unix and linux operating commands

Are policies mandatory and guidelines optional?

 
Thread Tools Search this Thread
# 1  
Old 07-11-2009
Are policies mandatory and guidelines optional?

Although this is often expressed, I fundamentally disagree that policies are mandatory whereas guidelines are optional.  This to me is a rather naïve assessment, and is distinctly unhelpful, misleading even.  Let me explain.

For a start, do you truly understand the distinction between "mandatory" and "optional"?  Are they really (as some claim) as different as binary and analogue?  I beg to differ.  In my world, they are both analogue concepts.  They are both a matter of degree.

Occasionally by "mandatory" the information security manager or CISO probably does mean an absolute hard-and-fast rule with no exemptions (authorized non-compliance) or exceptions (unauthorized non-compliance) whatsoever being permitted.  However this kind of binary situation tends to be rather unusual in information security.  More often, "mandatory" statements are in fact very strong requirements or obligations but if there are justifiable reasons for not complying, that's probably OK provided the resulting risks are understood and are acceptable to management - an important proviso.*  You may take the hard line that policies can only contain absolutely mandatory statements, in which case you will end up with an admirably succinct set of policies ... but a long list of exemptions and exceptions.  This mess is not easy to read, and worse still implies that exemptions and exceptions are the norm, not the exception (if you get my drift).

Likewise, "optional" could mean 'go ahead if you feel like it, otherwise ignore this and do whatever you want' but more often means 'advisory' or 'recommended' or 'strongly recommended' or 'ignore this at your peril' with many other context-dependent interpretations.  In other words, "optional" is not a specific strength of requirement but a broad range, meaning something slightly to a lot less than absolutely mandatory. 

There's nothing wrong in my book with policies offering implementation guidance as well as requirements, provided the wording is such that the intention is clear either way.  Words such as 'must' and 'shall' and 'will' normally mean firm requirements, whereas 'may' and 'should' and 'ought' and 'could'  and 'can' normally imply some discretion.  It is entirely appropriate for policies to allow management and possibly staff discretion in some circumstances, without the need always to create and seek management approval for a formal policy exemption or ending up by default with a policy exception. Furthermore, little bits of helpful advice and explanation such as examples make the requirements clearer.  Flexibility in the wording and interpretation can make a policy much more readable which creates a very important benefit per se: policies that are too formalised and/or attempt to lay out explicit requirements for all possible circumstances are stilted, difficult to read and hence are mostly not read in practice.  Read a typical contract or law, in detail, to see what I mean!  If you really intend your information security policies to sit on a shelf collecting dust until used in anger by the lawyers, go ahead with this approach but that is not generally accepted good information security practice.

Again, if you feel that guidelines are purely advisory, then you need to be extremely careful not to even mention any mandatory rules, requirements, laws or other obligations unless you have very deep pockets, since you will create a serious earning opportunity for the lawyers.  Guidelines often refer to more or less mandatory requirements from the policies and standards, offering tips or advice on how to implement them.  If you view the organization's policy/standards/procedures/guidelines etc. as a classic layered triangle, the mandatory requirements are formally identified in broad terms in the upper level/s of the triangle and trickle down through the entire hierarchy, with more and more helpful explanatory advice and details being added to items at the lower levels. 

Image


Therefore many things identified in a typical guideline will in fact be considered mandatory, whereas others are merely helpful suggestions.  Careful wording can or rather should make the distinction clear.  Mandatory requirements or obligations are often identified by referencing applicable policy statements.  In some cases, the exact wording may be formally quoted from a policy, and then "interpreted" in the guideline for one or more specific contexts. 

Finally, I'll just mention that essentially the same considerations apply to standards, procedures, advisories, recommendations, briefings, acceptable use policies, terms and conditions of employment and a million other things we use at work.   It's a brave or foolhardy information security manager/CISO who states categorically that particular documents are either totally mandatory or optional.

Bottom line: if you really intend to take such a clear-cut line on the differences between policies and guidelines in terms of the mandate or obligation to comply, be aware that in so doing you will be creating a whole new set of problems.

Kind regards,
Gary Hinson CISSP
ISO27001security
NoticeBored
IsecT

* Even laws work this way.  The police and judicial systems have some discretion in applying them.  Some commonplace practices break the laws and are strictly-speaking illegal, but offenders are not necessarily prosecuted or if they are may be given nominal penalties.

Image
Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

7 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Bash shell script with mandatory and optional input

Hello I would like to write a bash shell script which will need user to supply one variable which is mandatory and some other optional variables. If mandatory variable is not supplied by user, the script will exit. If optional values are not supplied by user, hard-coded value (in the script)... (3 Replies)
Discussion started by: atanubanerji
3 Replies

2. Shell Programming and Scripting

How to match mandatory column in file.?

(3 Replies)
Discussion started by: Rishabh Jain
3 Replies

3. AIX

Mandatory FS for mksysb

Hi all, my first post. Be kind to me and to my english writing (i'm french) :) During mksysb backup, some files are moving. I don't know yet which files (i'm starting a new job). For now, i'm wondering which fs are mandatory for a mksysb backup. Currently, hereafter the content of rootvg :... (5 Replies)
Discussion started by: Fundix
5 Replies

4. Shell Programming and Scripting

Usage: optional and mandatory arguments

I have an awk script which can be used in the following ways: xi and xf will only be mandatory when processing the file fin.zc. awk -v xi=0/-0.5 -v xf=80/30 -f ./zc2cmd.awk fin.zc > fout.cmod awk -f ./zc2cmd.awk -u awk -f ./zc2cmd.awk --usg awk -f ./zc2cmd.awk -e awk -f ./zc2cmd.awk... (1 Reply)
Discussion started by: kristinu
1 Replies

5. UNIX for Dummies Questions & Answers

How to implement password policies?

How would i ensure that whenever any user changes the password it should meet following. It should be more than 7 Characters. Atleast one Upper case character,digit and special character present. Password is not same as username or dictionary word . User should get email after changing his... (2 Replies)
Discussion started by: pinga123
2 Replies

6. UNIX for Advanced & Expert Users

Mandatory fileds in Bugzilla

Hi, We need to configure some of the fileds in bugzilla like Platform,OS, Version etc are mandatory. Is it possible to set, if yes then how to configure. Thanks & Regards, Bache (0 Replies)
Discussion started by: bache_gowda
0 Replies

7. UNIX for Dummies Questions & Answers

passwd policies

Hi Guys, i want to ask how i can add a special policies for users. for example i want so say that each user must chnage the password every 4 weeks the password should have min 5 chacaters ........ passwd -n DAYS ....... and which string is for the min password lenght ...... many thx! (1 Reply)
Discussion started by: scottl
1 Replies
Login or Register to Ask a Question