7. Operations: Monitoring and Auditing Program Performance Flashcards
What should metrics reflect?
Currency and value to the organization
*Must add value by by accurately reflecting the state of business objectives and goals
What should currency and value metrics be like?
- Simple
- Quantifiable
- Easy to use
- Correlated to
- Business performance
- Operational goals
- Technical outcomes
- Regulatory guidelines
What is good practice when it comes to measurement systems?
- Easy to understand
- Repeatable
- Reflective of relevant indicators to the organization
What is a metric?
A unit of measurement that should be as objective as possible and provide data that helps to answer specific questions about the business operations
What is the difference between an objective and a goal?
Objective - broad based
Goal - measurable, easy to understand, relevant and useful to the organization
In what ways can organizations implement privacy objectives?
Metrics that
- Normalize the privacy concepts - allow for meaningful privacy regime conversations
- Eliminate terminology and jargon - allow for decisions at an operational level
- Not based on a specific technology or application
- Advance the maturity of the privacy program and operations
What should metrics demonstrate?
- Compliance
- Program success
- Program maturity
- Resource utilization
- Return on investment
- Process improvement
What do metrics highlight?
Trends, issues, and gaps.
What do the right metrics allow for?
The development of KPIs that assist the organization in setting and tracking multiple objectives and goals.
What are general industry guidelines for metrics?
- Identify the privacy goals critical to the organization (why and to whom)
- Develop the formal intent of the metric based on goals
- Apply practical measurement to qualify the output (success, failure, goal met etc.)
- Evaluate and categorize metric data
What should metrics reflect?
- Compliance
- Data-driven decision making
- Overall impact of the privacy program
*Practical privacy program management in creating and maintaining compliance factors
What is the role of the metric owner?
Evangelize the purpose and intent of the metric.
What should a metric owner know?
- What is critical about the metric
AND
- How it fits into the business objective
What is the responsibility of the metric owner?
Monitoring process performance, variance, and undertaking visualizations
Preforming regular reviews to determine if the metric is still effective and provides value
What is one of the easiest statistical methods for data reporting?
Trend analysis - spot patterns in the information as viewed over a period.
What are examples of trending methods?
- Simple data patterns
- Fitting a trend
- Trends in random data
- Goodness of fit