Consider the organization where you work, or *an organization where you
would like to work* if you are not currently employed.
•Create a Policy that would benefit your organization
•Suggest some controls for your policy
•Suggest an audit mechanismUse the following Format for your policy:
Use the following format for your policy:
*Overview*
You should put one or two sentences here that summarize the policy and its
purpose for management. This is typically an explanation of why the policy
exists. Don’t be too technical.
*Scope*
This is where you define who or what the policy applies to, from all
employees to only cashiers that handle cash in the front office. If it
applies to equipment, it could be all equipment, all servers, all network
connected equipment, or just company issued cell phones. Be specific.
*Policy*
This is where the policy is actually defined. Don’t be too specific, leave
that to the procedures and controls that support the policy.
For example, a password policy might state that users cannot share
passwords, passwords must be complex, help desk personnel never request
passwords, and passwords must rotate periodically. The details of good
password construction can be then put in a guideline document, instructions
for the help desk on reseting passwords can be a procedure, and that Group
Policy is used to force password changes every 60 days is a technical
control. None of that should be in the policy, but it all needs to be
properly documented and communicated to the people that need it - the
guidelines to all staff, the help desk procedure to help desk staff, and
the technical controls to the domain admins.
If you are in doubt remember that good policy statements talk about *what*
the policy is trying to accomplish, and are addressed to a wide audience.
Procedures and controls talk about *how* it is to be accomplished and are
addressed to the staff that must carry it out.
*Compliance Measurement*
Typically, this section includes the job title of the person responsible
for overseeing its implementation or the department if multiple people are
responsible, a reference to audit mechanisms, and the consequences for
failure to abide by policy.
*Definitions, Related Standards and Policies*
This section usually contains definitions of technical or ambiguous terms,
cross-references to applicable regulations, and other policies that relate
to this policy. Examples include union contracts, discipline policies, and
implementation guidelines. In our password policy example, this where
readers would be told to consult the password construction guideline
document.
*Exceptions*
If there any circumstances that might allow temporary exception to the
policy, such as during an emergency, define them here. If there is anyone
with the authority to temporarily waive the policy, they should be
identified by job title. This section is often omitted since many policies
do not allow any exceptions.
*Note*: plagiarism free and APA format.
GeneralEssayUndergraduate
Need this done?
Similar assignment?
Get it done by a vetted professional writer in as little as 1 hour.