Align the data governance approach with other corporate strategies and policies (corporate plan, enterprise risk management policy, ICT or digital management frameworks) and connect it strongly to the agency's Data Strategy, which every agency must have to meet the Data and Digital Government Strategy commitment and which sets out the vision and priorities for collecting, storing, sharing and using data; take account of whole-of-government obligations such as the Data and Digital Government Strategy, the Data Availability and Transparency Act 2022 and the Framework for Governance of Indigenous Data. At a minimum keep a documented approach to data risks not covered elsewhere (for example in digital systems or privacy risk management), covering where applicable the transformation of data into insights and the use of those insights, developed with feedback from people in key responsible roles and data, digital and privacy experts.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.