Specialty Forums
Security and Virus
General Hardware
CPUs/Overclocking
Networking
Digital Photo/Video
Office Software
PC Gaming
Console Gaming
Programming
Database
Web Development
Digital Home

General Forums
Windows XP
Windows Vista
Windows 95/98
Windows Me
Windows NT
Windows 2000
Win Server 2008
Win Server 2003
Windows 3.1
Linux
PDAs
BeOS
Novell Netware
OpenVMS
Solaris
Disk Op. System
Unix
Mac
OS/2

Drivers
Driver Scan
Driver Forum

Software
Automatic Updates

BIOS Updates

My Computing.Net

Solution Center

Free IT eBook

Howtos

Site Search

Message Find

RSS Feeds

Install Guides

Data Recovery

About

Home
Reply to Message Icon Go to Main Page Icon

IT Policy

Original Message
Name: jefton5
Date: August 10, 2007 at 03:24:37 Pacific
Subject: IT Policy
OS: SBS 2003
CPU/Ram: 4GB
Model/Manufacturer: Dell
Comment:
Hi Everyone. I'm in a bit of a pickle. I need to write up an IT Policy for a small company with only about 14 users. We are about to install a Windows SBS 2003 Server domain but I need to write up a Policy be obviously doing that. I need some advice as to where to start. Or templates to work from. Anyone with some advice, ideas, templates etc. will be massively appreciated. Thanks guys

Report Offensive Message For Removal


Response Number 1
Name: Curt R
Date: August 10, 2007 at 05:33:56 Pacific
Subject: IT Policy
Reply: (edit)
If you're referring to an "appropriate use" policy, the first thing on it should be "nothing illegal" as per your local and federal laws.

Then list the things they're not allowed to do that are legal, like playing games or chatting online during work hours.

I suspect you'll need the big boss (or owner's) input on this since it has to "come from above" right....or at it will least rate some discussion with management.


Report Offensive Follow Up For Removal

Response Number 2
Name: XpUser
Date: August 10, 2007 at 06:10:09 Pacific
Subject: IT Policy
Reply: (edit)
I second the above. You may also want to read the following article to get ideas for discussion with your boss.

http://www.windowsecurity.com/artic...

i_Xp/VistaUser


Report Offensive Follow Up For Removal

Response Number 3
Name: jefton5
Date: August 10, 2007 at 06:43:02 Pacific
Subject: IT Policy
Reply: (edit)
Hi guys. Thanks very much for the replies.
XPUser - Thanks for the link. It does give me a headstart.

Curt R - I don't fully understand what you mean by an 'appropriate use' policy. Maybe I did not phrase it right or explained properly. I need to write a general company IT Policy e.g. like infrastructure in words really together with what I've done on the server. Say a heading like Internet Access - then I explain in use what I've implemented - no access to users during maybe 9 am and 5pm; only to be used for business reasons.

The reason is that I have to make a proposal in writing to the General Manager as to how I think the new Domain should be implemented, what everyones responsibilities is, restriction throughtout etc.

Just needs some tips as to where to start!!!

Thanks


Report Offensive Follow Up For Removal

Response Number 4
Name: jefton5
Date: August 10, 2007 at 06:45:33 Pacific
Subject: IT Policy
Reply: (edit)
Maybe if you can recommend like a checklist to give to by Manager where he can fill in what can be acessed, by who, who has access to what. Something / checklist from where I can then go and configure the Server according to that 'rules' set or chosen / noted by him. Jefton

Report Offensive Follow Up For Removal

Response Number 5
Name: XpUser
Date: August 10, 2007 at 07:00:05 Pacific
Subject: IT Policy
Reply: (edit)
You're welcome, jefton5.

Actually it's never easy to implement IT Policy. On one hand when you get too strict, you will be encouraging the best people to look for another job. On the other hand you will have to put up with tech savvy employees. You need to balance the policy between the two.

Another article that may interest you is HERE. It talks about the common challenge that the IT staff face with tech-savvy employees. An ongoing discussion regarding this topic can be found following this article.


i_Xp/VistaUser


Report Offensive Follow Up For Removal


Response Number 6
Name: jefton5
Date: August 10, 2007 at 07:28:15 Pacific
Subject: IT Policy
Reply: (edit)
XPUser thanks a mil!!! Do perhaps know where I can find a IT Policy template that I can work from a use as a baseline? Or maybe something in a checklist format? Thanks again

Report Offensive Follow Up For Removal

Response Number 7
Name: XpUser
Date: August 10, 2007 at 07:36:41 Pacific
Subject: IT Policy
Reply: (edit)
I guess you can start with the following

http://tqmcube.com/sample_aup.php

As stated in this article you do need to consult an attorney before you implement it or else you will find yourself slapped with expensive lawsuits. Of course Life is a bitch but that's the way it is today - everybody's litiguous.

i_Xp/VistaUser


Report Offensive Follow Up For Removal

Response Number 8
Name: jefton5
Date: August 10, 2007 at 08:58:47 Pacific
Subject: IT Policy
Reply: (edit)
XPUser. Once again thanks very much. The info you referred me to really was very helpful. I must admit I was maybe underestimating the extent and amount of work involved in writing up an IT Policy. Thanks

Report Offensive Follow Up For Removal

Response Number 9
Name: XpUser
Date: August 10, 2007 at 09:09:15 Pacific
Subject: IT Policy
Reply: (edit)
Again you're very welcome. No offense intended but I gather it was something you thought of doing to impress your boss, no? If this was the case, take my advice - look the other way around and let your boss fence for himself. Suggesting something like this out of the blue to the company can entice them to take advantage of your good deed and use you as their scapegoat when something go wrong in the IT Department. All bosses are vultures anyway (some take all the trouble to make sure it don't show up in the employees' radars at all.)

i_Xp/VistaUser


Report Offensive Follow Up For Removal

Response Number 10
Name: wanderer
Date: August 10, 2007 at 09:36:01 Pacific
Subject: IT Policy
Reply: (edit)
I think jefton5 you need to do the old "divide and conquer" method.

You need to document the following;
*ip plan
*infrastructure plan [how everything connects and server(s) physical configs]
*security plan [how you protect the network ie av, spyware checkers...door locks, who has access and at what level, how you protect your backups, etc]
*disaster recovery plan [what to do if the server dies, what to do if the building burns down, how you are going to recover, etc]
*internet and email appropriate usage policy
*computer and network appropriate usage policy [allow usb sticks from home? Take to and from work? Users install programs? etc.]
Server config documentation [GPO settings, user rights levels, etc]

Its a lot of work but once it is done its just a matter of updating as changes occur.

Imagine the power if you knew how to internet search


Report Offensive Follow Up For Removal

Response Number 11
Name: JohnCarrJr
Date: August 10, 2007 at 11:50:13 Pacific
Subject: IT Policy
Reply: (edit)
SANS has some tempates on thier website that are pretty nice:

http://www.sans.org/resources/polic...

John Carr
Network Analyst


Report Offensive Follow Up For Removal

Response Number 12
Name: jefton5
Date: August 10, 2007 at 12:21:18 Pacific
Subject: IT Policy
Reply: (edit)
Hi guys. I actually feel overwhelmed by all the advice and info you guys have to share and have given me so far. Thanks a lot.
XPUser - I didn't actually suggest anything. I was recruited just for general IT support but mostly to support another guy with web design and search engine optimization. This was however drafted as part of my Job Description to also see to the 'upgrade' to a Domain environment.

And wanderer and JohnCarrJr thanks for your advice also. The thing is that I don't have a problem actually implementing Group Policies, user rights etc., but just with documenting everything and drafting an initial IT Policy. Thanks


Report Offensive Follow Up For Removal

Response Number 13
Name: XpUser
Date: August 10, 2007 at 12:49:05 Pacific
Subject: IT Policy
Reply: (edit)
Gotcha! I have to say this was an interesting topic - something we don't often see posted & asked on this board.

i_Xp/VistaUser


Report Offensive Follow Up For Removal

Response Number 14
Name: JohnCarrJr
Date: August 10, 2007 at 13:03:16 Pacific
Subject: IT Policy
Reply: (edit)
I support a small bookstore "on the side". I setup his network and servers and desktops. I only wish I knew about these templates myself back then. He calls me for every little thing, especially when I'm on vacation!

But, the money's good I guess. I always send him bills between $400-1000, and he still pays them! That cash comes in handy sometimes.


John Carr
Network Analyst


Report Offensive Follow Up For Removal

Response Number 15
Name: jefro
Date: August 12, 2007 at 13:18:46 Pacific
Subject: IT Policy
Reply: (edit)
Just copy it from the MS site. It is already there.

http://www.microsoft.com/technet/se...

http://www.microsoft.com/technet/se...

As you say, a security template is easy to install and enforce in a domain where only a few people have access to admin. As always you try to run stuff from "run as".

My suggestion is to keep a few old junky live linux cd running computers for internet access. Remove all company's access from the web.

I read it wrong and answer it wrong too. So get off my case you goober.


Report Offensive Follow Up For Removal

Response Number 16
Name: jefton5
Date: August 14, 2007 at 08:33:11 Pacific
Subject: IT Policy
Reply: (edit)
Hi everyone. I apologise for the late reply and thank you, but I was really busy the last two days.

Once again to everyone who posted solutions and advice, it really is appreciated. I cannot explain how much I've learned here without having to follow the normal route of buying books and reading them like mad.

It all seems too much but any other views / advice still out there will still and always be appreciated. Don't want to drag on too long cause I already feel guilty just taking up so much of your time. THANKS!


Report Offensive Follow Up For Removal



Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: IT Policy 

Comments:

 
  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 


Data Recovery Software




CPU and Graphics Upgrade Questions

VIRUS ALERT in Taskbar, HELP!

DSHUB24 Connection Problems

need help with dsl and dial up

novel 3.12


The information on Computing.Net is the opinions of its users. Such opinions may not be accurate and they are to be used at your own risk. Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE

All content ©1996-2007 Computing.Net, LLC