1
00:00:00,450 --> 00:00:01,710
Policies.

2
00:00:01,710 --> 00:00:04,980
In IT governance, policies serve as the backbone

3
00:00:04,980 --> 00:00:07,320
guiding an organization's operations

4
00:00:07,320 --> 00:00:09,870
and ensuring compliance with regulations.

5
00:00:09,870 --> 00:00:13,260
They provide a framework for consistent decision making

6
00:00:13,260 --> 00:00:14,820
and behavior.

7
00:00:14,820 --> 00:00:16,470
In this lesson, we are going to cover

8
00:00:16,470 --> 00:00:20,670
several key IT policies including acceptable use policies,

9
00:00:20,670 --> 00:00:23,730
information security policies, business continuity,

10
00:00:23,730 --> 00:00:26,370
disaster recovery, incident response,

11
00:00:26,370 --> 00:00:29,010
software development lifecycle, or SDLC,

12
00:00:29,010 --> 00:00:31,320
and change management.

13
00:00:31,320 --> 00:00:34,200
First up, acceptable use policy.

14
00:00:34,200 --> 00:00:36,630
An acceptable use policy, or an AUP,

15
00:00:36,630 --> 00:00:39,960
is a document that outlines the do's and don'ts for users

16
00:00:39,960 --> 00:00:42,840
when interacting with an organization's IT systems

17
00:00:42,840 --> 00:00:43,920
and resources.

18
00:00:43,920 --> 00:00:46,320
It sets boundaries for appropriate use,

19
00:00:46,320 --> 00:00:48,000
aiming to protect the organization

20
00:00:48,000 --> 00:00:50,580
from legal issues and security threats.

21
00:00:50,580 --> 00:00:53,370
For example, an AUP might prohibit users

22
00:00:53,370 --> 00:00:55,680
from visiting potentially dangerous websites,

23
00:00:55,680 --> 00:00:57,570
downloading unauthorized software,

24
00:00:57,570 --> 00:01:00,540
or using company resources for personal gain.

25
00:01:00,540 --> 00:01:03,150
By clearly defining what is considered acceptable,

26
00:01:03,150 --> 00:01:07,950
an AUP helps maintain a safe and productive IT environment.

27
00:01:07,950 --> 00:01:11,040
Next, information security policies.

28
00:01:11,040 --> 00:01:13,560
Information security policies are the cornerstone

29
00:01:13,560 --> 00:01:16,020
of an organization's security posture.

30
00:01:16,020 --> 00:01:18,090
They outline how an organization

31
00:01:18,090 --> 00:01:20,670
protects its information assets from threats,

32
00:01:20,670 --> 00:01:22,890
both internal and external.

33
00:01:22,890 --> 00:01:25,560
These policies cover a range of areas

34
00:01:25,560 --> 00:01:29,820
including data classification, access control, encryption,

35
00:01:29,820 --> 00:01:31,740
and physical security.

36
00:01:31,740 --> 00:01:34,470
For instance, an information security policy

37
00:01:34,470 --> 00:01:37,530
might specify that sensitive data must be encrypted

38
00:01:37,530 --> 00:01:39,660
both in transit and at rest,

39
00:01:39,660 --> 00:01:43,260
and only authorized personnel should have access to it.

40
00:01:43,260 --> 00:01:44,760
These policies are essential

41
00:01:44,760 --> 00:01:47,730
for maintaining the confidentiality, integrity,

42
00:01:47,730 --> 00:01:50,760
and availability of an organization's data.

43
00:01:50,760 --> 00:01:52,740
Business continuity is all about ensuring

44
00:01:52,740 --> 00:01:55,590
that an organization can continue its operations

45
00:01:55,590 --> 00:01:58,740
even in the face of disruption or disaster.

46
00:01:58,740 --> 00:02:02,670
A business continuity policy focuses on how an organization

47
00:02:02,670 --> 00:02:05,160
will continue its critical operations

48
00:02:05,160 --> 00:02:07,680
during and after a disruption,

49
00:02:07,680 --> 00:02:09,660
outlines the steps to be taken

50
00:02:09,660 --> 00:02:12,390
to ensure minimal interruption to services

51
00:02:12,390 --> 00:02:14,880
and to recover as quickly as possible.

52
00:02:14,880 --> 00:02:16,380
This might include strategies

53
00:02:16,380 --> 00:02:19,470
for dealing with power outages, hardware failures,

54
00:02:19,470 --> 00:02:21,810
or natural disasters.

55
00:02:21,810 --> 00:02:23,940
By planning for business continuity,

56
00:02:23,940 --> 00:02:26,940
organizations can mitigate the impact of disruptions

57
00:02:26,940 --> 00:02:29,310
and ensure their survival.

58
00:02:29,310 --> 00:02:31,650
Next up, disaster recovery.

59
00:02:31,650 --> 00:02:34,110
Closely related to business continuity,

60
00:02:34,110 --> 00:02:36,120
disaster recovery focuses specifically

61
00:02:36,120 --> 00:02:40,110
on how an organization will recover its IT systems and data

62
00:02:40,110 --> 00:02:41,460
after a disaster.

63
00:02:41,460 --> 00:02:44,280
A disaster recovery policy outlines the steps

64
00:02:44,280 --> 00:02:46,440
for data backup and restoration,

65
00:02:46,440 --> 00:02:48,360
hardware and software recovery,

66
00:02:48,360 --> 00:02:50,850
and alternative processing locations.

67
00:02:50,850 --> 00:02:53,040
For example, it might specify

68
00:02:53,040 --> 00:02:54,960
that data should be regularly backed up

69
00:02:54,960 --> 00:02:58,500
to a secure offsite location and tested regularly

70
00:02:58,500 --> 00:03:02,160
to ensure it can be restored if needed.

71
00:03:02,160 --> 00:03:03,720
Incident response.

72
00:03:03,720 --> 00:03:05,310
An incident response policy

73
00:03:05,310 --> 00:03:08,040
is a plan for handling security incidents.

74
00:03:08,040 --> 00:03:11,490
It includes steps for detecting, reporting, assessing,

75
00:03:11,490 --> 00:03:14,610
responding to, learning from security incidents.

76
00:03:14,610 --> 00:03:17,760
For example, might specify who should be notified

77
00:03:17,760 --> 00:03:19,470
in the event of a data breach,

78
00:03:19,470 --> 00:03:22,380
how the breach should be contained and investigated,

79
00:03:22,380 --> 00:03:25,530
and how to prevent similar incidents in the future.

80
00:03:25,530 --> 00:03:28,530
By having a well-defined incident response policy,

81
00:03:28,530 --> 00:03:31,110
organizations can respond to incidents

82
00:03:31,110 --> 00:03:36,110
quickly and effectively, minimizing damage and downtime.

83
00:03:36,210 --> 00:03:38,460
Software development lifecycle.

84
00:03:38,460 --> 00:03:41,310
An SDLC policy guides how software is developed

85
00:03:41,310 --> 00:03:42,780
within an organization.

86
00:03:42,780 --> 00:03:45,660
It covers all stages of software development,

87
00:03:45,660 --> 00:03:49,260
from initial requirements gathering to design,

88
00:03:49,260 --> 00:03:52,740
coding, testing, deployment, and maintenance.

89
00:03:52,740 --> 00:03:54,750
The policy might also include standards

90
00:03:54,750 --> 00:03:57,300
for secure coding practices, code reviews,

91
00:03:57,300 --> 00:03:58,860
and software testing.

92
00:03:58,860 --> 00:04:02,850
By following an SDLC policy, organizations can ensure

93
00:04:02,850 --> 00:04:05,730
that their software is high-quality, secure,

94
00:04:05,730 --> 00:04:08,160
and meets the needs for users.

95
00:04:08,160 --> 00:04:10,140
Finally, change management.

96
00:04:10,140 --> 00:04:11,970
Change management policy governs

97
00:04:11,970 --> 00:04:15,330
how changes to the IT systems and processes are handled.

98
00:04:15,330 --> 00:04:18,360
It aims to ensure that changes are implemented

99
00:04:18,360 --> 00:04:20,940
in a controlled and coordinated manner,

100
00:04:20,940 --> 00:04:23,040
minimizing the risk of disruptions.

101
00:04:23,040 --> 00:04:25,410
This might involve procedures for requesting,

102
00:04:25,410 --> 00:04:28,620
proving, implementing, and reviewing changes.

103
00:04:28,620 --> 00:04:30,990
By managing changes effectively,

104
00:04:30,990 --> 00:04:33,870
organizations can ensure that their IT systems

105
00:04:33,870 --> 00:04:37,440
remain stable, reliable, and secure.

106
00:04:37,440 --> 00:04:41,040
So remember, an AUP policy is a policy that outlines

107
00:04:41,040 --> 00:04:41,940
the acceptable ways

108
00:04:41,940 --> 00:04:44,520
in which an organization's IT systems and resources

109
00:04:44,520 --> 00:04:45,990
can be used.

110
00:04:45,990 --> 00:04:49,350
A business continuity policy is a plan that outlines

111
00:04:49,350 --> 00:04:52,680
how an organization will continue its critical operations

112
00:04:52,680 --> 00:04:55,860
during and after disruption of a service.

113
00:04:55,860 --> 00:04:57,480
A change management policy

114
00:04:57,480 --> 00:05:00,120
governs how changes to IT systems and processes

115
00:05:00,120 --> 00:05:02,520
are handled within an organization.

116
00:05:02,520 --> 00:05:05,400
By understanding and implementing these policies,

117
00:05:05,400 --> 00:05:08,610
organizations can ensure they are operating securely,

118
00:05:08,610 --> 00:05:11,970
efficiently, and in compliance with relevant laws

119
00:05:11,970 --> 00:05:13,383
and regulations.

