Results 1 to 8 of 8

Thread: Implementing IT Policy

  1. #1
    TiG
    TiG is offline
    Walk a mile in other peoples shoes...
    Join Date
    Jul 2003
    Location
    Questioning it all
    Posts
    6,213
    Thanks
    45
    Thanked
    48 times in 43 posts

    Implementing IT Policy

    With my recent promotion to take over the running of IT of the company I work for (in addition to my technology/dev role of the speech recognition telephone systems), i've realised just how much there is to put in place for a company that doesn't do process well.

    I've taken a step back and realise there are huge gaping holes in what exists and what needs to be put in place.

    Lets start with the most important. (I have a brand new domain setup and almost ready to go with migration planned to fix some of the legacy issues - poor password/security policy. Backup proceedure usually takes 18hrs at the moment, new process in place backups all of the data in 1/9th the time)

    I've started on the new things such as :-
    IT new joiner/leaver policy
    Remote access VPN policies (already improved current setup with audit trail and encryption)

    Document policy is next on my list and the version control of the non development department is SHOCKING, i've checked one of our customer files and found 7, yes 7 versions, unlabelled of the same documents in different directories off the main sub folder.

    There is no order to any of it, Thoughts to resolve this and bear in mind the company doesn't do process, is to slowly migrate people to a sharepoint 2007 install, at least that way i'm going to get some measure of control over document management and version control.

    E-mail policy is already agreed but isn't being followed but thats easy to deal with.
    Web access is under control after a few people got a shock when their manager presented them with their traffic figures for two days worth of internet access.

    Question is what am I missing?.

    TiG
    -- Hexus Meets Rock! --

  2. #2
    DR
    DR is offline
    on ye old ship HEXUS DR's Avatar
    Join Date
    Jul 2003
    Location
    HEXUS HQ, Elstree
    Posts
    13,412
    Thanks
    1,060
    Thanked
    841 times in 373 posts
    the best way to enforce it is with a graphite rod...

  3. #3
    Senior Member burble's Avatar
    Join Date
    May 2007
    Location
    Olney
    Posts
    1,138
    Thanks
    8
    Thanked
    90 times in 89 posts
    Before you start implementing policy, make 100% sure that it can be enforced. A mate of mine setup some very sound policies but his management were too weak to do anything to enforce it (despite them agreeing to his proposals) so when the policies were largely ignored he was left looking like a right little hitler to some people in the company.

  4. #4
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    Have you looked at any of the MOF/ ITIL stuff Tony ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. #5
    TiG
    TiG is offline
    Walk a mile in other peoples shoes...
    Join Date
    Jul 2003
    Location
    Questioning it all
    Posts
    6,213
    Thanks
    45
    Thanked
    48 times in 43 posts
    Quote Originally Posted by burble View Post
    Before you start implementing policy, make 100% sure that it can be enforced. A mate of mine setup some very sound policies but his management were too weak to do anything to enforce it (despite them agreeing to his proposals) so when the policies were largely ignored he was left looking like a right little hitler to some people in the company.
    ahh you don't appreciate that i don't mind being the bad guy. But yes i'm well aware of that issue and while I appreciate the word of caution around this, its not just this that i want to understand its other things that i should be agreeing and documenting.

    Things like asset management?, Software licencing etc.

    Moby, good call - i'll have a read through later.

    TiG

    oh did i add i have a minion too
    -- Hexus Meets Rock! --

  6. #6
    Senior Member
    Join Date
    Jan 2004
    Location
    Cambridge
    Posts
    283
    Thanks
    13
    Thanked
    24 times in 23 posts
    • timread's system
      • Motherboard:
      • MSI B450 Tomahawk Max
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • 16GB (2x8GB) Corsair DDR4 Vengeance LPX
      • Storage:
      • 1x WD Blue SN550 500GB M.2 NVMe SSD, , 1x Crucial MX500 1TB SSD, 2x WD 1TB HDD in RAID1
      • Graphics card(s):
      • Gigabyte GeForce GTX 1660 Ti WINDFORCE OC 6G
      • PSU:
      • EVGA SuperNOVA 750W Gold Gen2
      • Case:
      • Fractal Design Define R3 Arctic White
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC 2590 G4, Dell U2412M
      • Internet:
      • VirginMedia
    USB device policy springs to mind (USB flash drives). Do you block write access to these by default?

    Does your email policy cover staff requests to access each other's mailboxes (e.g. during sickness, leave etc)? That's a very common one - you could require HR and/or VP approval on that.

  7. #7
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    Quote Originally Posted by TiG View Post
    ahh you don't appreciate that i don't mind being the bad guy.

    he's darn good at it too

    Minions are the clear way forward.

    Hopefuly the ITIL way will help get some order in where there was none.

    the biggest problem in those kinds of things is change management.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  8. #8
    TiG
    TiG is offline
    Walk a mile in other peoples shoes...
    Join Date
    Jul 2003
    Location
    Questioning it all
    Posts
    6,213
    Thanks
    45
    Thanked
    48 times in 43 posts
    Quote Originally Posted by timread View Post
    USB device policy springs to mind (USB flash drives). Do you block write access to these by default?

    Does your email policy cover staff requests to access each other's mailboxes (e.g. during sickness, leave etc)? That's a very common one - you could require HR and/or VP approval on that.
    I'm actually very aware that i've got complete and total access to everything, which did raise the question of how do i police myself....

    But luckily i've got that covered too, e-mail archiver to back up everything for compliance acts as a much better solution than giving carte blanche access to mailboxes. If you want an e-mail you need to know exactly who from, what time etc for me to be able to provide it back from the system.

    Works fairly well and the emphasis on knowing what you are requesting works quite well from the abuse aspect.

    As for Change management, i've got a complete IT fault and IT project register tracking everything done since i've taken over. I've had 3 years of complete IT incompitence here and if i've going to be able to change anything i do need to change attitudes (hearts and minds people )

    Telling them and physically/electronically being able to demonstrate how things have improved is essential for me to be able to distinguish me from the muppets that have come and gone.

    TiG
    -- Hexus Meets Rock! --

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Legality of Ebuyers return policy
    By Gordy in forum SHOPPING AND CLASSIFIEDS
    Replies: 12
    Last Post: 02-06-2007, 11:58 AM
  2. 30 day returns policy
    By RAYK47 in forum SCAN.care@HEXUS
    Replies: 11
    Last Post: 22-12-2006, 04:06 PM
  3. Replies: 30
    Last Post: 09-06-2005, 03:42 PM
  4. apple returns policy
    By MuTTy_Hc in forum Apple Mac
    Replies: 5
    Last Post: 28-01-2005, 01:54 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •