opposite.

Süreçlerimiz varWe have processes
Jira kullanıyoruzWe use Jira
Jenkins kullanıyoruzWe use Jenkins
QRadar varWe have QRadar
Guardium varWe have Guardium
Onay mekanizmalarımız varWe have approval mechanisms
Pilot ortamlarımız varWe have pilot environments
Risk tablolarımız varWe have risk registers
Kalite prosedürlerimiz varWe have quality procedures
İç denetimimiz varWe have internal audit
PCI denetiminden geçiyoruzWe pass PCI audits
Yetki ayrılığı uyguluyoruzWe apply segregation of duties

Hepsi doğru. Hiçbiri yanlış değil. Bu listedeki her araç kendi işini iyi yapıyor.

All of it is true. None of it is wrong. Every tool on that list does its own job well.

Ama her biri farklı bir soruyu cevaplıyor ve hiçbiri diğerinin cevabını görmüyor.

But each answers a different question, and none of them sees the answer of the others.

Ne yaparWhat it does Ne yapmazWhat it does not do
Jira değişikliği takip ederJira tracks the change Kararın hangi kurala dayandığını taşımazIt does not carry the rule the decision rested on
Jenkins değişikliği üretime taşırJenkins delivers the change to production Taşınmalı mıydı sorusunu sormazIt does not ask whether it should have been delivered
QRadar olayı görürQRadar sees the event O olayın izinli olup olmadığını bilmezIt does not know whether that event was permitted
Guardium erişimi izlerGuardium monitors the access O erişimin onaylı olup olmadığını söylemezIt does not say whether that access was approved
Risk tablosu riski tanımlarThe risk register defines the risk Tanımın işlem anında uygulandığını göstermezIt does not show the definition was applied at the moment of the action
Yetki ayrılığı prosedürü kuralı yazarThe segregation of duties procedure writes the rule Acele edildiğinde kuralın uygulandığını garanti etmezIt does not guarantee the rule held when people were in a hurry
Bu bir araç eksikliği değil. Bu araçların hiçbirinin sahiplenmediği bir sorumluluk.This is not a missing tool. It is a responsibility that none of these tools owns.

Veritabanı operasyonlarının görünmeyen bedeliThe hidden cost of database operations

Bu maliyetin bütçede bir satırı yoktur. Sadece insanların takviminde görünür.This cost has no budget line. It only shows up in people's calendars.

Planlı işPlanned work Görünmeyen işInvisible work
  1. 1Denetimden önceki iki hafta. Ekran görüntüsü toplanır, e-posta aranır, "bunu kim onaylamıştı" diye sorulur.The two weeks before an audit. Screenshots are gathered, inboxes are searched, someone asks who approved this.
  2. 2Tatile çıkamayan kıdemli veritabanı yöneticisi. Sürüm sırasını bilen tek kişi odur.The senior database administrator who cannot take leave. They are the only one who knows the release order.
  3. 3Onaylanmış ama hiç çalıştırılmamış değişiklik. Üç hafta sonra fark edilir.The change that was approved and never executed. It surfaces three weeks later.
  4. 4Gece 02:10'da doğaçlama yazılan geri alma betiği. Çalıştı, bir dahakine çalışacağının garantisi yok.The rollback script written at 02:10 in the morning. It worked. Nothing guarantees it will work next time.
  5. 5Kişisel posta kutusuna giden veri çıktısı. Kimse kötü niyetli değildi, sadece kural yoktu.The data extract that went to a personal mailbox. Nobody meant harm. There was simply no rule.
  6. 6Aynı riskin iki farklı kişi tarafından iki farklı değerlendirilmesi. İkisi de savunulabilir, ikisi de kayıtsız.The same risk assessed two different ways by two different people. Both defensible, neither recorded.

Bunların hiçbiri bir olay kaydı açmaz. Hepsi normal kabul edilir. Normal olan ölçülmez, ölçülmeyen yönetilmez.

None of these opens an incident. All of them count as normal. What counts as normal is never measured, and what is never measured is never governed.

En pahalı riskler, herkesin normal saydığı işlerin içinde saklıdır.The most expensive risks hide inside the work everyone considers normal.

Mevcut araçlar neden yetmiyorWhy existing tools are not enough

Hepsi doğru soruyu cevaplıyor. Sadece bir soru eksik.They all answer the right question. There is just one question missing.

Araçlar kötü değil. Hatta çok iyiler. Sadece hepsi aynı soruyu cevaplıyor: değişiklik üretime nasıl ulaşır.

The tools are not bad. They are very good. They just all answer the same question: how does a change reach production.

Denetçi bu soruyu sormuyor.

The auditor is not asking that question.

Denetçinin sorusu şu: bu değişiklik üretime ulaşmalı mıydı, buna kim karar verdi, hangi kurala göre karar verdi, o kural o gün neydi ve bunu ne kanıtlıyor.

The auditor asks whether this change should have reached production, who decided, under which rule they decided, what that rule was on that day, and what proves it.

YönetişimGovernance
GeliştirmeDevelopment
SürümlemeVersioning
İncelemeReview
BiletTicket
HatPipeline
ÜretimProduction

Hattın dışından üretime yapılan müdahale yönetişim kapsamı dışında kalıyor. Work that reaches production outside the pipeline stays outside the governance scope.

Araç ailesiTool family Cevapladığı soruThe question it answers Açık bıraktığı soruThe question it leaves open
Şema sürümleme araçlarıSchema versioning tools Şema değişikliği nasıl sürümlenir ve uygulanırHow is a schema change versioned and applied Bu değişikliğin üretim için güvenli olduğuna kim karar verdiWho decided this change was safe for production
Karşılaştırma ve yayınlama araçlarıCompare and release tools Farkları nasıl karşılaştırıp yayınlarızHow do we diff and publish Onay anında yürürlükteki kural neydiWhat rule was in force at the moment of approval
Hat ve otomasyon araçlarıPipeline and automation tools Hattı nasıl otomatikleştiririzHow do we automate delivery Hattın dışından yapılan işlemin sahibi kimWho owns work performed outside the pipeline
Kurumsal değişiklik sistemleriEnterprise change systems Değişiklik biletini kim onayladıWho approved the change ticket Bilette yazan ile veritabanında çalışan aynı şey miDo the ticket and the database agree
Sunucu izleme ve yönetim araçlarıServer monitoring and management tools Sunucuda ne olduWhat happened on the server Olmasına izin var mıydıWas it allowed to happen
Log ve SIEM platformlarıLog and SIEM platforms Ne kaydedildiWhat was recorded Kaydın değiştirilmediğini ve bir karara bağlı olduğunu ne gösteriyorWhat shows the record is unaltered and tied to a decision
Bu araçlar "nasıl" sorusunu çözer. Yönetişim "kim, hangi kurala göre ve neyle kanıtlıyorsun" sorusudur.These tools solve the "how". Governance is the "who, under which rule, and what proves it".

Buradan çıkarılacak sonuç "bu araçları değiştirin" değil. Tam tersi.

The conclusion here is not that you should replace these tools. It is the opposite.

Jira, ServiceNow, Jenkins, Azure DevOps, Git, Guardium ve SIEM platformunuz yerinde kalır ve çalışmaya devam eder. Hiçbiri kaldırılmaz, hiçbirinin yerine geçilmez. Her biri kendi alanında sizden daha iyisini yapamayacağımız bir işi yapıyor.

Jira, ServiceNow, Jenkins, Azure DevOps, Git, Guardium and your SIEM platform all stay and keep running. None is removed and none is replaced. Each does a job in its own area that we would not do better.

Eksik olan bir araç değil. Bu araçların ürettiği kararların, kuralların ve kanıtların tek bir modelde buluşması.

What is missing is not a tool. It is a single model where the decisions, rules and evidence these tools produce come together.

DevOps ile uyum arasındaki eksik katmanThe missing layer between DevOps and compliance

DevOps akışı yönetir. Uyum kanıtı yönetir. Kararı kimse yönetmiyor.DevOps manages flow. Compliance manages proof. Nobody manages the decision.

UyumCompliance Kanıt üretirProduces proof
?
DevOps Akışı hızlandırırMakes delivery faster

DevOps ekibinin amacı akışı hızlandırmak. Bunda haklılar, işleri bu.

The DevOps team exists to make delivery faster. They are right about that. It is their job.

Uyum ekibinin amacı kanıt üretmek. Bunda da haklılar, işleri bu.

The compliance team exists to produce proof. They are right about that too. It is their job.

İkisinin arasında kimsenin sahiplenmediği bir alan var: karar.

Between the two sits an area nobody owns: the decision.

Bir değişikliğin üretime çıkıp çıkmayacağına, hangi koşulda çıkacağına, kimin durdurabileceğine ve bunun neyle kanıtlanacağına karar veren katman.

The layer that decides whether a change goes to production, under what condition, who can stop it, and what will prove it afterwards.

Bu katman olmadığında DevOps hızlanır, uyum yavaşlatır, ikisi birbirini suçlar ve gerçek karar her seferinde o anki en kıdemli kişinin sezgisine kalır.

Without that layer, DevOps accelerates, compliance slows things down, the two blame each other, and the real decision falls to whoever happens to be the most senior person in the room.

Sezgi ölçeklenmez. Denetlenemez. Devredilemez.

Judgement does not scale. It cannot be audited. It cannot be handed over.

Karar bir kişinin sezgisindeyse, o kurum yönetişim değil şans yönetiyordur.If the decision lives in one person's judgement, the organisation is not managing governance. It is managing luck.

Bir veritabanı ekibinin günüA day in a database team

Hiçbiri kural ihlali değil. Hepsi normal bir gün. Sorun tam olarak bu.None of this breaks a rule. This is a normal day. That is exactly the problem.

SaatTime Ne oluyorWhat happens Kayıtta ne varWhat the record holds
09:12
Geliştirici bir değişiklik talebi açıyor. Betik doğru. Hangi tabloya dokunduğunu anlamak için birinin bakması gerekiyor.A developer opens a change request. The script is correct. Someone has to read it to know which table it touches.
Talep metniThe request text
10:40
Onay sohbet uygulamasından geliyor. "Bende sıkıntı yok, geçebilir." Bu bir onaydır. Altı ay sonra kanıt değildir.Approval arrives in a chat app. "Looks fine to me, go ahead." That is an approval. Six months later it is not evidence.
Kayıt yokNo record
13:05
Bir yöneticiden veri talebi. Sorgu çalışıyor, sonuç bir tabloya yapıştırılıp gönderiliyor. Kimin ne aldığı hiçbir yerde yok.A manager asks for data. The query runs, the result is pasted into a spreadsheet and sent. Who took what exists nowhere.
Kayıt yokNo record
16:20
Acil durum. Onay adımı "sonra hallederiz" diye atlanıyor. Gerçekten sonra hallediliyor. Ama kayıtta bunun acil olduğu yazmıyor.An emergency. The approval step is skipped with "we will sort it out later". It is genuinely sorted out later. The record never says it was an emergency.
Kayıt yokNo record
23:40
Sürüm gecesi. Sıra önemli. Sırayı bilen tek kişi ekranda, diğerleri bekliyor.Release night. Order matters. The one person who knows the order is at the keyboard. Everyone else waits.
Kayıt yokNo record
02:10
Bir adım beklendiği gibi gitmedi. Geri alma betiği o an yazılıyor. Çalışıyor. Kimse bunu bir daha görmeyecek.One step did not go as expected. The rollback script is written on the spot. It works. Nobody will ever look at it again.
Kayıt yokNo record

Ertesi ay denetçi soruyor: 16:20'deki değişikliği kim onayladı ve hangi kurala göre acil sayıldı?

The next month the auditor asks: who approved the 16:20 change, and under which rule was it treated as an emergency?

Cevap birinin hafızasında.

The answer is in someone's memory.

Bu ekipte kimse hata yapmadı. Kurallar da vardı. Sadece kurallar sistemde değil, insanlarda yaşıyordu.Nobody in this team made a mistake. The rules existed too. They just lived in people, not in the system.

Yönetişimden sonra ne değişirWhat changes after governance

Daha fazla süreç değil. Daha az soru.Not more process. Fewer questions.

ÖnceBefore SonraAfter
"Bunu kim onayladı" sorusu e-postada aranırSomeone searches their inbox for who approved this Soru sorulmaz. Cevap kaydın kendisidir.The question is never asked. The record is the answer.
Aynı risk, değerlendiren kişiye göre farklı sonuç verirThe same risk gets a different answer depending on who assesses it Aynı risk her seferinde aynı şekilde değerlendirilirThe same risk is assessed the same way every time
Denetim hazırlığı iki haftalık bir projedirAudit preparation is a two week project Denetim hazırlığı bir dosya indirmedirAudit preparation is a file download
Acil durum, kuralın atlanması demektirAn emergency means skipping the rule Acil durum, kuralın kısalması ve gerekçesinin kayda geçmesi demektirAn emergency means shortening the rule and recording why
Sürüm sırasını bir kişi bilirOne person knows the release order Sıra sistemde tanımlıdır, kişi değişse de kalırThe order lives in the system and survives the person
Kurumsal hafıza ekipten ayrılan kişiyle birlikte giderInstitutional memory leaves with the person who leaves Kurumsal hafıza sistemde kalır, devir teslim bir belgeye dönüşmezInstitutional memory stays in the system and a handover stops being a document
Veri talebi kişisel inisiyatifle karşılanırA data request is handled on personal initiative Veri talebi kayıtlı, onaylı ve hassas alanları maskeli teslim edilirA data request is recorded, approved and delivered with sensitive fields masked
Geri alma o gece yazılırThe rollback is written that night Geri alma değişiklikle birlikte hazırlanırThe rollback is prepared together with the change
Kural değişince eski kayıtlar anlamını yitirirWhen the rule changes, old records lose their meaning Her kayıt, o gün yürürlükte olan kuralı taşırEvery record carries the rule that was in force that day
Yönetişim iş yükü eklemez. Sonradan yapılan işi ortadan kaldırır.Governance does not add work. It removes the work you do afterwards.

Kurumunuz hangi seviyedeWhich level is your organisation at

Altı soru, beş dakika. Sonuçta bir seviye ve bir sonraki adım. Six questions, five minutes. You get a level and a next step.

Bu disiplini uygulayan platform: SQL Change Guard. The platform that implements this discipline: SQL Change Guard.