NEWSLETTER

Part 2: Building Strong IT Policy Foundations for Local Government Reorganisation

Steve Macmillan

In part one of this series we outlined how a key part of LGR planning and transition will be ensuring that the rules for managing, operating, and using information systems are clearly defined. This means developing IT policies and procedures that set out how a newly formed unitary authority will manage information securely throughout its lifecycle, and protect it from unauthorised access or misuse.

While it may be tempting to adapt existing policies from the constituent councils of a new unitary authority, this approach could prove to be a false economy. Developing new policies and procedures from the outset provides an opportunity to streamline the process, encourage stakeholder engagement and collaboration, establish clear information security requirements for the new organisation, and ensure alignment with current standards and best practice.

Read how Rother District Council found an alternative way to get policy work done whilst in the midst of a technology refresh project.

Once an organisation understands the importance of IT policies, the next challenge is developing and maintaining them effectively.

In this article, we explore the key elements involved in building, implementing, and maintaining an effective IT policy framework including:

  • Who should be involved in policy development,
  • Why stakeholder engagement matters, and
  • How organisations can create and maintain effective policies 

Who should be involved in policy development?

Creating effective IT policies requires collaboration across several roles. Stakeholder engagement should occur throughout the policy lifecycle, from development and review through to approval and ongoing maintenance.

Involvement should include:

  • Executive Leadership Team – to provide strategic direction, sponsorship, and approval
  • CIO, IT Manager, and Technology Teams – to define technical requirements and security controls
  • Information Management and Records Teams – to support information governance and lifecycle management
  • Human Resources – to align policies with employee responsibilities and organisational processes
  • Risk, Compliance, Privacy, and Legal Teams – to manage regulatory and compliance obligations
  • Business Unit Representatives – to ensure policies are practical and aligned with operational needs

When developed collaboratively, IT policies are more likely to be adopted, supported, and embedded throughout the organisation.

Why stakeholder engagement matters

Engaging stakeholders throughout the policy development process helps ensure policies are practical, relevant, and aligned with operational requirements. It also increases buy-in across the organisation, making policies more likely to be understood, adopted, and consistently followed.

Stakeholder engagement can help organisations to:

  • Identify operational challenges and risks that may otherwise be overlooked
  • Ensure policies are practical and achievable in day-to-day operations
  • Align security requirements with business objectives
  • Reduce resistance to policy changes
  • Improve awareness, ownership, and accountability
  • Support a stronger culture of information security

For new unitary authorities, stakeholder engagement is particularly important given that the new entity will incorporate a diverse range of users, a different operating model, and services that rely on information systems. Involving representatives from technology, information management, human resources, legal, risk, and operational teams helps ensure policies reflect both security requirements and business realities.

Creating and maintaining effective IT Policies

Effective IT policies should be clear, practical, and aligned with both organisational objectives and security requirements. Policies that are overly technical or difficult to understand are less likely to be adopted and followed by staff. A policy should provide clear direction while remaining flexible enough to support changing technology, business processes, and risk environments.

When creating policies, organisations should:

  • Define the purpose and scope of the policy
  • Clearly outline roles and responsibilities
  • Align requirements with legal, regulatory, and contractual obligations
  • Align with recognised standards and frameworks such as ISO 27002, PCI-DSS, Cyber Assessment Framework, where appropriate
  • Consider operational requirements and business objectives
  • Use clear and accessible language
  • Establish review and approval processes
  • Communicate policies effectively to staff and stakeholders
  • Provide ongoing awareness and training to support adoption and compliance

Once developed, for policies to be effective, they need to be easily accessible, regularly reviewed, and actively supported through awareness and training programs.

An ad hoc approach to maintaining policies makes it difficult to embed a strong culture of information security. Policies can quickly become outdated, reducing their effectiveness and increasing organisational risk. 

To address these issues policies should have clearly assigned owners who are responsible for reviewing content, coordinating updates, and ensuring the document continues to reflect organisational, regulatory, and technology changes.

Download the whitepaper: The Role of IT Policies in Managing Technology Changes

In part 3 of this series we will cover:

  • Common policy management challenges
  • Policy ownership and review processes
  • Managing third-party and supplier risk

Contact us today to discuss how we have helped Local Authorities to valuable free up resources to focus on key projects in times of changes.

PROTOCOL POLICY SYSTEMS

Contact Us Today

Fill in the form or call us on (UK) +44 845 241 0099 or (NZ) +64 9 570 2233