Making Policy

Making Policy

One of the most common challenges we come across working with clients who have mature management systems is that they tend to grow.

There's a relationship between managing a management system, and gardening. It's not enough to just constantly plant more and let it grow, as what you end up with is an overgrown mess. Pruning and cutting out parts that are no longer appropriate is more important to a healthy system than planting everything you can think of.

Perfection is not when there's nothing more to add, it's when there's nothing that needs to be removed.

Especially when you're a small organisation like ours this sort of minimalist approach is essential to building a sustainable BMS.

What is Policy?

Part of this challenge is that many don't fully understand what policies are. A policy is a statement of intent, to guide decision-making further. It is not a step-by-step guide to achieve that intent, or a set of controls, or instructions to configure a system. Policies are high level, and while the document that contains a policy may contain other items such as processes, procedures, standards, etc., the policy part should be a high-level statement of intent.

When using templates there's an easy temptation to make sure you have a policy for everything.

Avoid that temptation. Templates are useful, but just because a template exists does not mean it has to be used.

We'll have a number of policies at Bores , but only the ones we have a definite need for.

Looking at a few of the templates that Adoptech provides the basics for (we're running through a lot more, along with our own policies and some combined, but this is already dry and listing dozens of policies won't improve that), we'll select the ones that are relevant for us to have:

  • Artificial Intelligence
  • Business Continuity and DR
  • Code of Ethics
  • Complaints
  • Visitor Security Policy

Artificial Intelligence Policy ?

Artificial intelligence isn't something we use for business activities. I make some use of it for presentations at community conferences, but our stance at the moment is that we won't use it for any company activities as there's no real benefits in what we do. So, an Artificial Intelligence policy would be pointless.

Business Continuity and DR Policy ??

Business Continuity and DR policy is a different matter. While by our nature we're pretty resilient, and small enough that the incident response team involves the entire company, there's aspects which are useful to document so that we all have exactly the same information available. On top of this, it's one of those that clients ask about in their rather hefty due-diligence questionnaires, so having it well-documented makes life easier.

Code of Ethics Policy ??????

The Code of Ethics policy is a big one for us. Since we're a family company in a very literal sense, every piece of work we do has our family name on it. Both because we're good people, and because we can't weather reputational damage due to ethical violations in the way larger organisations do (naming no names) putting our code of ethics front and centre, and making sure it is rock solid, is incredibly important. This is a must-have, even though it's not one we've ever been asked about and is usually relevant to financially-regulated companies.

Having said that, we do security and technology Due Diligence work for investment firms, and while there's no legal requirement to have a code of ethics for that sort of work, it is relevant.

Complaints Policy ??

I'm pleased to say that we've never received a client complaint.

If we did though, we want to make sure it is handled well. Given our size that's challenging, but we can at least put some good practices in place such as making sure someone relatively independent can handle it, and that it gets real attention rather than falling through the cracks.

Visitor Security Policy ?

This is one we've had conversations about with clients before.

We don't have a premises, instead we're fully distributed. As such, we go to client's offices rather than the other way around, and don't really have visitors. Since we're mainly working from personal premises, applying any visitor policy would cause more than a few problems with non-business guests.

That doesn't mean it's not a control we'll ignore later in the process, but a visitor security policy is not a reasonable or rational response given our circumstances.

Templates or Custom?

With most of the policies, they're largely based on pretty standard wording which we'll customise as needed. At this point, any policies are going into draft forms, not approved. As we go through there'll be a number of edits and changes, until we sit down to run through everything at the end.

Next, we'll be going into risk management to refine things further.

Timely article, James Bore... how would you suggest resolving conflicts in poiicy creation/change discussions?

要查看或添加评论,请登录

James Bore的更多文章

  • Boring On is Going Multimedia

    Boring On is Going Multimedia

    For those who follow my word of the day (and there are enough of you that it convinced me to keep it going) you've…

    2 条评论
  • Customer Insecurity

    Customer Insecurity

    I'm a big fan of taking lessons from one area of security to another, and a recent article about Walgreens[1] was too…

    3 条评论
  • The Thinking Trap

    The Thinking Trap

    We've all seen the posts about how AI can streamline research, accelerate papers, short-circuit decision-making, and…

    16 条评论
  • Can't Think Outside the Box Without a Box

    Can't Think Outside the Box Without a Box

    I recently had a brief conversation which gave me a full-on epiphany about why so many VC-funded, massively successful…

    8 条评论
  • Dropping the Ball

    Dropping the Ball

    It happens to everyone from time to time, both in personal and professional life, but it's much more noticeable when…

    3 条评论
  • Defining Objectives

    Defining Objectives

    Last week we talked about building the foundation of our management system - defining who we are and what we are as a…

    2 条评论
  • Starting Over

    Starting Over

    This is a bit of an experiment. We've decided to rebuild our BMS (Business Management System) from scratch.

    3 条评论
  • Informational Flak

    Informational Flak

    I did have another topic planned, but given what I'm already seeing out there this one seemed more timely…

    14 条评论
  • Deepfakes: Solving the Wrong Problem

    Deepfakes: Solving the Wrong Problem

    I first wrote about deepfakes back in 2019 in a textbook for Springer, and made a few predictions. Sadly the publishing…

    27 条评论
  • (AI)SO 42001

    (AI)SO 42001

    While this is going to be specific to 42001, there's some useful general notes about the ISO management system…

    2 条评论