Kean University DG – Data Governance Committee (DGC) Operations (SOP) 15
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines the structure, responsibilities, and operating procedures of the Data Governance Committee (DGC). The DGC provides institutional oversight for data governance, data protection, access controls, and policy enforcement.
This SOP operationalizes governance requirements defined in KU DG 01 – Data Governance & Protection Policy and supports alignment with University security, privacy, and regulatory obligations.
Scope
- The Data Governance Committee (DGC)
- Data Owners, Data Stewards, IT Security, IT Custodians, and GRC
- All University data domains and classifications
- Data-related policies, SOPs, standards, risks, and exceptions
This SOP covers meeting cadence, decision-making, documentation, escalation, and reporting.
Definitions
- Data Governance Committee (DGC) – Cross-functional body providing data governance oversight.
- Data Domain – Logical grouping of related data assets (e.g., student, HR, finance).
- Governance Decision – Formal determination impacting policy, standards, or controls.
- Quorum – Minimum of 50% of voting members required to conduct official business.
Roles & Responsibilities
Data Governance Committee (DGC)
- Oversee the data governance framework
- Approve or recommend policy and SOP updates
- Review escalated risks and exceptions
- Endorse enterprise data tools and platforms
Data Governance Lead
- Chair DGC meetings
- Set agendas and manage documentation
- Track decisions and action items
IT Security, GRC, and IT Custodians
- Provide security, risk, and technical guidance
- Support feasibility and compliance analysis
Procedure
Step 1 — Schedule Meetings
The DGC meets monthly. Additional meetings may be called by the CISO, CIO, or Data Governance Lead.
Step 2 — Distribute Agenda
Agendas are distributed at least five business days in advance and include policy updates, risks, incidents, and exception reviews.
Step 3 — Conduct Meeting & Make Decisions
Quorum is verified. Decisions are made by majority vote and action items are assigned with owners and due dates.
Step 4 — Document & Track Actions
Meeting minutes and decision logs are stored in the Governance repository within five business days.
Step 5 — Annual Review & Reporting
Policies and SOPs are reviewed annually. Quarterly and annual governance reports are produced.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU DG SOP 09 – Data Access Review
- KU DG SOP 11 – Logging, Monitoring & Alerting
- KU DG SOP 14 – Exception Management
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Identify | ID.GV – Governance | ID.GV01, ID.GV03 |
| Protect | PR.IP – Policy Implementation | PR.IP01 |
| Recover | RC.IM – Improvements | RC.IM01 |
Metrics & KPIs
- Meeting attendance rate
- Percentage of action items closed on time
- Number of governance decisions per quarter
- Percentage of policies and SOPs reviewed annually
Required Records & Storage
- DGC meeting agendas and minutes
- Decision and action item logs
- Quarterly and annual governance reports
- Policy and SOP review documentation
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Data Governance Lead | Chief Information Security Officer |
``