- Your policies are out of date, disorganized, and complicated. They don’t reflect current regulations and don’t actually mitigate your organization’s current IT risks.
- Your policies are difficult to understand, aren’t easy to find, or aren’t well monitored and enforced for compliance. As a result, your employees don’t care about your policies.
- Policy issues are taking up too much of your time and distracting you from the real issues you need to address.
Our Advice
Critical Insight
A dynamic and streamlined policy approach will:
- Right-size policies to address the most critical IT risks.
- Clearly lay out a step-by-step process to complete daily tasks in compliance.
- Obtain policy adherence without having to be “the police.”
To accomplish this, the policy writer must engage their audience early to gather input on IT policies, increase policy awareness, and gain buy-in early in the process.
Impact and Result
- Develop more effective IT policies. Clearly express your policy goals and objectives, standardize the approach to employee problem solving, and write policies your employees will actually read.
- Improve risk coverage. Ensure full coverage on the risk landscape, including legal regulations, and establish a method for reporting, documenting, and communicating risks.
- Improve employee compliance. Empathize with your employees and use policy to educate, train, and enable them instead of restricting them.
Member Testimonials
After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve. See our top member experiences for this blueprint and what our clients have to say.
8.8/10
Overall Impact
$49,848
Average $ Saved
34
Average Days Saved
Client
Experience
Impact
$ Saved
Days Saved
Seattle Indian Health Board Inc
Guided Implementation
10/10
$13,700
50
No bad parts. The analyst has been super helpful and I am finding many P&P templates of use.
Geidea
Guided Implementation
8/10
N/A
N/A
Sidney is an excellent and professional analyst. He is always helpful and assist us a lot in different processes, thank you
Town of Andover, MA
Guided Implementation
7/10
N/A
N/A
Not a lot of concrete directions for me to pursue either in organizing a policy database nor in selecting policy management technology solutions
Eswatini Railway
Guided Implementation
10/10
$9,847
32
The Infotech SME was able to explain and give guidance on the best approach to review and Improve our IT Policies.. This saved us money and time ... Read More
City of Alexandria, VA
Guided Implementation
9/10
$125K
20
Nelson
Guided Implementation
8/10
$1,600
4
Insights and reminders into what would drive the need or desire to put policies in place (managing risk).
Carver County, MN
Guided Implementation
10/10
N/A
5
NorthCentral Missouri College
Guided Implementation
10/10
$2,000
20
This material and guidance were just what I needed to help me start fulfilling a core need communicated to me by my institution's President. Having... Read More
Mercury Insurance Service
Guided Implementation
9/10
$58,899
10
Dodge County
Guided Implementation
9/10
$10,000
9
Great Lakes Cheese
Guided Implementation
10/10
N/A
N/A
Extremely helpful to hear from a professional in regards to policy and framework development/implementation. There were things just from the initi... Read More
Cross Country Mortgage, Inc.
Guided Implementation
10/10
N/A
N/A
Asahi Intecc USA
Guided Implementation
10/10
$50,000
50
City Of South Fulton
Guided Implementation
7/10
N/A
N/A
Georgia State Accounting Office
Guided Implementation
9/10
N/A
5
Strong knowledge of topic. Spoke a little fast at times.
Sirtex Medical US Holdings, Inc.
Guided Implementation
10/10
$64,999
50
Best: - the epiphany moment, during the first call with Larry Fretz when he said "Remember the purpose of a policy is to reduce risk". It might so... Read More
Highland Shores Children's Aid Society
Guided Implementation
8/10
$10,000
16
Very friendly and helpful consultants, great templates and documents/resources. The worst part is there is so many good topics and resources to lea... Read More
Financial Services Regulator Authority of Ontario
Guided Implementation
10/10
N/A
N/A
IT Management & Policies
Find the right balance between risk mitigation and operational efficiency.
This course makes up part of the Strategy & Governance Certificate.
- Course Modules: 5
- Estimated Completion Time: 2-2.5 hours
- Featured Analysts:
- David Yackness, Sr. Research Director, CIO Practice
- James Alexander, SVP of Research and Advisory, CIO Practice
Workshop: Review and Improve Your IT Policy Library
Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.
Module 1: Establish & Assess
The Purpose
- Identify the pain points associated with IT policies.
- Establish the policy development process.
- Begin formulating a plan to re-design the policy network.
Key Benefits Achieved
- Establish the policy process.
- Highlight key issues and pain points regarding policy.
- Assign roles and responsibilities.
Activities
Outputs
Introduce workshop.
Identify the current pain points with policy management.
- List of issues and pain points for policy management
Establish high-level goals around policy management.
- Set of six to ten goals for policy management
Select metrics to measure achievement of goals.
- Baseline and target measured value
Create an IT policy working group (ITPWG).
- Amended steering committee or ITPWG charter
Define the scope and purpose of the ITPWG.
- Completed RACI chart
- Documented policy development process
Module 2: Assess Your Risk Landscape & Map Policies to Risks; Create a Policy Action Plan
The Purpose
- Identify key risks.
- Develop an understanding of which risks are most critical.
- Design a policy network that best mitigates those risks.
Key Benefits Achieved
- Use a risk-driven approach to decide which policies need to be written or updated first.
Activities
Outputs
Identify risks at a high level.
- Ranked list of IT’s risk scenarios
Assess each identified risk scenario on impact and likelihood.
- Prioritized list of IT risks (simplified risk register)
Map current and required policies to risks.
Assess policy effectiveness.
Create a policy action plan.
- Policy action plan
Select policies to be developed during workshop.
Module 3: Develop Policies
The Purpose
Outline what key features make a policy effective and write policies that mitigate the most critical IT risks.
Key Benefits Achieved
Write policies that work and get them approved.
Activities
Outputs
Define the policy audience, constraints, and in-scope and out-of-scope requirements for a policy.
Draft two to four policies
- Drafted policies
Module 4: Create a Policy Communication and Implementation Plan and Monitor & Reassess the Portfolio
The Purpose
Build an understanding of how well the organization’s value creation activities are being supported.
Key Benefits Achieved
Identify an area or capability that requires improvement.
Activities
Outputs
Review draft policies and update if necessary.
- Final draft policies
Create a policy communication plan.
- Policy communications plan
Select KPIs.
- KPI tracking log
Review root-cause analysis techniques.