A few weeks ago, we explored managing risks arising from situations of a delicate nature that cannot be widely disclosed within the enterprise. Because the conventional risk management apparatus — plans, meetings, publication, review and approval — is likely to lead to inappropriate disclosure of sensitive personal information, either such risks are not managed properly, or sensitive personal information is disclosed inappropriately or even illegally.
Let's examine what we would need to do to manage these risks while maintaining an appropriate level of confidentiality.
- Confidentiality infrastructure
- Whatever infrastructure we deploy must be capable of maintaining the confidentiality of sensitive personal information. It's likely that we need a tiered structure for access to personnel-sensitive risk management information. When designing or modifying procedures for managing personnel-sensitive risks, experts in management, security, risk management, and human resources must be involved.
- Multi-part risk plans
- Because some parts of a given risk plan could contain sensitive information, those parts might have to be separated and have controlled access. The number of controlled-access components of a risk plan could depend on the individuals who present personnel-sensitive risks. For instance, in a need-to-know based system, if risks associated with two people are involved and they have different supervisors, we might need independently confidential risk plan components for the two personnel-sensitive risks.
- Access for project managers and sponsors
- For a given project, the project manager and sponsor must have full access to risk management artifacts. To develop and manage their risk plan, they might need access to personnel-sensitive information not normally available to them. This could require adjustment of existing policies.
- Confidential risk reviews for personnel-sensitive risks
- Currently, It's likely that we need a tiered
structure for controlled access
to personnel-sensitive risk
management informationrisk plan review is usually conducted without regard to personnel confidentiality. That process can continue for the enterprise-public portions of risk plans, but the personnel-sensitive components must be reviewed in a confidential manner.
- Confidential budgeting and resource allocation
- Components of project budgets and resource allocation plans intended to cover personnel-sensitive risks can remain enterprise-public, but the documents justifying these budgets and allocations are likely to be confidential and have controlled access, in parallel with the risk plans that drive them.
- Since the people involved in these procedures include some who are unfamiliar with procedures for maintaining confidentiality of personnel matters, training in personnel confidentiality is probably required. And since many of those already familiar with personnel matters are probably unfamiliar with the ways of risk management, they might also require some training.
Because the set of people with access to a given controlled-access document or decision can vary with the content of the document or decision, the requirement for confidentiality of some risk plan components can become cumbersome. But the alternatives — either non-compliance with regulations or poor risk management or both — is worse. First in this series Top Next Issue
Are your projects always (or almost always) late and over budget? Are your project teams plagued by turnover, burnout, and high defect rates? Turn your culture around. Read 52 Tips for Leaders of Project-Oriented Organizations, filled with tips and techniques for organizational leaders. Order Now!
Your comments are welcomeWould you like to see your comments posted here? rbrenHRWSQrmxuncpiGUvner@ChacQQwNfjWWBGVcpxhqoCanyon.comSend me your comments by email, or by Web form.
About Point Lookout
Thank you for reading this article. I hope you enjoyed it and found it useful, and that you'll consider recommending it to a friend.
Support Point Lookout by joining the Friends of Point Lookout, as an individual or as an organization.
Do you face a complex interpersonal situation? Send it in, anonymously if you like, and I'll give you my two cents.
More articles on Ethics at Work:
- When You're Scared to Tell the Truth
- In the project context, we need to know that whatever we're hearing from colleagues is the truth as
they see it. Yet, sometimes we shade the truth, or omit important details. Here's a list of some of
the advantages of telling the truth.
- Email Ethics
- Ethics is the system of right and wrong that forms the foundation of civil society. Yet, when a new
technology arrives, explicitly extending the ethical code seems necessary — no matter how civil
the society. And so it is with email.
- Dubious Dealings
- Negotiating contracts with outsourcing suppliers can present ethical dilemmas, even when we try to be
as fair as possible. The negotiation itself can present conflicts of interest. What are those conflicts?
- The Attributes of Political Opportunity: The Finer Points
- Opportunities come along even in tough times. But in tough times like these, it's especially important
to sniff out true opportunities and avoid high-risk adventures. Here are some of the finer points to
assist you in your detective work.
- On the Appearance of Impropriety
- Avoiding the appearance of impropriety is a frequent basis of business decisions. What does this mean,
what are the consequences of such avoiding, and when is it an appropriate choice?
Forthcoming issues of Point Lookout
- Coming August 23: Look Where You Aren't Looking
- Being blindsided by an adverse event could indicate the event's sudden, unexpected development. It can also indicate a failure to anticipate what could have been reasonably anticipated. How can we improve our ability to prepare for adverse events? Available here and by RSS on August 23.
- And on August 30: They Just Don't Understand
- When we cannot resolve an issue in open debate, we sometimes try to explain the obstinacy of others. The explanations we favor can tell us more about ourselves than they do about others. Available here and by RSS on August 30.
I offer email and telephone coaching at both corporate and individual rates. Contact Rick for details at rbrenKBidIdRPkNWvbTOAner@ChacfhOeuxMYaSuTUDmOoCanyon.com or (617) 491-6289, or toll-free in the continental US at (866) 378-5470.
Get the ebook!
Past issues of Point Lookout are available in six ebooks:
- Get 2001-2 in Geese Don't Land on Twigs (PDF, USD 11.95)
- Get 2003-4 in Why Dogs Wag (PDF, USD 11.95)
- Get 2005-6 in Loopy Things We Do (PDF, USD 11.95)
- Get 2007-8 in Things We Believe That Maybe Aren't So True (PDF, USD 11.95)
- Get 2009-10 in The Questions Not Asked (PDF, USD 11.95)
- Get all of the first twelve years (2001-2012) in The Collected Issues of Point Lookout (PDF, USD 28.99)
Are you a writer, editor or publisher on deadline? Are you looking for an article that will get people talking and get compliments flying your way? You can have 500 words in your inbox in one hour. License any article from this Web site. More info
- The Race to the South Pole: Ten Lessons for Project Managers
- On 14 December 1911, four men led by Roald
Amundsen reached the South Pole. Thirty-five days later, Robert F. Scott and four others followed. Amundsen
had won the race to the pole. Amundsen's party returned to base on 26 January 1912. Scott's party perished.
As historical drama, why this happened is interesting enough, but to organizational leaders, business
analysts, project sponsors, and project managers, the story is fascinating. Lessons abound. Read
more about this program. Here are some dates for this program:
- The Westin Virginia Beach Town Center, 4535 Commerce Street,
Virginia Beach, VA 23462: September 13,
Monthly Meeting, Hampton Roads Chapter of the Project Management Institute. Register now.
- CTCPA, 716 Brook Street,
Rocky Hill, CT 06067: September 20,
Full-day Workshop, Southern New England Chapter of the Project Management Institute. Register now.
- The Westin Virginia Beach Town Center, 4535 Commerce Street, Virginia Beach, VA 23462: September 13, Monthly Meeting, Hampton Roads Chapter of the Project Management Institute. Register now.
- Creating High Performance Virtual Teams
- Many people experience virtual teams as awkward, slow, and sometimes
frustrating. Even when most team members hail from the same nation or culture, and even when they all
speak the same language, geographic dispersion or the presence of employees from multiple enterprises
is often enough to exclude all possibility of high performance. The problem is that we lead, manage,
and support virtual teams in ways that are too much like the way we lead, manage, and support co-located
teams. In this program, Rick Brenner shows you how to change your approach to leading, managing, and
supporting virtual teams to achieve high performance using Simons' Four Spans model of high performance.
Read more about this program. Here's a date for this
- Baci Grill, 134 Berlin
Road, Berlin, CT 06416: September 19,
Monthly Meeting, Southern New England Chapter of the Project Management Institute. Register now.
- Baci Grill, 134 Berlin Road, Berlin, CT 06416: September 19, Monthly Meeting, Southern New England Chapter of the Project Management Institute. Register now.
- The Power Affect: How We Express Our Personal Power
- Many people who possess real organizational power have a characteristic demeanor. It's the way they project their presence. I call this the power affect. Some people — call them power pretenders — adopt the power affect well before they attain significant organizational power. Unfortunately for their colleagues, and for their organizations, power pretenders can attain organizational power out of proportion to their merit or abilities. Understanding the power affect is therefore important for anyone who aims to attain power, or anyone who works with power pretenders. Read more about this program.