Draw practical lessons from failures in technology use and security policy without assigning blame that suppresses reporting.
Building Information Technology Use and Security Policies
An applied course in technology use and security policy built around the decisions practitioners actually face.
Course Overview
Technical debt in technology use and security policy is borrowed against future delivery capacity, at compound interest. Most outages involving security policy are triggered by a change somebody considered routine. Practitioner evidence points the same way: the technology and systems delivery discipline improves fastest where responsibility for it is named and owned. Every module pairs a short input on technology use and security policy with structured practice on the participant's own material. It treats this aspect of technology and systems delivery as an operating discipline and equips participants to run it as one. The version of security policy described in the manual and the version practised on the floor tend to diverge over time. It suits anyone whose decisions touch technology use and security policy, in large organisations and small ones alike. Participants take away a working set of documents supporting security policy, ready to be adapted internally. The course ends by identifying what the participant will stop doing to make the practice within technology and systems delivery sustainable.
Expected Learning Outcomes
Design the architecture of security policy around its failure modes, not only its happy path.
Apply data protection and retention requirements within technology use and security policy.
Apply access control and least privilege throughout security policy.
Test the organisation's response to technology use and security policy under conditions that are less than ideal.
Plan capacity for security policy against measured growth rather than optimism.
Establish escalation routes for technology use and security policy that work outside normal hours.
Who Should Attend
Risk managers assessing the exposure created by technology use and security policy.
Software engineers and technical leads building security policy.
Technical staff being prepared for supervisory responsibility over technology use and security policy.
Project managers delivering changes to security policy.
Database administrators managing data within technology use and security policy.
Quality and test engineers verifying security policy.
Course Modules
Technology use and security policy: documentation, support and handover
2 sessions · 8 pointsSession 1Keeping technology use and security policy alive after the initial push
- Write down the assumptions underpinning the approach to technology use and security policy.
- State the availability and recovery objectives for security policy as numbers.
- Arrange the handover of technology use and security policy so capability survives staff changes.
- Identify the single points of failure in security policy.
Session 2The change to security policy that caused the last outage
- Measure current load on technology use and security policy and project it forward twelve months.
- Run a load test on security policy at expected peak plus a margin.
- Collect evidence on the present handling of technology use and security policy before proposing changes.
- Check that security policy still works when volumes rise unexpectedly.
Security policy: incident response and severity
2 sessions · 8 pointsSession 1Who answers for security policy, and to whom
- Restore a backup of technology use and security policy in a test environment and time it.
- Confirm data retention and deletion rules applied within security policy.
- Set out how exceptions to technology use and security policy are requested and approved.
- Establish what evidence demonstrates security policy is under control.
Session 2Documenting security policy so someone else can operate it
- Apply change control to technology use and security policy including emergency changes.
- Record the technical debt in security policy and schedule repayment.
- Document the runbook for technology use and security policy to the level a new engineer could use.
- Define incident severity levels for security policy and the response each triggers.
Security policy: backup, recovery and continuity
2 sessions · 8 pointsSession 1Sizing capacity for security policy on measured growth
- Test the failover for technology use and security policy rather than assuming it works.
- Identify where judgement in security policy is legitimate and where it is not.
- Draft the minimum viable technical standard for technology use and security policy.
- Confirm every release of security policy can be rolled back within a defined time.
Session 2Comparing technology use and security policy with recognised practice
- Define acceptance criteria for technology use and security policy in advance.
- Benchmark the organisation's security policy against comparable operations.
- Plan the sequence in which improvements to technology use and security policy will be introduced.
- Confirm the support model and escalation path for security policy.
Security policy: change control and rollback
2 sessions · 8 pointsSession 1Retiring the legacy part of security policy
- Prepare the response for the most likely failure in technology use and security policy.
- Review access rights on security policy and remove what is no longer needed.
- Set out the decisions in technology use and security policy that require sign-off and by whom.
- Agree the smallest change to security policy that would be visibly useful.
Session 2Making releases of security policy routine instead of risky
- Review logging on technology use and security policy for coverage and retention.
- Decide what will be stopped to create capacity for security policy.
- Inventory third-party dependencies inside technology use and security policy and their update status.
- Rank the weaknesses in security policy by consequence rather than by ease of fixing.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.