You are on page 1of 7

Setting Up and Enforcing

Orgnanizational Policies
A TenStep White Paper

Contact us at info@tenstep.com
TenStep, Inc.
2363 St. Davids Square
Kennesaw, GA. 30152
877.536.8434
770.795.9097
Setting Up and Enforcing Organizational
Policies
Why does your IT organization and approved by the people or
need formal policies? group that owns the process.
Because of this, you hope that the
When companies are small, they rarely
policy reflects the best practices of
have many (if any) formal policies in
the group that is most experienced
place. However, as they get bigger
in the area and most impacted by
they always start to codify many of the
the outcome. The policy then aligns
important aspects of the culture into
everyone else under these best
formal policies. Your IT organization
practices. For example, look at
may have started the same way. When
your company Expense Reporting
there were only a handful of people
Policy. This policy is going to be
performing your IT function, there
established by the Finance group.
may have been no formal policies.
That should make sense. Even if
Now look around. How many policies
your team had the time to create
do you see? If you’re like most
the policy yourself, you don’t have
organizations, you probably have
the expertise to know the best way
policies for:
to handle expenses. You are IT
• Application Development people – not accountants. So,
following the established process
• Security
gives you the sense that you are
• Production turnover to support working on a firm foundation. Let
the Finance Department establish
• Asset management
the finance policies. Let the
• Teleworking Database Group establish the
database policies. Let your
• Finance
management team establish the
• Procurement management policies. These
groups are then accountable for
• Dozens or hundred of others
the policies and you know where to
How did it come to this – an go if you need an exception or if
organization guided by policies? you would like to change the
policy.
Policies reflect an organizations logical
progression from working in an ad-hoc • Working more efficiently
manner to one where people are through process reuse. Most of
following common and consistent us recognize the value of reuse. It
processes. A policy reflects your makes more sense to reuse things
organization’s desire for everyone to that are already developed instead
perform a specific function in a specific of having to re-invent everything
way. Policies help everyone we do from scratch. This is true
understand how to do things, and they with work processes and policies as
help managers understand the well. For instance, you could
framework in which they can manage. certainly come up with a
framework for handling IT security
Policies are developed and are they
on your project. But why would
are important for two main reasons.
you need to if your organization
• Working more effectively under has already developed and
company best practices. One approved a Security Policy. You
thing you will observe about could also come up with a
policies is that they are created workstation replacement policy

Copyright© 2007 TenStep, Inc. All Rights Reserved


877.536.8434 / 770.795.9097
Setting Up and Enforcing Organizational
Policies
that makes sense for your If you are in an organization with
department. But why should you if strong governance you can get a
your IT Department already has an policy adhered to strictly through the
established and approved governance process. You create the
Workstation Upgrade Policy. policy, get it approved through the
Having common policies saves you appropriate channels, and then issue it
the time to having to invent and for everyone to follow. In this case the
gain approval on these for each concept of winning support for the
individual project or group. It also policy applies to the approval process.
saves time for new people in the Once the policy is approved, the
company as they learn how things management structure enforces it.
work in your world. This way of winning support is perhaps
applicable in the military and other
One short definition of culture is that it
organizations with a strong
is “how things are done around here”.
governance culture.
Written policies become part of your
culture since they reflect how things However, let’s say that you work in an
are done in your organization. As organization where it is not quite so
companies get bigger, they need to easy. You have to work a little more to
establish policies so that people have gain acceptance of your policy. If this
guidance on how to do things. Since applies to you, the following steps will
policies are established and approved help win support for your policy.
by the subject-matter experts, you
• Make sure you own the business or
also should feel good that everyone is
IT process. You can’t create
doing things in ways that protect the
policies in areas that you don’t
company and make sense.
own. This means that you can
You might complain about policies, but create a database policy if you are
don’t complain about policies in the database group. You can create
general. If you do not agree with some a telecommunication policy if you
specific policy try to change it with are in the telecommunications
your better idea. However, all group. However, you can’t create
organizations need policies. Your the new helpdesk policy if you are
organization would quickly get out of in the IT development area. Of
control and be much worse off without course, the policy may be issued
them. by another senior manager. The
CIO may issue a policy on cell
Win support for your new policy
phone usage. However, the CIO
Have you ever had to create an IT certainly did not create the policy.
policy to formalize the way that some The telecommunications people
process is executed or the way people did.
perform certain functions? If you have
• Communicate the purpose of the
you know that it may or may not be
standard policy. People must
easy. Actually effort required to
understand why you are creating
implement IT policies can vary
the policy. There has to be a clear
dramatically in different organizations
purpose. Not everything needs a
depending on your governance culture.
common policy. For instance,
(Governance refers to your ability to
having a policy that results in email
enforce organization priorities through
getting scanned for viruses and
the management hierarchy.)
spam is important. Determining

Copyright© 2007 TenStep, Inc. All Rights Reserved


877.536.8434 / 770.795.9097
Setting Up and Enforcing Organizational
Policies
how often a manager must talk to it applies to, how you work under
each staff member probably cannot the policy, etc. You may need to
be dictated in a policy. provide some examples. If there
are general exceptions, make sure
• Make sure the policy drives
you state what those are. Just as
business value. Policies provide
with the point above, you probably
guidance on how things should be
want to circulate the policy to
done, so they save the time and
others outside your functional area
effort that would be required if
to make sure it is understandable.
everyone had to figure it out on
their own. You need to make sure • Try to have an enforcement
your organization derives overall mechanism. You can issue a policy
value from your policy. A policy that is perfectly clear and that has
that results in more effort and cost everyone’s buy-in. However, you
without corresponding business will be much more successful if you
value doesn’t make sense. You have an enforcement capability.
might as well leave people on their For example, you may be able to
own if that drive more enforce a policy on scanning for
organizational value. email viruses since you probably
own the email servers. However, if
• Get input from affected groups. It’s
you issue a policy on email
a good idea to gather input from
etiquette, you will probably be less
the people that the policy will
successful because you don’t have
impact. This helps make sure that
the enforcement capability.
the policy is workable and also
helps solicit their buy-in for when Those are some of the basics.
the policy is issued. Depending how political your policy is,
you may have a multifaceted
• Validate the policy make sense.
campaign to communicate the policy
This sounds obvious, but
and gain the support of the effected
sometimes misguided policies are
staff. However, for most policies, you
written that never have a chance
just need the basics – be the owner,
to be adopted or supported
have a purpose, drive business value,
because they don’t make sense.
have a reasonable policy, be clear,
People will generally be more apt
gather initial feedback and have an
to follow a policy that seems to
enforcement mechanism if possible. If
make sense, even if they don’t
you will follow th4se simple, but
agree with it entirely. One way to
critical steps, you will have a much
ensure the policy makes sense is to
better chance of building support for
circulate it to a broader group of
your policy with the people that are
people outside your functional
affected.
area.
Use a policy audit to ensure your
• Make sure the policy is clear. You
policies are followed
don’t want to issue a policy and
have people say they do not Many IT organizations are good at
understand it. In fact, it would be establishing policies but have an
good if your organization has a uneven ability to get their staff to
common format for describing your follow them. It is important that an
policies. The policy must be very organization be able to enforce
clear on when it is applicable, who policies. If the policies are important

Copyright© 2007 TenStep, Inc. All Rights Reserved


877.536.8434 / 770.795.9097
Setting Up and Enforcing Organizational
Policies
enough to create and approve, they ensure that the policy is followed.
are important enough to enforce. In For instance, you may have a
fact, if the organization is not prepared policy for virus scanning of all
to enforce a policy, there is really no inbound emails. When you talk to
reason to create it to begin with. the email group, you may discover
that this policy can be enforced
The best way to make sure your
systematically since this group
organization follows your defined
owns the email servers and they
policies is to initiate a policy audit. On
can ensure that all incoming emails
the surface, a policy audit might seem
are scanned. If a group can enforce
daunting. However, it is not so hard.
a policy systematically, they need
Follow this simple process to execute
to prove that the policy is being
an audit to ensure your IT policies are
enforced in all instances. If they
being followed.
can, you are fine for that policy. If
1. Inventory your policies. You they cannot validate that the policy
can’t do a policy audit if you are is being enforced in all instances,
not sure what your policies are. then document this policy as one
The first thing to do is to inventory that needs further scrutiny.
all of the policies in the IT
5. Manually audit the remainder
organization.
of the policies. Most policies
2. Pick the policies that are most cannot be enforced systematically.
important - and then a few Work with the policy owner to
more. You could audit every policy determine the best way to validate
in your inventory but you don’t that the policy is being followed.
need to. You should pick out the Depending on the policy, this could
policies that are important to you; take many forms. For instance:
such are your email policies, your
• You cold look at the paperwork
Internet usage policy, and your
for 25 turnover instances to
hardware procurement policy. Then
validate your production
pick out a couple more policies
turnover policy.
more or less at random. The
reason for picking both is that you • Your teleworking policy may
want to ensure that your most require that you identify 5
important policies are being teleworkers and interview them
followed, plus you want to check and their managers.
some others to make sure that
• You could analyze a cross-
your organization seems to be
section of 20 workstations from
following all policies – not just the
around the company to
important one.
determine whether your
3. Talk to the business owners of workstation policies are being
each policy. Start by identifying followed.
the business owner of each policy
6. Prepare general conclusions.
and have a discussion with them
After you have completed all of the
about each policy.
individual audits, you can make
4. Validate automated some overall conclusions. For
enforcement. Ask the policy instance, if the results of the
owner whether there are any individual policy audits are all
enforcement mechanisms that generally favorable (perhaps not

Copyright© 2007 TenStep, Inc. All Rights Reserved


877.536.8434 / 770.795.9097
Setting Up and Enforcing Organizational
Policies
prefect, but generally favorable) flagship product is the TenStep Project
then the CIO should feel confident Management Process®, which has
that policies are generally being been licensed to thousands of
followed. If the results of most of companies and individuals around the
the specific audits were world. In addition, TenStep has
unfavorable, then the CIO should training, consulting and business
have reason for concern that methodology products covering Project
policies in general are not being Management Offices, portfolio
followed. There will be some management, software development
follow-up necessary to determine and application support.
why the policies are not being
The TenStep process is translated into
followed, and then an action plan
14 languages, allowing it to be utilized
will need to be put into place to
by organizations in most parts of the
turn ensure your organization does
world.
follow defined policies.
TenStep meets the needs of local
You don’t have to audit every policy
businesses with a network of
and every instance to make an overall
offices in the USA and around the
conclusion on whether your
world.
organization is following your
documented policies. Based on the Our training classes include:
results of this policy audit you can
• Project Management (advanced
determine if you are okay in how your
and basic)
organization follows policies or
whether you have more work to do. • Preparing for the PMP Exam
• Earned Value Management
• Setting up and Running Project
Setting up and enforcing Management Offices
organizational policies does • Setting up and Running Portfolios
not have to be a daunting • Gathering Business Requirements
task. • Many, many more
We have done it before.
Our consulting services include:
Contact us for more
• Project management deployment
information. and customization
info@tenstep.com • Project Quickstarts
877.536.8434 / 770.795.9097
• Setting up PMOs
• Project management coaching,
auditing documentation review
About TenStep
• Managing your projects
TenStep, Inc. (www.TenStep.com) is
headquartered in Atlanta, Georgia • Many more
(USA), and specializes in developing,
About the Author:
consulting and training in business
methodologies. The company’s

Copyright© 2007 TenStep, Inc. All Rights Reserved


877.536.8434 / 770.795.9097
Setting Up and Enforcing Organizational
Policies
Tom Mochal, PMP is the president of
TenStep, Inc. (www.TenStep.com), a
methodology development, consulting
and training company. He is also the
head of The TenStep Group, a network
of TenStep offices supporting the
TenStep process in numerous
languages and countries around the
world.
Mochal is author of a book on
managing people called "Lessons in
People Management" and a companion
book on project management called
"Lesson in Project Management”.
Mochal also authored all of the
TenStep methodology products.
Mochal recently won the
Distinguished Contribution Award
from the Project Management Institute
for his work spreading knowledge of
project management around the world.
Mochal is a speaker, lecturer,
instructor and consultant to companies
and organizations around the world.
He is a member of the Atlanta,
Georgia (USA) chapter of the Project
Management Institute (PMI), the
American Management Association
(AMA), the American Society for the
Advancement of Project Management
(asapm®), and is a partner in The
Management Mentors, a group
dedicated to building knowledge in
project management, IT management
and leadership/personal development.
Contact us at info@tenstep.com
TenStep, Inc.
2363 St. Davids Square
Kennesaw, GA. 30152
877.536.8434
770.795.9097

Copyright© 2007 TenStep, Inc. All Rights Reserved


877.536.8434 / 770.795.9097

You might also like