IT Policy Help
June 21, 2011 3:18 PM Subscribe
What questions should I ask applicants for a position involving the development of IT policies?
I work for a mid-sized non-profit. One of my large projects for both this year and next revolves around technology - upgrading systems, replacing old, mission critical equipment, and so forth. Part of the work is to review and update our existing IT policies, and to create the pieces that are missing (security, disposal of hardware, etc). I have the funds to hire a consultant to work on these with me, and I have two potential candidates to interview.
However, I am feeling uncertain about what would make good interview questions for the candidates beyond questions about time and project management, working within a team, etc. What questions would help me determine the candidate with the best skills to address IT policy development and creation?
posted by never used baby shoes to technology (5 answers total) 1 user marked this as a favorite
"What constitutes a good policy?" (Length, format, structure, etc)
"What policy frameworks have you worked with before? What were the advantages and drawbacks?" (In my world, you might hear about COBIT or ISO 27001)
"How should policies be tiered or structured?" (For example, for me, disposal of hardware isn't a policy, it's a standard. Policies are high level, approved by the board of directors, and rarely change. Standards adhere to the policy but provide specific direction on how to perform tasks in a compliant manner.)
"How should policies be approved and how should acceptance and adherence be tracked?"
If your consultant does this for a living, they probably have a big book of policies they're going to do a search-and-replace on to insert your org's name. Will this be OK? Try to get an idea of the amount of time they expect to spend on a particular policy. Who are the constituents they would expect to work with on a Document Destruction policy, for example.
Your policies should be a informed by your org's mission, balancing industry, regulatory, and other requirements. Is the consultant familiar with the regulatory requirements and industry best practices you'll be expecting to work against?
Finally, how will you/the consultant track the change and approval of policies? Paper docs with signatures? Word docs on Sharepoint? A GRC tool like Archer?
posted by These Premises Are Alarmed at 4:10 PM on June 21, 2011