Sık sorulan sorularFrequently asked questions
Cevapların çoğu ürünle değil, kurumun mevcut durumuyla ilgili. Most of the answers are not about a product. They are about where the organisation stands today.
Jira süreci taşır, Jenkins teslimatı otomatikleştirir. İkisi de doğru işi yapar. Ancak ikisi de bir veritabanı işleminin riskini değerlendirmez, o riskin kurumun kuralına göre kimin sorumluluğunda olduğunu belirlemez ve kararın kanıtını üretmez.Jira carries the process, Jenkins automates delivery. Both do the right job. Neither one assesses the risk of a database operation, decides whose responsibility that risk is under the organisation's own rule, or produces evidence of the decision.
Yönetişim katmanı bu araçların yerine geçmez. Ürettikleri kararları tek bir karar ve kanıt modeline bağlar.The governance layer does not replace these tools. It connects the decisions they produce into a single decision and evidence model.
Tam tersi. Yönetişim, ekibin zaten doğru yaptığı işi görünür ve kanıtlanabilir hale getirir.The opposite. Governance makes visible and provable the work the team already does correctly.
Bugün ekip doğru kararı veriyor ama kararın izi kalmıyor. Bu, bir olay sonrasında sorgulandığında ekibi savunmasız bırakır.Today the team makes the right call, but no trace of the call remains. When questions follow an incident, that leaves the team exposed.
Kontrol riske göre işlerse yavaşlatmaz. Bugün yavaşlatan şey, her işin aynı kapıdan geçmesidir.Not if the control works by risk. What slows you down today is that every item goes through the same gate.
Riski kurumun kuralı belirlediğinde düşük riskli iş beklemez, yüksek riskli iş ise hak ettiği dikkati alır.When the organisation's rule determines the risk, low risk work does not wait, and high risk work gets the attention it deserves.
SQL Server, PostgreSQL ve Oracle. Her biri için işlemin ne yaptığı kendi dilinde çözümlenir; kurallar aynı yönetişim modeli üzerinden uygulanır.SQL Server, PostgreSQL and Oracle. What an operation actually does is analysed in each platform's own language, while the rules are applied through the same governance model.
Kural motoru betiği gerçek dilbilgisiyle ayrıştırır ve cümle yapısı üzerinden çalışır. Bu yüzden filtresiz bir UPDATE, kritik nesne üzerinde DROP veya adlandırma kuralı gibi betiğin kendisinden okunabilen her şeyi yakalar.The rule engine parses the script with a real grammar and works on sentence structure. That is why it catches everything readable from the script itself: an UPDATE without a filter, a DROP on a critical object, or a naming convention.
Bir sorgunun indeksli kolon kullanıp kullanmadığı ise betikten okunamaz; hedef veritabanının kataloğuna bakmayı gerektirir. Bu kontrol bugün kural motorunun kapsamında değildir ve veritabanı izleme araçlarının alanına girer.Whether a query uses an indexed column, however, cannot be read from the script; it requires looking at the target database catalogue. That check is not in the scope of the rule engine today and belongs to database monitoring tools.
Kurumun kendi ortamına kurulur. Veritabanlarınıza erişim sizin ağınızın içinde kalır, veri kurum dışına çıkmaz.It is installed in your own environment. Access to your databases stays inside your network, and data does not leave the organisation.
Olgun süreçler bu yaklaşımın asıl hedef kitlesidir. Soru sürecin var olup olmadığı değil, sürecin kişilerden bağımsız işleyip işlemediğidir.Mature processes are exactly who this is for. The question is not whether the process exists, but whether it runs independently of specific people.
Aynı işi iki farklı kişi aynı sonuçla değerlendiremiyorsa, süreç vardır ama henüz kurumsallaşmamıştır.If two different people cannot assess the same work with the same outcome, the process exists but has not yet become institutional.
Günlük kullanıcıları veritabanı ve uygulama ekipleridir. Kararlarını ve raporlarını ise değişiklik yönetimi, bilgi güvenliği ve iç denetim kullanır.Day to day, the database and application teams. Its decisions and reports are used by change management, information security and internal audit.
Sahipliğin tek bir yerde tanımlı olması, kullanıcı sayısından daha önemlidir.Ownership being defined in one place matters more than the number of users.
Çünkü kayıt olaydan sonra derlenmez, olayla birlikte oluşur ve kendi bütünlüğünü taşır. Denetçi kaydın sonradan değiştirilmediğini kendisi doğrulayabilir.Because the record is not assembled after the event. It forms with the event and carries its own integrity. The auditor can verify for themselves that it was not altered later.
Kanıtın değeri içeriğinden değil, kim tarafından hazırlanmadığından gelir.The value of evidence comes less from its content than from who did not prepare it.
Kurumun bugün hangi seviyede olduğunu görmekle. Altı soruluk öz değerlendirme, hangi alanın en zayıf halka olduğunu gösterir.By seeing which level the organisation is at today. A six question self assessment shows which area is the weakest link.
Yönetişimde toplam seviye, en zayıf halkaya eşittir.In governance, the overall level equals the weakest link.