NEWSLETTER
September 22, 2026
In Parts 1 & 2 we explored the key elements involved in building, implementing, and maintaining an effective IT policy framework - who should be involved in policy development, why stakeholder engagement matters, and how to create and maintain effective policies.
This final part discusses common policy management challenges, policy ownership and review processes, and managing third-party supplier risk.
Creating and maintaining effective IT policies is about far more than producing documentation. Organisations must identify the right policies, position them within a clear governance framework, and keep them aligned with evolving business, technology and regulatory requirements.
A comprehensive IT policy framework aligned with recognised good practice will typically comprise 20 to 25 policies covering key operational areas, although the number will vary according to the organisation’s size, complexity, risk profile and regulatory obligations. Examples of user-focused policy topics include – Access Control, Password and Authentication, Information Management, and an Acceptable Use Policy. Technical policy examples include Network Management, Software Management and use of Cloud Services.
To ensure staff understand what is expected of them and apply also those expectations consistently and effectively, policies should be supported by related standards, guidelines, operational processes and procedures.
Once policies are in place, effective lifecycle management becomes essential. Staff changes may result in original authors leaving the organisation increasing the risk that continuity will be lost. Without clear ownership and defined review processes, policies can become inconsistent, duplicated or outdated.
Organisations frequently encounter policy lifecycle issues such as:
An ad hoc approach makes it difficult to build and sustain a strong culture of information security.
To ensure policies remain valuable as business and technology requirements evolve, organisations should consider:
Policies should have clearly assigned owners who are responsible for reviewing content and coordinating updates to ensure the policies continue to be fit for purpose and remain current. As a general guide, policies should be reviewed:
Effective ownership with defined review processes will help address policy management and lifecycle challenges and issues.
Many organisations rely heavily on cloud providers, software vendors, managed service providers, consultants, and contractors.
As a result, information security responsibilities often extend beyond internal staff and systems so your IT policies should cater for these relationships and should clearly define:
Third-party arrangements should also be subject to due diligence, ongoing monitoring, and periodic review to ensure security expectations continue to be met.
Protocol Policy Systems specialises in helping organisations develop, deliver and maintain their IT policies. Our Policy Management as a Service offering establishes the foundations for a secure computing environment and improved cybersecurity maturity and resilience. Contact us today to discuss how the service can support your organisation.
PROTOCOL POLICY SYSTEMS
Fill in the form or call us on (UK) +44 845 241 0099 or (NZ) +64 9 570 2233