A subject is Governed when an identified Authority applies defined Roles, Policies, decision processes, accountability mechanisms, and oversight within an established scope.
A Governed subject has an identified governance context that can establish:
A subject can be Governed throughout:
A Governed subject can include:
subject to Governance exercised by an identified Authority through defined Roles, Policies, decision processes, accountability mechanisms, and oversight within an established scope
Adapted from:
This definition establishes the characteristics required to describe a subject as Governed. It prevents the term from serving as an undefined claim of control, approval, or oversight.
Use the following link whenever the adjective appears:
[[dido:99_annexes:annex-b-terms-and-definitions:g:governed|Governed]]
Governed differs from managed:
A subject can be managed without an adequately defined governance context.
Governed differs from controlled:
A technical control does not by itself make a subject Governed.
Governed differs from authorized:
A Governed subject is not necessarily authorized for every use.
Governed differs from approved:
A Governed subject can remain proposed, pending review, rejected, suspended, withdrawn, or retired.
Governed differs from compliant:
A Governed subject can be noncompliant. Governance establishes how the responsible Actors identify, evaluate, report, and address the noncompliance.
Governed differs from Validated:
A Governed subject is not necessarily Validated. A Validated subject is not necessarily Governed unless the Validation occurs within an established governance context.
Describing a subject as Governed requires more than the existence of a Policy. The governance context must identify, directly or through referenced information:
Governance can be centralized, distributed, or federated. Distributed or federated Governance must identify how participating Authorities coordinate:
A DIDO-TE Test Environment is Governed when the applicable governance context identifies:
The Test Environment is not Governed merely because an administrator can configure it or an access-control mechanism restricts its use. The identified Authority, Roles, Policies, decision processes, accountability mechanisms, oversight, and Evidence establish that the Test Environment is Governed.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.