Governed

A subject is Governed when an identified Authority applies defined Roles, Policies, decision processes, accountability mechanisms, and oversight within an established scope.

A Governed subject has an identified governance context that can establish:

  • The governing Authority
  • The governed subject
  • The applicable scope
  • The applicable Governance Domain
  • The applicable Organizations
  • The applicable Actors
  • The applicable Roles
  • The applicable responsibilities
  • The applicable decision rights
  • The applicable Policies
  • The applicable Governance Policies
  • The applicable approval processes
  • The applicable change-control processes
  • The applicable exception and waiver processes
  • The applicable escalation processes
  • The applicable enforcement mechanisms
  • The applicable review processes
  • The applicable accountability mechanisms
  • The required Evidence
  • The required Provenance
  • The required Traceability

A subject can be Governed throughout:

  • Creation
  • Registration
  • Classification
  • Review
  • Approval
  • Use
  • Modification
  • Versioning
  • Deployment
  • Operation
  • Validation
  • Retention
  • Supersession
  • Withdrawal
  • Retirement

A Governed subject can include:

subject to Governance exercised by an identified Authority through defined Roles, Policies, decision processes, accountability mechanisms, and oversight within an established scope

Adapted from:

This definition establishes the characteristics required to describe a subject as Governed. It prevents the term from serving as an undefined claim of control, approval, or oversight.

Use the following link whenever the adjective appears:

[[dido:99_annexes:annex-b-terms-and-definitions:g:governed|Governed]]

Governed differs from managed:

  • Governed identifies the Authority, Roles, Policies, decision rights, accountability, and oversight applicable to a subject
  • Managed concerns the activities used to plan, administer, coordinate, monitor, or control a subject

A subject can be managed without an adequately defined governance context.

Governed differs from controlled:

  • Governed establishes who possesses Authority, which Policies apply, and how decisions receive accountability and oversight
  • Controlled indicates that mechanisms constrain or direct the subject’s behavior, state, access, or modification

A technical control does not by itself make a subject Governed.

Governed differs from authorized:

  • Governed identifies the governance context applicable to the subject
  • Authorized indicates that an Actor has granted permission for a specified action or use

A Governed subject is not necessarily authorized for every use.

Governed differs from approved:

  • Governed identifies the applicable governance framework and processes
  • Approved indicates that an authorized Actor has accepted a particular proposal, state, action, or outcome

A Governed subject can remain proposed, pending review, rejected, suspended, withdrawn, or retired.

Governed differs from compliant:

  • Governed identifies the applicable Authority, Policies, responsibilities, and decision processes
  • Compliant indicates satisfaction of identified obligations or criteria

A Governed subject can be noncompliant. Governance establishes how the responsible Actors identify, evaluate, report, and address the noncompliance.

Governed differs from Validated:

  • Governed identifies the applicable governance context
  • Validated indicates that an authorized Actor has evaluated the subject against defined Validation Criteria for a stated purpose

A Governed subject is not necessarily Validated. A Validated subject is not necessarily Governed unless the Validation occurs within an established governance context.

Describing a subject as Governed requires more than the existence of a Policy. The governance context must identify, directly or through referenced information:

  • The governing Authority
  • The governed subject
  • The applicable scope
  • The responsible Roles
  • The applicable Policies
  • The applicable decision processes
  • The applicable accountability mechanisms
  • The applicable review and enforcement mechanisms
  • The Evidence required to demonstrate application of Governance
  • The required Provenance and Traceability

Governance can be centralized, distributed, or federated. Distributed or federated Governance must identify how participating Authorities coordinate:

  • Decision rights
  • Policy precedence
  • Conflicts
  • Exceptions
  • Delegations
  • Accountability
  • Evidence
  • Provenance
  • Traceability

A DIDO-TE Test Environment is Governed when the applicable governance context identifies:

  • The Organization responsible for the Test Environment
  • The governing Authority
  • The applicable Governance Domain
  • The Test Administrator, Test Operator, Evaluator, and Approval Authority Roles
  • The Policies governing creation, configuration, access, use, modification, and retirement
  • The approved Baseline
  • The Test Definitions authorized for use
  • The Resources authorized for allocation
  • The process for initiating Test Runs
  • The Validation Criteria
  • The process for assigning Verdicts
  • The process for making Validation Decisions
  • The required Evidence
  • The required Provenance
  • The required Traceability

The Test Environment is not Governed merely because an administrator can configure it or an access-control mechanism restricts its use. The identified Authority, Roles, Policies, decision processes, accountability mechanisms, oversight, and Evidence establish that the Test Environment is Governed.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/99_annexes/annex-b-terms-and-definitions/g/governed.txt
  • Last modified: 2026/08/05 01:35
  • by nick_dido