| Home > Security > News > An IT Security Experts View on the Six Steps to Policy Excellence | DCS Europe Data storage and IT management: Network security, security software, network monitoring |
|
Striking the right balance between risk mitigation and the commercial demands of the business is an essential skill, which must be adapted according to the nature of your industry and the size, culture and risk appetite of your organisation. This role needs to have clear ownership at senior management level. Organisations need to take a systematic and proactive approach to risk mitigation if they are to be better prepared to satisfy evolving legal and regulatory requirements, manage the costs of compliance and realise competitive advantage. Achieving and maintaining policy compliance becomes more difficult to sustain as organisations grow, become more geographically dispersed and more highly regulated. But, it doesn’t have to be this way.
The purpose of policies and procedures
So, what is the secret for effective policy management?
Policy excellence in six steps External factors that affect policies are evolving all the time: for example technology advances may lead to information security policies and procedures becoming obsolete. Additionally, changes in the law or industry regulations require operational policies to be frequently adjusted. Some policies, such as Payment Card Industry DSS compliance, have to be re-presented and signed up to on an annual basis. Typically, most “policy” documents are lengthy, onerous and largely unreadable – many are written using complex jargon, and most contain extraneous content which would be better classed as procedures, standards, guidelines and forms. Such documents should be associated with the policy. Documents must be written using language that is appropriate for the target audience and should spell out the consequences of non-compliance. Smaller, more manageable documents are easier for an organisation to review and update, whilst also being more palatable for the intended recipients. Inadequate version control and high production costs can be reduced by automating the entire process using an electronic system.
Step Two: Distribute
Step Three: Achieve Consent A process needs to be implemented that monitors users’ response to policies. Policy distribution should be prioritised, ensuring that higher risk policies are signed off earlier by users than other lower risk documents. For example, an organisation may want to ensure that a user signs up to their Information Governance policy on the first day that they start employment, whilst having up to two weeks to sign up to the Travel & Expense Policy. Systems need to in place to grant a user two weeks to process a particular document, after which the system should automatically force the user to process it.
Step Four: Understanding
Step Five: Auditability Being able to quickly drill down for specific details in areas of poor policy compliance dramatically improves management’s ability to understand and address underlying issues.
Bringing it all together
where are you current policies? – Are the accessible to staff? For those organisations that are serious about staff reading, understanding and signing up to policies, they should consider adopting automated policy management software. This raises standards of policy compliance and provides managers with practical tools to improve policy uptake and adherence. Ultimately, policy compliance is about getting people to do the right thing, in the right way, every time. Ensuring everyone understands what is expected of them and how they are required to carry out their jobs according to corporate policies and procedures is not a new practice. Embedding an automated policy management solution into an organisation is really the only viable way to create and sustain a culture of compliance, where people understand their responsibilities and the importance of adhering to corporate standards.
Doing so empowers people to do their jobs within an acceptable governance framework rather than constrained by a rigid set of unenforceable rules. By effectively handling the policy management lifecycle you can create a firm foundation for effective risk mitigation and governance. Automation helps the benefits of policy compliance for The Board, line managers and the general workforce get to grips with policy compliance and puts forward a cost-efficient approach for achieving policy excellence.
ShareThis
Tags: Security |
| Related White Papers | ||||||
|---|---|---|---|---|---|---|
|
||||||
| Related News | ||||
|---|---|---|---|---|
|
||||
| Read more News » |
| Related DCS TV | ||||||
|---|---|---|---|---|---|---|
|
||||||
| Related Web Exclusives | ||||
|---|---|---|---|---|
|
||||
| Related Magazine Articles | |
|---|---|
|
|
| White Paper Downloads |
|---|
|
Keep up to date with the latest industry products, services and technologies from the world's leading IT companies.
|
| Recruitment |
|---|
|
Latest IT jobs from leading companies.
|