You are on page 1of 25

OMIS 604 Information Technology

Policy and Strategy

Session 2
Session Title: Types of IT/IS Policies
Prof. Richard Boateng/Dr. Acheampong Owusu, UGBS
Email: richboateng@ug.edu.gh/aowusu@ug.edu.gh | Semester II 2019/2020 Academic Year

Richard Boateng - richboateng@ug.edu.gh


Objectives of the Session
The objectives of this session are to:
• Enable students review and understand the basic types of IT
policies required in organizations and differentiate between
the different types of IT/IS policies.
• Enable students evaluate each of them into detail in order to
understand its components.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Recommended Text

INFORMATION TECHNOLOGY POLICY AND STRATEGY

• Author: RICHARD BOATENG


• Year: 2017
• ISBN-10: 1544115229
• ISBN-13: 978-1544115221
• Paperback: 238 pages
• Publisher: CreateSpace Independent Publishing
Platform, Amazon Company USA
• Available: Amazon.com and UG Bookshop
Session Topics
Topics to be Covered
1. Types of IT/IS Policies
2. General Organizational Policies and IT Management
3. SANS Security Policy Information Security Policy Chapter 2

Recommended Text

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Types of IT/IS Policy
• There are several types of IT/IS policies which
govern the appropriate and acceptable use of
information technologies in organizations.
• We will explore a number of them and also
explore their constituents.
• Exhibits 5 – 7 illustrate different types of IT/IS
policies.
• We’re going to review and complete the related
practice questions in this session.
Chapter Two
Richard Boateng - richboateng@ug.edu.gh
Exhibit 5 - Categories of IT/IS Policies in Western Michigan University
Exhibit 6 - Systemwide IT Policies & Guidelines, University of California
Exhibit 6 - Systemwide IT Policies & Guidelines,
University of California contd.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Exhibit 6 - Systemwide IT Policies & Guidelines,
University of California contd.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Exhibit 7 - University of California Office of the President IT Policies &
Guidelines
Exhibit 7 - University of California Office of the
President IT Policies & Guidelines contd.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Exhibit 2 - University of Chichester’s IT Policies
Review of IT Policies - IS/IT and Policy - Practice Question 5
Practice Question 6
Provide descriptions to explain the different categories
of IT/IS policies identified in practice question 5
Category Description

1.

2.

3.

4.

5.

6.

7.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Review of IT Policies - IS/IT and Policy - Practice Question 7

The word ‘APPLICABLE’ is used repeatedly in the description of


the IT/IS policies of University of California. What does it mean?

………………………………………………………………………………………………………………………………………………………………………
………………………………………………………………………………………………………………………………………………………………………
………………………………………………………………………………………………………………………………………………………………………
………………………………………………………………………………………………………………………………………………………………………
General Organizational Policies and IT Management
• Exhibit 8 – IT/IS Related Policies of Highland Bank

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


General Organizational Policies and IT Management
• Exhibit 8 – IT/IS Related Policies of Highland Bank contd.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


General Organizational Policies and IT Management
• General policies governing business operations may also influence or affect
the governance of IT/IS management
• This is evident in financial institutions
• In reference to Exhibit 8 :
• Highland Bank’s IT policies tend to govern activities directly related to the
use of computer related transactions. It includes
– Information Security Policy
– ID Theft policy
– Privacy statement
– Do Not Call Policy
– Technical requirements
– External Link Disclaimer
Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh
General Organizational Policies and IT Management
• Yet, there is also a Do Not Call Policy which addresses the
respect of the privacy of all consumers.
• This policy has an indirect effect on IT Management. How?
• Thus, there is the need to develop and maintain a database to
support the marketing communications unit of the bank.
• Additionally, the CIO of the bank must consider the indirect
effects of general policies when developing IT/IS policies.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Practice Question 8
General policies of Community Banker University is
summarized below. Evaluate the implications of these
general policies on IT/IS Management.

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Practice Question 8

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


SANS Security Policy Information Security Policy

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


SANS Security Policy Information Security Policy

Richard Boateng/Acheampong Owusu - richboateng@ug.edu.gh/aowusu@ug.edu.gh


Lesson Evaluation

Can you be able to


• Identify and explain the basic types or categories of IT/IS policies
required in organizations.
Thank You

See You Next Week

You might also like