The risk assessment that should come first
A risk assessment tells the organization which risks it actually has. Nearly every other governance activity, the policy review included, is guesswork without it.
Ideas and field notes
Practical writing about cybersecurity, compliance, and sustainable security operations.
A risk assessment tells the organization which risks it actually has. Nearly every other governance activity, the policy review included, is guesswork without it.
An annual review should test a policy against current obligations and operations, then record decisions, evidence, owners, and follow-up work. Most standards require the review; few organizations get full value from it.
A useful policy and/or procedure identifies the evidence that will show whether the organization is actually following it.
A policy states what the organization will do; its procedures state how, who, and with what. Keeping them apart makes both usable and keeps neither one stale.