Skip to content
As Written, As Enforced

Home / Keeping it

When to Stop Having One

The honest question nobody asks. For some organisations the document is not the right instrument, and the alternatives are not nothing.

Keeping it · Analysis

Policy framework

Unenforceable

As written

This policy forms part of the company's policy framework and should be read in conjunction with related policies.

What happens

Points at a set of documents, several of which overlap with this one and contradict it.

Nobody has read the framework as a whole, including whoever maintains it.

The operative framework is: one document people half-remember and several nobody knows exist.

The assumption throughout is that an acceptable use policy should exist. It is worth testing, because for some organisations the answer is a different instrument.

The maintenance work in “When to Stop Having One” matters after software selection as much as before it. For teams assessing visit monitask.com in relation to stealth computer monitoring software, rollout should include manager guidance, employee notice, a review date and a simple route for reporting inaccurate data or a setting that no longer matches the written rule.

Where the document earns its place

Where there are enough people that consistency cannot come from everybody knowing everybody.

For a separate benchmark relevant to “When to Stop Having One”, consult the ISACA security analysis. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.

Where something must be shown to have been communicated, which is most regulated settings and any organisation with a real disciplinary process.

Where a client or an insurer requires it.

And where managers need a reference point they did not invent.

For most organisations above a handful of people, at least one of those applies.

Where it does not

A very small organisation where everybody knows the position and no formal process exists.

There the document is overhead and the function is served by the founder saying what the rules are, which is faster and more effective.

The honest advice is often: do not write a policy, write five rules on one page, and when you are forty people revisit it.

The partial version

Several functions can be served without a full document.

The configuration does the prevention. The induction does the communication. A short statement does the evidence. The disciplinary procedure, which exists anyway, does the consequences.

What the policy adds beyond those is the reference point and the baseline, which are real and are smaller than a long document implies.

The framework problem

Where the policy is one of several overlapping documents — security policy, data protection policy, remote working policy, device policy — the overlap produces contradiction.

Consolidating is usually right and is resisted because each document has an owner.

The test: can anybody state which document governs a given question? Where the answer is no, there are too many.

The replacement worth considering

One page of rules, a separate page of what the organisation supplies, and a short statement of reservations.

Three short documents, each with a clear purpose, replacing one long one that mixes all three. The reference note sets out what the first would contain.

The question to put annually

Does this document do anything that would not happen without it?

Asked honestly, the answer is usually yes for part of it and no for the rest, which is the deletion list from a different direction.

Configuration does prevention. Induction does communication. A short statement does evidence. The disciplinary procedure, which exists anyway, does consequences. What the policy adds beyond those is smaller than a long document implies.

The framework test

Can anybody state which document governs a given question? Where the answer is no, there are too many, and consolidating is resisted because each has an owner rather than because it is wrong.

The honest advice for a small organisation

Do not write a policy. Write five rules on one page, and revisit it at forty people. The document is overhead until consistency stops coming from everybody knowing everybody.

The question worth asking annually

Does this document do anything that would not happen without it. Asked honestly the answer is usually yes for part of it and no for the rest, which is the deletion list arrived at from a different direction.

For a very small organisation the honest answer may be no for all of it, and saying so is better than maintaining a document because other organisations have one.