Developing and Implementing IT and Digital Policies
IT and digital policies are often outdated, copied from templates or ignored, leaving organisations exposed to security incidents, data protection breaches and audit findings. This programme gives IT, security, compliance and business leaders a practical method to develop, approve, implement and monitor a policy framework that people understand and follow.
Most organisations have IT policies, but many are long, technical documents written once for an audit and rarely read. They do not cover cloud services, remote work, personal devices, data sharing or artificial intelligence. Ownership is unclear, exceptions are granted informally, and nobody checks whether policies are applied in practice. When an incident or audit occurs, the gap between the written policy and actual behaviour becomes visible.
This programme treats policy as a governance tool rather than a document exercise. It moves from designing the policy framework and hierarchy, to drafting clear policies for the main IT and digital risk areas, to aligning them with regulatory and standard requirements, to implementing them through processes, technology and awareness, and finally to monitoring compliance and keeping policies current.
Built on recognised practice. The programme references ISO/IEC 38500 on the governance of IT, COBIT 2019, ISO/IEC 27001 and ISO/IEC 27002 on information security, the NIST Cybersecurity Framework 2.0, ISO 22301 on business continuity and ISO/IEC 42001 on AI management systems. It also considers how national cybersecurity and data protection requirements in the region shape policy content.
Decisions this programme improves. Which policies the organisation actually needs and at what level of detail; who owns and approves each policy; how to handle exceptions; how to balance security with usability and business needs; which controls and indicators show that policies are working; and when a policy should be reviewed or retired.
How it is delivered. Twenty hours across five sessions, built around one running case: an organisation adopting cloud services and generative AI tools with an outdated policy set and a forthcoming regulatory audit. Participants map gaps, redraft selected policies, design an implementation plan and define compliance indicators.
In-house option. For organisations, the programme can be tailored to your own policy library, regulatory obligations, technology environment and governance structure, and delivered to IT, security, legal, risk and business teams together.
Who Should Attend
Objectives
Course Outline
Competencies
Vienna
Related Topics
IT functions are often judged on uptime and cost while leaders expect them to shape strategy, and the gap shows up as projects that do not deliver value and investment that is hard to justify. This programme gives IT and digital leaders a practical way to use ITIL 4 to align direction, planning, services and improvement with organisational goals.
GIS projects often deliver software and maps but not the decisions they were funded to support: data arrives late or unfit for use, requirements shift and the system is hard to sustain after go-live. This programme gives GIS managers and project leaders a structured approach to plan, procure, deliver and sustain GIS projects, from user needs to operational handover.
To provide IT professionals with the knowledge, skills, and best practices in portfolio management, enabling them to maximize the value of IT investments and align IT initiatives with organizational strategy.
