IT Policies Help IT Staff and Reduce Liabilities

"What do you mean I can't download ... fill-in-the-blank?"complete record of all software that has been
As IT managers we are constantly berated by userspurchased for company computers and can register,
because they want to do something on their companysupport and upgrade said software.
computer that we know they shouldn't. But gettingSoftware and Hardware Disposal - Often forgotten,
users to conform to reasonable standards is a realthis policy makes sure that software/hardware is
challenge for most IT departments. We live in thedisposed of in a controlled manner. An organization
information age and with the benefits of technologymay have additional disposal requirements and/or
come the associated risks and liabilities. The sameoptions.
tools that allow productivity gains have the potential toShareware, Freeware, Public Domain, Games, Fonts,
diminish worker productivity and to expose theScreensavers and Wallpaper - This policy is important,
company to harmful content as well as regulatory andsince users often think that because software is "free"
legal liabilities.or on evaluation, it falls outside the boundaries of the
Many business executives do not yet grasp theorganization's software policies, and they are unaware
importance of protecting Information Technologyof the licensing issues surrounding these types of
assets from liabilities and need to focus on the legalitiessoftware. In many cases, these are copyrighted
surrounding IT as well as the use of IT systems bymaterials and may be used only in accordance with
employees. If you take a moment to read anythe license agreement of the publisher.
newspaper you will likely find several instances inPasswords, Security, Viruses - This policy must detail
which either by ignorance or design, employees havethe importance of passwords, how they are
used company IT assets in a way that puts theadministered, how often they are changed and of
company at risk, or worse: gets them in serious hotwhat characters they should consist. Stress the
water.importance of user's keeping their passwords safe.
So why aren't companies focusing on these risks? InDetail how the organization protects itself against virus
my experience a large part of the problem lies in staffattack. The omnipresence of the Internet and
not knowing how to begin writing acceptable useweb-based applications can open backdoors to the
policies for IT systems. Then add to that hurdle thecorporate IT infrastructure. Employees can either
facts of constrained budgets, limited staff and that awillfully or by neglect expose the organization to rapidly
typical IT manager will likely assume the company legalspreading viruses or other malicious and harmful code
department will advise of any need to change policiesby accessing or downloading files of unknown origin.
or the management of IT assets. And at the sameData Protection - Detail the importance of your
time, management is occupied with running theorganization's data. Also, cover how employees must
business and assumes that IT and legal will managetreat specific types of data, such as customer
any issues related to these assets. Unfortunately, theinformation, research material, legal documents and
legal department typically understands the broaderrecords, etc. Because each organization will guard
laws but does not necessarily focus on day-to-day ITparticular information based upon the type of business,
operational issues.explore each topic in detail within the organization.
Liabilities will be reduced if the focus of IT, legal and theInternet, Instant Messaging, P2P Software - Most
business side of the house are pulled together, to putorganizations in today's business climate will have
into place reasonable and effective policies,some type of Internet policy likely covering areas such
procedures, disciplinary standards and company-wideas pornography, picture and media files (GIF, BMP,
educational programs. In addition, in doing so will give ITPCX, JPEG, MP3, etc.), personal use and more.
managers a defendable position against those usersCompanies must also be concerned with the ease of
who berate them! Policies and procedures are a criticalobtaining software of all types from the Internet.
first step in protecting the organization's vital enterpriseE-mail - As with the Internet, there are many liabilities
IT assets. These same policies, while protecting assetssurrounding e-mail use. Companies should be aware of
and assisting IT staff in managing user "problems," arethe pitfalls of improper data protection, defamatory
also used as a defense against potential legal liabilities.comments, inappropriate bandwidth usage, viruses, etc.
A legally compliant IT department must addressIncreasingly, subject matter considered inappropriate
several areas of concern, such as software licensefor consumption or distribution within an organization is
compliance, the appropriate use of the Internet andreceived, forwarded, mishandled, etc. The type of
e-mail, data protection, privacy and more.website content that is inappropriate within an
Though proper software licensing is the mostorganization is also unsuitable content for an e-mail.
frequently considered topic of IT compliance,Auditing and Monitoring - This policy alerts users to the
companies face other equally important IT asset liabilityfact that regular monitoring of and audits on company
issues. Inappropriate use of e-mail and the Internet is asIT assets are conducted. The policy must contain a
widespread a problem as copyright violationsstatement that indicates that the user should have "no
(software piracy). Bandwidth abuse and lost employeereasonable expectation of privacy" for any file,
productivity are two additional areas of concern formessage, or content on all company systems.
most employers. Not only should a policy coverMobile, Laptop and PDA Users - Mobile devices are a
appropriate use but inappropriate use as well.difficult group of assets to control because of the
E-mail content filtering has become a popular solutiondevice portability and the fact that they may rarely
for blocking documents containing obscene, racist,connect to the corporate network. Because of this,
offensive or explicit words and phrases as well as forlaptop users often believe that they fall outside the
virus prevention. Another benefit of e-mail contentboundaries of the software policies. It is essential that
filtering is the reduction of leaks of confidentialappropriate policies as well as unique procedures are
company data. Statistics reveal that most securitycreated to address this elusive group of users.
breaches originate from within the organization,Backup and Maintenance of IT Systems - Be sure to
therefore an organization must also monitor what filesdefine who is responsible for system backup and how
are leaving the network.these tasks are completed. This policy is important,
Significant case law supports the verity that e-mail andbecause organizations rarely look at licensing, retention
Internet monitoring is legal when a company providesand destruction, e-discovery and privacy issues when
the systems on which the employee uses thesecreating backup procedures. It is essential to address
products. An employee does not have a "reasonablethese issues before having to retrieve from backup
expectation of privacy" when using these tools.because of an unforeseen problem or because of
However, it is essential that the employee be advisedlitigation.
of the company policies on these issues and that theDisciplinary Procedures - Policy statements can be a
policies are clear, well disseminated and supportedwaste of time if they are not reinforced with
company-wide.disciplinary procedures for those that breach them.
Privacy and other forms of data protection areYour organization may already have procedures in
another big area of concern for businesses. Finesplace and these must be included in any set of
from regulatory bodies and loss of competitive datatechnology policies.
have continued to push organizations to increasePolicy Review - It is important to review and update
control over these assets, to reduce associatedpolicies and procedures when needed. The team or a
liabilities and risks.subset of the initial compliance team will need to
The way to efficiently educate users is to adopt,review the policies and procedures on an annual basis
implement and enforce policies and procedures(or more frequently, if needed) to respond to changes
detailing the "Dos and Don'ts" of computer conductin the business environment and the larger legal
and explaining how the organization deals with theenvironment. Users must be told how new policies will
complete lifecycle of its IT assets.be communicated.
Regardless of the size of your organization, start byFurthermore, additional policies not included in this list will
creating a project team to administer thelikely be required in some organizations. For example,
implementation of an IT compliance program. The sizefinancial institutions and hospitals are regulated by
of the team will vary from one company to the next,outside bodies that require specific situations be
but regardless of the size, the organization will need tohandled in the manner specified. Ensure that the
commit appropriate resources, both human andcompany's legal representatives ascertain the
financial, for the project to be a success.requirements made by other regulatory agencies and
The project team should consist of a senior memberincorporate those demands into the policies and
of the IT department, to provide top-level exposure; ofprocedures.
human resources, to ensure no policy violates existingPolicy statements should be short and to the point.
regulations and to ensure that there are appropriateProcedures can be long and detailed. Use a standard
steps in place to discipline violators; of legal counsel, toformat for all of the policies, including the policy area to
ensure that policies and procedures drafted by thebe covered, the reasons for the policy and a
team are thoroughly reviewed and consecrated; andprocedure specifically adapted for your organization.
representatives from large departments, administration,Lastly, but of great importance -- make sure your
security, training, IT, etc. If more than one physicalusers are trained on the policies. I can't tell you how
location exists, be sure to include a member from eachmany organizations miss this essential step! The
site to ensure that their specific needs and limitationspolicies will not be defendable or, frankly, enforceable
are considered as well.unless users are made aware of them. For the best
Following is a list of the areas that should be covered.results, have your internal training department (or other
(Note: this list may not be comprehensive for everysuitable group) develop a system to train users as well
environment and some areas may not apply to everyas track the training and to collect a written agreement
organization):to follow the policies from every employee.
Begin with an overall opening statement by the CEOMake sure all new employees receive training and sign
(or equivalent) of the organization to not only addan agreement. At least once per year conduct
valuable corporate weight to the policies but also tofollow-up training which need not be as
show that these policies come from the very top andcomprehensive, but should serve to remind users of
are being embraced by everyone in the organization,the company's commitment to compliance.
including the Board.I promise you, the effort you put forth developing
Then create policies for the following essential areas:company-wide IT policies and procedures will pay off
Software requisition, acquisition, delivery, installation andmultifold -- this isn't an IT problem; this is a company
license compliance - Explain that software acquisition isproblem and the solution needs to be addressed
restricted in order to ensure that the company has acompany-wide.