IT‑IS Networking
Documents › White paper

Enterprise Security Committee Charter

The charter for the body that served as the city's enterprise architecture review board — written so its chair could be outvoted. Revision 5.0.

An eight-member body: six independent, non-executive managers selected for depth in enterprise design, security, standards and architecture, plus the customer relationship manager, chaired by the Technology Officer. Decisions carried by majority vote, with the membership sized so ties could not occur and independent contributors held equal weight.

A review board whose chair always wins is not a review board — it is an approval queue, and nobody outside the room honours it.

The charter also defined the governance stack beneath the committee, its ownership of risk appetite and the accept/avoid/mitigate thresholds, and its authority to review and approve the security business case and its funding — which is what gave its standards force in an estate where nothing could be mandated.

Carried to revision 5.0. Adopted as issued.