Showing posts with label policies. Show all posts
Showing posts with label policies. Show all posts

Tuesday, March 30, 2010

Governance Part 4: Standards

We’ve covered how management uses policies to govern an undertaking, whether that’s a business, a household, or one’s career. Today we’ll continue the Governance series with a look at standards and how they bridge the gap between executive ideals and technical practicality.

The relationship between a policy and a standard is similar to the relationship between a vision and a mission:

Friday, March 5, 2010

Governance Part 3: Policies

In Part 2, we discussed the Missions, Visions, and Charters, which define a task, lay out an overall strategy for accomplishing that task, and authorize someone to do it. Today, we’ll discuss how policies tell everyone to execute the charter to accomplish the mission that realizes the vision. (If I can make this into a spoof of The Court of King Caractacus, why not?).

Humor aside, a policy is a high level statement from senior management to the enterprise describing how it expects everyone to conduct business.

Monday, February 15, 2010

The lights come on, the set is down, the curtains float away...

People already blog about information security – just look at my short but growing blog roll. Does the world really need one more? I think so, and my inaugural post is to make the case for it.

Information Security is big business. The U.S. federal government alone spent 7.1 billion dollars on it in 2009, and private industry dropped a pretty penny on it as well. The headlines regularly show the cost of not getting it right, literally and figuratively. Companies appoint executives, staff departments, allocate budgets, and do all the other things that businesses do in order to secure their computing. I should know – it’s kept me employed full time for most of my adult life.

And yet, the headlines keep coming.