YouTube2Text

Strategic Management 2 Policies Free MBA course — Transcript

by Swiss School of Business Research · 4,052 words · 680 segments · language en · Watch on YouTube

Full transcript

  1. 0:00so hello everybody and welcome back to
  2. 0:03this module on MBA marketing management
  3. 0:06so if you cast your mind back to the
  4. 0:08first session we spoke about strategy
  5. 0:11strategic management and touched on the
  6. 0:14differences between policies tactics and
  7. 0:16strategies this module is purely focused
  8. 0:20on policy so creating policies and
  9. 0:23everything we need to know around that
  10. 0:25so before we continue and move on to the
  11. 0:27next slide have a think about policies
  12. 0:30that you've come across
  13. 0:32um and then just consider how easy do
  14. 0:35you think it is to create an effective
  15. 0:37policy so you might just want to stop
  16. 0:39the video here and just have a little
  17. 0:41bit of reflection policies that you've
  18. 0:43come across whether that's contracts
  19. 0:45that you've signed that have come up
  20. 0:47that include a policy or remember when
  21. 0:49you go and book a flight and it talks to
  22. 0:51you about the airline policy or maybe
  23. 0:53studying at the business school the
  24. 0:55policy that they have in place so think
  25. 0:57a little bit about do you think it's
  26. 0:59easy to create an effective policy
  27. 1:02so answering that question in more
  28. 1:04detail
  29. 1:05some of the rules for creating effective
  30. 1:07policies that we need to be aware of are
  31. 1:10around the fact that writing policies
  32. 1:12are inherently a little bit risky so
  33. 1:16it's a risk communication exercise that
  34. 1:18is performed frequently by people who
  35. 1:21lack the skills needed to create a good
  36. 1:24security policy
  37. 1:25so fortunately the use of a few best
  38. 1:28practices for planning and writing
  39. 1:30policy can make a huge difference in its
  40. 1:33Effectiveness in reducing risk
  41. 1:36so some of the challenges and issues
  42. 1:38what do you think they are because
  43. 1:40obviously it's inherently risky so what
  44. 1:43do you think are the key challenges and
  45. 1:45issues in writing a policy so have a
  46. 1:48little think about it and we will
  47. 1:50continue
  48. 1:51so some of the key challenges around
  49. 1:53writing policies are that for example
  50. 1:56security policies are developed by the
  51. 1:59security team in isolation and alienate
  52. 2:03the rest of the organization which could
  53. 2:05potentially lead to high levels of
  54. 2:06resistance and counterproductivity
  55. 2:09a rigid policy unnecessarily removes our
  56. 2:12ability to consider multiple options to
  57. 2:15hard or complex problems
  58. 2:17another key challenge regarding to
  59. 2:19policy writing is the fact that policies
  60. 2:22which are badly worded can introduce
  61. 2:24problems such as inconsistent policy
  62. 2:27positions the inability to ensure
  63. 2:31compliance unacceptably high risk
  64. 2:34profiles or unnecessarily high costs
  65. 2:37and security policies that are not
  66. 2:39adapted to changes in the business
  67. 2:40environment or the external environments
  68. 2:43will become Obsolete and restrict
  69. 2:45Business Development
  70. 2:47so now we're a little bit more aware of
  71. 2:49the key challenges in writing a policy
  72. 2:52what would you recommend to overcome
  73. 2:54these difficulties so what do you think
  74. 2:57needs to be in place to help us
  75. 2:59counteract these problems that we've
  76. 3:01highlighted here so stop the video for a
  77. 3:03few minutes and just pause to consider
  78. 3:07so to overcome these difficulties things
  79. 3:10that we need to recommend
  80. 3:11involve developing and maintaining a
  81. 3:15policy as part of a process
  82. 3:17so we need to engage heavily with
  83. 3:20stakeholders who are affected by the
  84. 3:22policy because this will build support
  85. 3:24and improve policy quality and
  86. 3:26pragmatism
  87. 3:28we need to ensure that our policy is
  88. 3:31flexible enough to support the array of
  89. 3:34risk appetites that may exist within our
  90. 3:36organization and we need to have our
  91. 3:38policies drafted by someone with
  92. 3:40competence in policy development
  93. 3:43the rules are only as strong as the text
  94. 3:45that expresses them and we need to make
  95. 3:48sure that our policy is pragmatic by
  96. 3:51testing it out
  97. 3:53so what do you think is involved in
  98. 3:55developing a policy what do you think
  99. 3:57are the key steps that we should follow
  100. 4:00so have a little think about that while
  101. 4:02you're reading the recommendations
  102. 4:04so
  103. 4:06when we are looking at developing and
  104. 4:09maintaining a policy we should
  105. 4:11definitely approach it as a process
  106. 4:13so it is a bit of a mistake to assume
  107. 4:15that you can successively develop policy
  108. 4:18by having a knowledgeable person compose
  109. 4:20a document in one sitting in isolation
  110. 4:23from the rest of the organization
  111. 4:25this will alienate the rest of the
  112. 4:27organization and lead to high levels of
  113. 4:31resistance and counterproductivity
  114. 4:35and successful policy outcomes almost
  115. 4:38always require
  116. 4:39consultation and iteration before a
  117. 4:43final sustainable policy position is
  118. 4:45drafted
  119. 4:46so if you can't defend your process you
  120. 4:49can't defend your policy
  121. 4:50and once your policy is published it
  122. 4:53should be reviewed occasionally for
  123. 4:55example every three years and it should
  124. 4:57include a consultation with other
  125. 4:59stakeholders internal and if necessary
  126. 5:02external along with an assessment of
  127. 5:04issues that have Arisen since the
  128. 5:06preceding review
  129. 5:08so the characteristics that our process
  130. 5:11in following this and making sure that
  131. 5:13we adhere to following the correct
  132. 5:15procedure in actually developing the
  133. 5:17policy should have the following
  134. 5:19characteristics
  135. 5:20so as we mentioned earlier we should
  136. 5:22have an iterative approach
  137. 5:24so it's not really feasible to write and
  138. 5:27enforce every potentially useful policy
  139. 5:29at once
  140. 5:31so starting with a small body of the
  141. 5:33most necessary policies and building on
  142. 5:36that over a period of years will result
  143. 5:38in a more effective body of policy
  144. 5:41another characteristic is that we should
  145. 5:44base policy on business risk priorities
  146. 5:47so it's not necessary to address every
  147. 5:49possible form of loss through written
  148. 5:51policy this results in too many policies
  149. 5:55we need to choose our battles and keep
  150. 5:57the body of written rules to a minimum
  151. 5:59by addressing only that most highest
  152. 6:02impact areas
  153. 6:05and also during the policy writing
  154. 6:07process we should keep notes and an
  155. 6:11explicit written goal for each policy
  156. 6:13element should be included during the
  157. 6:15creation of the policy and the review
  158. 6:17process
  159. 6:18and it should be filed for further
  160. 6:20reference
  161. 6:21so it's preferable to include the goal
  162. 6:23as a normal part of the published policy
  163. 6:25as an awareness building mechanism
  164. 6:28notes relating to the reason for the
  165. 6:30policy and its goal should be kept as
  166. 6:33background material for review Cycles
  167. 6:36so notes are especially useful during
  168. 6:38policy revision
  169. 6:40and and include the source of borrowed
  170. 6:42text and discussions over choices
  171. 6:45unused policies along with an
  172. 6:47explanation as to why it was not used
  173. 6:49can also be stored as a reference for
  174. 6:52future questions and possible future use
  175. 6:57and what we also need to think about is
  176. 6:59using a structured approach to support
  177. 7:01flexibility
  178. 7:03so large organizations normally have a
  179. 7:05number of semi-autonomous business units
  180. 7:08and without careful policy coordination
  181. 7:10such a structure results in an overall
  182. 7:13increase in Risk
  183. 7:15so Acquisitions widely varying lines of
  184. 7:19business and distribution across
  185. 7:20multiple countries are all facts of life
  186. 7:23that encourage battles over policy it
  187. 7:27can take many years to eventually arrive
  188. 7:29at policy consensus on some issues
  189. 7:32so can we think of some examples in this
  190. 7:36area so for example when we talk about
  191. 7:38these semi-autonomous business units
  192. 7:41they're all going to have dis different
  193. 7:42risk appetites
  194. 7:44so one example for example is a bank
  195. 7:46where a retail banking division will be
  196. 7:49far more risk-averse than an investment
  197. 7:52banking decision
  198. 7:53the policy therefore must be
  199. 7:55sufficiently flexible to accommodate
  200. 7:57these different risk appetites without
  201. 8:00compromising the entire organization
  202. 8:04and then a policy that is too rigid in
  203. 8:06its approach or its implications can be
  204. 8:09just as problematic as a policy that
  205. 8:11does not result in sufficiency or
  206. 8:13sufficiently strong security controls
  207. 8:18so for this reason it's really in
  208. 8:21sists is on risk management rather than
  209. 8:24compliance to a prescriptive set of
  210. 8:26controls
  211. 8:28and this can be achieved through the use
  212. 8:30of language
  213. 8:32so for example substituting
  214. 8:36um should using should instead of must
  215. 8:38or through the policy structure for
  216. 8:41example devolving some policy
  217. 8:43requirements to guideline level
  218. 8:45um what we're going to go through now is
  219. 8:47I'm going to show you an example where
  220. 8:49we demonstrate that and we work through
  221. 8:51an example of the policy and all the
  222. 8:53different
  223. 8:54subordinate layers
  224. 8:57um to give you an idea of what we're
  225. 8:58talking about so if you take a look here
  226. 9:01at this diagram if I explain it a little
  227. 9:04bit more in detail going from the
  228. 9:06charter through to the processes this is
  229. 9:08one of the ones that we actually saw in
  230. 9:10the last module what do we notice well
  231. 9:13we notice that we've got at the top
  232. 9:15we've got a charter so the Mandate for
  233. 9:17the policy is provided via this Charter
  234. 9:20and because the policy has been signed
  235. 9:22at the very highest level of the
  236. 9:23organization The Authority that it
  237. 9:26carries is preserved in the lower more
  238. 9:28detailed levels that the CEO does not
  239. 9:31need to see
  240. 9:32then working our way down we then have
  241. 9:35standards so the standards describe the
  242. 9:38functional requirements that must be
  243. 9:40universally met with no exceptions other
  244. 9:43than via a formal exemption process
  245. 9:46guidelines are almost exactly the same
  246. 9:49as standards and those follow except the
  247. 9:52individual business units are free to
  248. 9:54deviate from the guidance without
  249. 9:56seeking formal approval
  250. 9:59then working our way down
  251. 10:01we've got this idea that actually by
  252. 10:04doing that this is the mechanism through
  253. 10:06which a minimum standard of security can
  254. 10:09be assured while still allowing for
  255. 10:11flexibility amongst those divisions that
  256. 10:14have different risk appetites as we saw
  257. 10:17in the example of the bank
  258. 10:20so what we do we need to be thinking
  259. 10:22about is we shouldn't ever develop our
  260. 10:24policy in isolation we should build
  261. 10:26support by a process of Engagement
  262. 10:29so policies require Universal support
  263. 10:31and they include and accommodate
  264. 10:34relevant audiences across multiple
  265. 10:36business units
  266. 10:38so policies can be undermined if the
  267. 10:42stakeholders affected by them have not
  268. 10:44helped to shape the outcome
  269. 10:46so strong business unit resistance may
  270. 10:48lead to reluctance by the CEO to approve
  271. 10:51a policy and even if the policy is
  272. 10:53approved the security team may have a
  273. 10:56long and unproductive arguments with
  274. 10:58business units about how to implement it
  275. 11:01or how to comply to it rather than more
  276. 11:05satisfying and productive discussions
  277. 11:07about how security can help achieve
  278. 11:09future business aspirations
  279. 11:12so it's really important there that the
  280. 11:14focus is on doing the right thing at the
  281. 11:17start because otherwise time and energy
  282. 11:19is spent as it says talking about
  283. 11:22compliance and implementation rather
  284. 11:25than looking ahead at
  285. 11:27um creating or achieving future goals
  286. 11:32so who should be
  287. 11:33altered then in this policy what do you
  288. 11:35think so we've talked about the
  289. 11:36stakeholders but who are the people who
  290. 11:38should be consulted in in drafting a
  291. 11:40policy
  292. 11:42so basically it's necessary to consult
  293. 11:44with each business unit that is affected
  294. 11:47by the policy if the policy is to be
  295. 11:49politically and pragmatically viable so
  296. 11:52we need to consult widely with
  297. 11:54stakeholders and especially the
  298. 11:56following
  299. 11:58so in terms of the following
  300. 12:00considerations we need to consult wisely
  301. 12:03with the stakeholders and what we need
  302. 12:06to be doing in in these situations is
  303. 12:08actually identifying instances of
  304. 12:10potentially unacceptable policy outcomes
  305. 12:13such as in the banking example that we
  306. 12:15discussed so this can be particularly
  307. 12:17important in those instances where
  308. 12:19business units are distributed across
  309. 12:22different jurisdictions and they may
  310. 12:25have different needs and different
  311. 12:26abilities to impose controls so in these
  312. 12:29kind of cases the global global
  313. 12:31corporate policy
  314. 12:33can only address those few things that
  315. 12:36are applicable across the entire
  316. 12:38organization
  317. 12:39so we also need to focus on the fact
  318. 12:41that
  319. 12:43um every part of the organization needs
  320. 12:45to be consulted
  321. 12:47but also that the policy implications
  322. 12:49are very well understood so we consult
  323. 12:52with every part of the organization and
  324. 12:54the people and the different business
  325. 12:56units and teams and departments really
  326. 12:58understand
  327. 12:59so once approved there can be no
  328. 13:01complaints that this is a surprise
  329. 13:04so it is effectively a part of the
  330. 13:06awareness and education process
  331. 13:09another thing we should focus on is
  332. 13:11making sure that we build coordination
  333. 13:12among business units that might
  334. 13:14otherwise operate in ignorance or
  335. 13:16Defiance of peer business units
  336. 13:19and this ensures that a rogue business
  337. 13:20unit is not allowed to operate with a
  338. 13:23security profile that would otherwise
  339. 13:25introduce unacceptable risk to the other
  340. 13:27business units
  341. 13:31and then other than consultation during
  342. 13:33development
  343. 13:35we should also ensure wide-ranging
  344. 13:37support at the senior management level
  345. 13:39prior to seeking final approval from the
  346. 13:42CEO or equivalent position
  347. 13:45and and so when we're talking about
  348. 13:47these areas that we need to focus on and
  349. 13:49and who should be consulted and and
  350. 13:50who's involved in this
  351. 13:52who do you think should actually write
  352. 13:54these policies who is going to be
  353. 13:56responsible for ensuring that they are
  354. 13:58written and drafted correctly so stop
  355. 14:00the video for a minute and just think a
  356. 14:01little bit about that
  357. 14:04so
  358. 14:05what we do need to make sure is when we
  359. 14:07have a policy drafted it is drafted by
  360. 14:09someone with competence in policy
  361. 14:11development
  362. 14:12so the rules are only as strong as the
  363. 14:15text that expresses them
  364. 14:16so policy is a really important form of
  365. 14:19communication about risk and the impact
  366. 14:21on the reader will be maximized if the
  367. 14:25text is well crafted in organizational
  368. 14:27appropriateness and writing style
  369. 14:30so what do we mean by that so in terms
  370. 14:32of writing style
  371. 14:35um Gartner which is an American Research
  372. 14:37and advisory firm reviews policies on a
  373. 14:39very regular basis and it tends to be
  374. 14:42obvious when a policy has been written
  375. 14:44by a person who is not experienced at
  376. 14:46drafting policy and who has for example
  377. 14:49maybe primary skills in a different area
  378. 14:51such as technology management
  379. 14:54so what's really important is the person
  380. 14:56who drafts this policy has at the very
  381. 14:58least
  382. 15:00um is or has the policy that has been
  383. 15:02developed by or the rail is reviewed by
  384. 15:04someone with expertise in drafting
  385. 15:06policy
  386. 15:09and we need to develop guidelines for
  387. 15:11drafting policy documents so we're going
  388. 15:14to provide you now with some examples of
  389. 15:16the guidelines or the guidance that may
  390. 15:18be included
  391. 15:19so we need to make sure that when we are
  392. 15:22following these guidelines we need to
  393. 15:24make sure that we take into account the
  394. 15:25mindset of the reader so decide what
  395. 15:28specific effect a policy item should
  396. 15:30have on the reader and keep that purpose
  397. 15:33in mind while writing and editing
  398. 15:36another consideration is to avoid
  399. 15:38opposite obsolescence
  400. 15:40so policy text that it's highly specific
  401. 15:43in terms of dates service or product
  402. 15:46names personal names Etc can easily
  403. 15:49become very quickly outdated through
  404. 15:52changing circumstances that have no
  405. 15:54material effect on the policy
  406. 15:56so the policy needs to be kept generic
  407. 15:58enough to avoid the need for trivial
  408. 16:00changes
  409. 16:02another consideration is to make sure
  410. 16:04that we use a consistent level of
  411. 16:06abstraction
  412. 16:07so requirements documentation can range
  413. 16:11in abstraction level from a very general
  414. 16:13statement of purpose that is signed by
  415. 16:16the CEO to detail specifications for
  416. 16:19registry settings on a specific instance
  417. 16:22of windows
  418. 16:23so treating your policy documents as a
  419. 16:26hierarchical set of separate documents
  420. 16:28as we saw in the in the image earlier
  421. 16:31will make the policy more accessible to
  422. 16:34the reader and will help maintain it
  423. 16:38and another important consideration when
  424. 16:40drafting policy is to make sure that it
  425. 16:42is direct and specific so make it clear
  426. 16:45what is to be done and who is going to
  427. 16:47do it
  428. 16:49and then other considerations in terms
  429. 16:52of the language is to really avoid the
  430. 16:54use of legalese and pompous language so
  431. 16:58policy writers sometimes get concerned
  432. 17:00that plain language will lack impact and
  433. 17:03actually it's the opposite because when
  434. 17:05I'm tempting to influence people the
  435. 17:07more clear we can be and the higher
  436. 17:09level of clarity the easier it is to
  437. 17:10understand
  438. 17:12so using pretentious words such as
  439. 17:14whereas and therefore or mimicking
  440. 17:17contractual Language by using two words
  441. 17:20when actually one will be enough
  442. 17:22sends a message that the writer lacks
  443. 17:25confidence in the innate importance of
  444. 17:27the policy
  445. 17:29another thing in terms of writing the
  446. 17:31policy you need to make sure we stick to
  447. 17:32a consistent Style
  448. 17:34so they're very subtle differences
  449. 17:36between should must and will and
  450. 17:39therefore it's important to choose a
  451. 17:40verb and stick with it and also use a
  452. 17:43consistent person I'll be saying you
  453. 17:45they won and Etc
  454. 17:49and then finally once that's been all
  455. 17:51put together and um written in the most
  456. 17:54effective way possible then what is
  457. 17:57really important is that the document is
  458. 17:58really edited very carefully
  459. 18:01so subject matter experts are not always
  460. 18:04the most effective communicators so
  461. 18:06finding a skilled technical writer to
  462. 18:08ensure that the final document commands
  463. 18:10respect from the reader is actually
  464. 18:12really important
  465. 18:13so have the policy reviewed by several
  466. 18:15members of the target audience to ensure
  467. 18:17that it is clear and realistic
  468. 18:21and then what do we need to think about
  469. 18:23well if we're writing for an
  470. 18:24international audience
  471. 18:27a multi-organization a multinational
  472. 18:28Organization for example has no choice
  473. 18:31but to make compromises in the
  474. 18:32communication of I.T governance policy
  475. 18:35it's not realistic to expect that the
  476. 18:37larger body of IIT administrative policy
  477. 18:40let alone standards and guidelines will
  478. 18:43be translated into every national
  479. 18:45language although it is normal to
  480. 18:47translate a small amount of user policy
  481. 18:49into multiple languages and of course
  482. 18:51English has become the default language
  483. 18:53for it in many organizations
  484. 18:56so what do we need to bear in mind in
  485. 18:59terms of the use of language well as we
  486. 19:01discussed before the avoidance of
  487. 19:03legalese being specific in or being
  488. 19:06consistent in the types of verbs that we
  489. 19:08use and really keeping language simple
  490. 19:11so keeping short keeping sentences short
  491. 19:14and words short avoiding slang avoiding
  492. 19:18culturally specific references and
  493. 19:21whether or not a document is translated
  494. 19:23the simpler it is the more likely it is
  495. 19:26that it will be correctly understood by
  496. 19:28non-native speakers
  497. 19:31and another important consideration is
  498. 19:33to make sure that a native speaker
  499. 19:34reviews the final document so countries
  500. 19:37in which English is widely spoken
  501. 19:39inevitably inevitably develop their own
  502. 19:42idiosyncrasies that are not understood
  503. 19:44by Outsiders
  504. 19:46for example
  505. 19:47um in Swiss Germans refer to servers as
  506. 19:50productive systems instead of production
  507. 19:52systems so in any in any country there's
  508. 19:55always going to be Regional variations
  509. 19:57and development of a language that is
  510. 20:00used which is perhaps a little bit based
  511. 20:02on yeah local local variations and and
  512. 20:06vernacular so what's really important is
  513. 20:08that those are understood in this in the
  514. 20:12sense that it's it's understood and
  515. 20:14reviewed by somebody who's a native
  516. 20:16speaker
  517. 20:18and then remember that language usage is
  518. 20:21not consistent between countries so the
  519. 20:23language is named after England France
  520. 20:25Spain Portugal China and Germany can
  521. 20:28vary significantly when used in other
  522. 20:30countries for example the verb to table
  523. 20:33has opposite meanings in the US and the
  524. 20:36UK
  525. 20:39and then what's therefore important is
  526. 20:42to make sure there are representatives
  527. 20:43of each region to review the final
  528. 20:45document because language problems go in
  529. 20:48both directions so even text that seems
  530. 20:51very simple and clear to a native
  531. 20:52speaker may contain a concept that
  532. 20:55actually is easily misunderstood by
  533. 20:57other cultures
  534. 20:59and then therefore it is important to
  535. 21:02take time out to learn about the
  536. 21:04cultural environmental differences
  537. 21:05because every country has its own forms
  538. 21:08of control and methods of mediating
  539. 21:09disputes and its laws reflect that so
  540. 21:12there can be significant differences
  541. 21:13between countries within the same
  542. 21:15continent that speak the same language
  543. 21:17let alone between countries on different
  544. 21:20sides of the globe so we shouldn't
  545. 21:22assume that every part of our
  546. 21:23organization has the same leadership and
  547. 21:25discipline customs
  548. 21:27and therefore
  549. 21:29um using a user guide is is quite an
  550. 21:32important consideration because it will
  551. 21:34be difficult for staff to comply with
  552. 21:36the policy if they do not understand it
  553. 21:37so while the language in the policy
  554. 21:39statement is presumably safe from an
  555. 21:42administrative and legal perspective
  556. 21:44staff members May simply not understand
  557. 21:46what it actually means
  558. 21:49so it is therefore important to maybe
  559. 21:52consider engaging a professional writer
  560. 21:55to develop a user guide so this is a
  561. 21:57document that is intended to be
  562. 21:58understood by all staff members
  563. 22:00regardless of whether they are
  564. 22:02technically proficient security
  565. 22:04proficient or legally proficient
  566. 22:07so it's written in a manner that engages
  567. 22:09normal late the normal lay person and
  568. 22:13maintains their interests and explains
  569. 22:15requirements to them in a way that can
  570. 22:17be easily understood
  571. 22:20um and if you've got a professional
  572. 22:21writer interview the policy writer if
  573. 22:25you have a professional writer interview
  574. 22:26the policy writer then these questions
  575. 22:27are more likely to be answered and the
  576. 22:30writing style of the user guide is
  577. 22:32likely to be more in keeping with the
  578. 22:34goal of educating the audience
  579. 22:36so these are some guidelines about how
  580. 22:39to make the policy as effective as
  581. 22:40possible what do you think are some of
  582. 22:43the common criticisms of policies so
  583. 22:46stop the video for a second and just
  584. 22:48pause maybe policies as I mentioned
  585. 22:49earlier that you've come across what do
  586. 22:51you think are are common problems and
  587. 22:53criticisms
  588. 22:56so basically one very common criticism
  589. 23:00of policies and standards is that they
  590. 23:03often can tell people what they cannot
  591. 23:05do but rarely tell people what they can
  592. 23:08do
  593. 23:09so it's important therefore to test out
  594. 23:12a number of actual scenarios that staff
  595. 23:14members are faced with and determine how
  596. 23:16the policy supports or inhibits them
  597. 23:19so consider including a section in a
  598. 23:21user guide as discussed earlier that
  599. 23:24outlines common situations that people
  600. 23:27may find themselves in and then describe
  601. 23:30how they can do their work
  602. 23:33so we're going to see here an example so
  603. 23:36for example what if a staff member is
  604. 23:39working remotely and staying in a hotel
  605. 23:42how would you respond if a line of
  606. 23:44business can make a legitimate case for
  607. 23:46the use of cloud technology what about
  608. 23:48the use of personal cloud service
  609. 23:52how will the policy work with a bring
  610. 23:54your own device program
  611. 23:56if another organization has control over
  612. 23:58your information for example because of
  613. 24:01Outsourcing how will this work when the
  614. 24:04policy changes
  615. 24:05will the vendor continue to use the old
  616. 24:08policy or will there be a commercial
  617. 24:10implication to switch to the new
  618. 24:12policies
  619. 24:13so use high profile events reported in
  620. 24:15the media or important new legal
  621. 24:17developments to develop scenarios for
  622. 24:20verifying the extent to which your
  623. 24:22policy protects your organization
  624. 24:25and how will you therefore ensure
  625. 24:27compliance what do we need to consider
  626. 24:30so we do need to think about is
  627. 24:34um the policy can only be effective if
  628. 24:36we can verify compliance
  629. 24:38so what we might want to do is consider
  630. 24:40going through each policy requirement
  631. 24:42and expressingly considering the
  632. 24:45following questions
  633. 24:46so if a user asks you how do I comply
  634. 24:50what specific measures will you
  635. 24:52recommend
  636. 24:53how will you measure compliance how will
  637. 24:56you detect non-compliance
  638. 24:58and how will you report on compliance in
  639. 25:01terms of both the extent and the
  640. 25:03business value
  641. 25:06and if you cannot verify compliance that
  642. 25:09it's possible that the policy statement
  643. 25:11may be unenforceable and this may
  644. 25:14eventually lead to a situation in which
  645. 25:16an auditor will issue an audit finding
  646. 25:19that you are unable to address
  647. 25:21and more importantly you are left with a
  648. 25:24control that is not fully effective in
  649. 25:26mitigating risks
  650. 25:29so just some notes regarding this as we
  651. 25:33are now reaching the end of this session
  652. 25:34so in terms of document lifetimes
  653. 25:38document lifetimes are suggestions only
  654. 25:40and local preferences may vary so local
  655. 25:44preferences may also dictate preferred
  656. 25:46locations for some of the content of the
  657. 25:48policy for example some organizations
  658. 25:51include security principles in the
  659. 25:53Enterprise security Charter whereas
  660. 25:56others actually include them in the
  661. 25:58policy
  662. 25:58another thing to be consistent of is
  663. 26:01using a consistent style so the paper
  664. 26:04the article keywords for use in request
  665. 26:07for comments to indicate requirement
  666. 26:09levels
  667. 26:10um uh RFC for short contains
  668. 26:13internationally accepted guidelines on
  669. 26:16the use of these words so a couple of
  670. 26:18footnotes there for you to think about
  671. 26:21so we've now finished this session on
  672. 26:24policies hopefully now you've got a much
  673. 26:27clearer idea on how to create an
  674. 26:29effective policy in terms of the process
  675. 26:31to follow the language to use taking
  676. 26:34into account International audiences and
  677. 26:36therefore who should be involved in the
  678. 26:38development of a policy and maintaining
  679. 26:40it okay so thank you for listening and I
  680. 26:43will see you in the next session

About this transcript

This page contains the full transcript of Strategic Management 2 Policies Free MBA course by Swiss School of Business Research, generated from the public captions YouTube serves with the video. The transcript has 4,052 words across 680 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.