SlideShare a Scribd company logo
1 of 4
Download to read offline
Abstract—Policy management in organizations became rising
issue in the last decade. It’s because of today’s regulatory
requirements in the organizations. To manage policies in large
organizations is an imperative work. However, major challenges
facing organizations in the last decade is managing all the policies in
the organization and making them an active documents rather than
simple (inactive) documents stored in computer hard drive or on a
shelf. Because of this challenge, organizations need policy
management program. This policy management program can be
either manual or automated. This paper presents suggestions towards
managing policies in organizations. As well as possible policy
management solution or program to be utilized, manual or automated.
The research first examines the models and frameworks used for
managing policies from various perspectives in the literature of the
research area/domain. At the end of this paper, a policy management
framework is proposed for managing enterprise policies effectively
and in a simplified manner.
Keywords—Policy, policy management, policy management
program, policy repository.
I. INTRODUCTION
OLICY can be defined as plan of action used by an
organization to give instructions from its senior
management to those who make decisions to take actions,
and perform other duties on behalf of the organization’s
context [1]. Major challenge facing organizations in the last
decade is how to distribute all their policies to target
employees. And to keep them read, understand and comply
with all policies in the organization [3]. Because of this
challenge, there is a strong demand in organizations for some
kind of policy management solution. This policy management
solution can be either manual or automated [3]. Policy
management in the context of this paper is the conversion of
policies into practical and enforceable [3] documents, rather
than simple documents in which employees neglect or don’t
read it, that can be implemented in the organization as whole.
However, most organizations manage their policies manually.
Weisman quoted “Developing a manual policy management
solution is creating a set of procedures that reflects the purpose
of the policy. Keep the policies as high level as possible; the
procedures and guidelines will provide the details necessary
D. A. Ga’al is with the Information Systems Department, Universiti
Teknologi Malaysia, Johor, Malaysia (daaha_isme@yahoo.com).
W. Zainal Abidin, is an associate professor at the Advanced Informatics
School, Universiti Teknologi Malaysia, International Campus, 54100, Kuala
Lumpur, Malaysia (wardah@utm.my).
for day-to-day operations” [3]. Managing policies manually is
good for small organizations, but large organizations should
have software solutions to manage their policies in a way that
is quick, online and reliable.
II. POLICY
Policy can be defined as plan of action used by an
organization to give instructions from its management to those
who perform day to day duties on behalf of the organization
context [1]. It can also be defined as organizational rules and
regulations that define acceptable and unacceptable behavior
within the organization [1]. Policy is typically written
document that defines a plan or course of action to guide
decisions and achieve rational outcome(s) in organization [2].
III. POLICY MANAGEMENT
In the last decade, policy management became an
imperative issue in organizations, because of modern
regulatory requirements. Therefore, policy management
entails, managing the life cycle of the policy from drafting
until archival. According to [4], there are five key stages of
policy management:
• Establishing policy requirements - Investigating all the
“relevant law, regulatory requirements, guidelines and
best practice” [4] which is necessary to identify the
business requirements.
• Drafting policy – is to come up with statements, those
sounds fine in legality, in simple English [4].
• Policy deployment - Sharing and distributing policies
around the organization.
• Testing understanding & affirming acceptance - To
make sure that employees understand the policy and
ready to abide by it.
• Auditing policy penetration - Reviewing policy and
generating report to the [4] management on
compliance status.
IV. POLICY REPOSITORY
Another important issue which was examined in this
research is policy repository. It is a shared database where all
policy documents are stored for ease of access. In large
organizations, a huge number of policy documents are used;
and those documents need management solution. Thus,
management starts from storing them in a single database
where everyone in the organization is able to access them any
Policy Management Framework for Managing
Enterprise Policies
Dahir A. Ga’al and Wardah Zainal Abidin
P
World Academy of Science, Engineering and Technology 70 2010
136
time. Policy repository is the main important component of
policy management program. However, this component will be
used as part of the proposed policy management framework.
V.POLICY MANAGEMENT PROGRAM
To implement policy management across the organization, a
policy management program should be developed. As
discussed earlier, policy can be managed manually or
automated way. Based on this, there are two approaches for
developing policy management program [3]; manual or
automated. For the manual, there is human involvement to
manage the policies. For the automated approach, software
tools are used instead [3]. The manual way of policy
management program is good for small organizations because
of their limited number of policies which people can manage
easily. But large organizations need software solution to
manage the large number of policies across the organization.
VI. POLICY MANAGEMENT MODELS
In order to propose a policy management framework,
several existing related frameworks were studied and the
IETF/DMTF Policy Framework is deemed most suitable to be
investigated in depth.
VII. THE IETF/DMTF POLICY FRAMEWORK
The IETF/DMTF policy framework is introduced by IETF
(Internet Engineering Task Force) and DMTF (Distributed
Management Task Force) and is shown in figure 1. This
framework is being used as the basis for the efforts of
designing a policy management framework. It consists of four
components namely: policy management tool, policy
repository, policy decision point and policy enforcement point.
Fig. 1 The IETF/DMTF policy framework [5]
The policy management tool is a graphical user interface
where the users or policy readers can use it to access the
organization’s policies. This tool provides the mechanism to
retrieve policies from the policy repository. Within this tool
the management users can also draft new policies, review
existing ones within specified time frame, or simply view
policies that are stored in the policy repository. The policy
repository is used for the storage of policies, after they have
been drafted and approved by the approvers of that policy by
using policy management tool. It is a database, which is
connected to the Policy Management Tool for the storage of
the policies. Lastly, Policy Decision Point is the final point
where management users can approve newly drafted policies
and allow them to be accessed by the normal users or staff.
VIII.UNIVERSITI TEKNOLOGI MALAYSIA: CASE STUDY
Universiti Teknologi Malaysia (UTM) is one of Malaysia’s
leading universities in engineering, science and technology. It
is located in Johor Bahru, the southern city of Malaysia [6]. It
is famous [6] for being at the forefront of engineering and
Technological knowledge in Malaysia. Interest in policy
management began when the University’s legal affairs
department decided to have a software tool to use for
managing policy documents all over UTM because of the
existing huge policy documents. The department needs to
make all UTM policies in digital format, rather than printed
documents kept on shelves, to ease access. To digitize UTM
policies, they need to have web base policy management tool.
This will consist of policy repository, for the storage of all
policies, and policy management for retrieval, drafting,
reviewing and storing policies. The legal department also
needs to keep all staffs updated on the current and old policies
by providing online policy management tool. This tool can
give them access to all policies online which is very easy for
them to read understand and to keep them updated on new
policies. After the problems have been identified, an interview
was conducted with top officers of the legal department in
UTM to get deep understanding on the state of the problem.
The result from the interview showed that there is a need for
policy management software to use as a solution for the
problem. However, policy management framework was
proposed as a solution for the problem regarding on how to
make all policies online and how to keep staff to read and
understand organization’s policies.
IX. PROPOSED POLICY MANAGEMENT FRAMEWORK
As discussed above, IETF/DMTF policy framework is used
as the basic concept in order to design policy management
framework as a solution for the policy management need in
organizations. The proposed framework will give
organizations policy management solution and is shown in
figure 2.
Policy
Repository
Policy management Tool
Policy decision Point
Policy enforcement point
World Academy of Science, Engineering and Technology 70 2010
137
Fig. 2 Proposed Policy management framework
As shown in the above figure, the proposed
framework consists of the following components:
1. Policy Reviewers
2. Policy Approver, Readers and Owner
3. Browser
4. Policy Management Tool
a. User Interface Manager
b. Policy Editor
c. Policy Decision Point
5. Policy Approvers
6. Policy Repository
Policy Repository
Policy Reviewers Policy Readers
Browser
Policy Management Tool
Policy Decision Point
UI Manager Policy Editor
Policy Approvers
Retrieve
Policies
Draft /
Review
existing
Policies
Retrieve newly
drafted Policies
Approve
Store approved policy
Policy Owners
World Academy of Science, Engineering and Technology 70 2010
138
TABLE I SUMMARY OF PROPOSED POLICY MANAGEMENT FRAMEWORK DESCRIPTION
Policy Approver, Readers and
Owner
These three components are the users of the policy management
framework. Policy approver is the person who approves the policy after it
has been drafted by the policy creator or owner. Policy readers are the
target groups in the organization those required to read the policy. Lastly,
policy owner is the person(s) drafted the policy or created it.
Browser This is the first component that helps users to access the policy
management tool by using web browser.
Policy Management Tool The second component is the Policy management tool. This component
consists of three sub components which are User Interface Manager, Policy
Editor and Policy Decision Point.
User Interface Manager The User Interface Manager is the front end of the policy management
tool where the users may be able to view the existing policies.
Policy Editor The second component of policy management tool is the policy editor.
This component allows the user to view, draft and review the policies and
save it to the repository.
Policy Decision Point The final component of the policy management tool is the Policy
decision Point where the administrator or top level management users can
release the newly approved policies and allow them to be accessed by the
target staff.
Policy Approvers The third component of the proposed model is the Policy Approvers,
where the administrator or top level management users can approve the
newly drafted policies so the readers will be able to view.
X.CONCLUSION
There is not a clear and complete definition of policy
management in the past literature. However, this paper
presented what is meant by policy management according to
the researcher’s view. And also IETF/DMTF policy
framework is used as basic idea in designing policy
management framework, which is the main result of the paper.
This proposed policy management framework was designed to
help large organizations to manage their policies and keep
their employees read and understand all policies across the
organization. In the near future, to implement the framework
presented in the paper, a policy management tool is needed to
develop. The tool can be used to manage all policies in
organization, in order to proof the concept presented in this
paper. This policy management tool will be a website that has
all policy management need across the organization.
ACKNOWLEDGMENT
The authors would like to thank University Teknologi
Malaysia (UTM) for their sincere help and cooperation in
making this paper successful. The authors are also indebted to
the Ministry of Science, Technology and Innovation (MOSTI)
of Malaysia, under the FRGS (Fundamental Research Grant
Scheme) (Vot: 78654). This research is still ongoing.
REFERENCES
[1] Micheal E. Whithman and Herpert J. Mattord. (2005). Principles of
Information Security. (2nd Ed). Canada: Thomson Learning.
[2] Wikipedia. Policy. http://en.wikipedia.org/wiki/Policy. (Last accessed
on April 30, 2010).
[3] Harris Weisman. (2006). Policy management: Manual vs. automated
tools. Information Security magazine.
[4] PolicyMatter - White Paper: the Freedom of Information Act - Why
effective policy management is crucial. 05/01/2005 available:
http://www.policymatter.com/news/news050105/.
[5] Dinesh C. Verma & IBM Thomas J Watson Research Centre (2002).
Simplifying Network Administration Using Policy-Based Management.
IEEE Network, 02, 0890-8044.
[6] UTM. (2010). Introduction. http://www.utm.my/aboututm/about-
utm.html (accessed on: 19 May 2010).
Ga’al, Dahir Abdi (Mr.) received his B.sc. in Science in Information
Technology from Somali Institute of Management and Administration
Development (SIMAD), Mogadishu, Somalia in 2007 and M.sc. in IT
Management from University Technology Malaysia (UTM), Malaysia in
2009. Currently he is a PhD student in Faculty of Computer & Information
Sciences, University Technology Petronas (UTP), Malaysia.
Wardah Zainal Abidin (Assoc. Prof) is an associate professor at
the Advanced Informatics School, UTM. She obtained her first degree at
Universiti Kebangsaan Malaysia (UKM), in 1981, in Pharmacology. After
that she pursued her studies in Computer Science in Universiti Teknologi
Malaysia (UTM), first taking her Advanced Diploma and later Masters in
Computer Science. On 30th August 1984, her life as an academician at
UTM began and she has not looked back ever since. Computer Science
and later Information Technology have never ceased to amaze her although
her first degree was in biological sciences. Apart from teaching at the
Department, she had the opportunity to be involved with several consultancy
groups mostly involving government agencies and government-linked
companies since 1992.
World Academy of Science, Engineering and Technology 70 2010
139

More Related Content

What's hot

Ahlan, arshad, ajayi 2014 - it governance in a malaysian public institute o...
Ahlan, arshad, ajayi   2014 - it governance in a malaysian public institute o...Ahlan, arshad, ajayi   2014 - it governance in a malaysian public institute o...
Ahlan, arshad, ajayi 2014 - it governance in a malaysian public institute o...Binyamin Ajayi
 
WP1 - Planning and Budgeting Systems
WP1 - Planning and Budgeting SystemsWP1 - Planning and Budgeting Systems
WP1 - Planning and Budgeting SystemsFabien Lennertz
 
Conceptualizing Information Technology Governance Model for Higher Education:...
Conceptualizing Information Technology Governance Model for Higher Education:...Conceptualizing Information Technology Governance Model for Higher Education:...
Conceptualizing Information Technology Governance Model for Higher Education:...journalBEEI
 
Structured Approach To Implementing Information And Records Management (Idrm)...
Structured Approach To Implementing Information And Records Management (Idrm)...Structured Approach To Implementing Information And Records Management (Idrm)...
Structured Approach To Implementing Information And Records Management (Idrm)...Alan McSweeney
 
IT Governance Made Easy
IT Governance Made EasyIT Governance Made Easy
IT Governance Made EasyJerry Bishop
 
Financial Management Information System within Government Institution and Sup...
Financial Management Information System within Government Institution and Sup...Financial Management Information System within Government Institution and Sup...
Financial Management Information System within Government Institution and Sup...sececonf
 
Corporate governance of INFORMATION TECHNOLOGY (IT)
Corporate governance of INFORMATION TECHNOLOGY (IT)Corporate governance of INFORMATION TECHNOLOGY (IT)
Corporate governance of INFORMATION TECHNOLOGY (IT)Osman Hasan
 
What Is It Governance Introduction
What Is It Governance   IntroductionWhat Is It Governance   Introduction
What Is It Governance Introductionnicxenos
 
Protecting business interests with policies for it asset management it-tool...
Protecting business interests with policies for it asset management   it-tool...Protecting business interests with policies for it asset management   it-tool...
Protecting business interests with policies for it asset management it-tool...IT-Toolkits.org
 
LBBD ICT Strategy Report 2013-17
LBBD ICT Strategy Report 2013-17LBBD ICT Strategy Report 2013-17
LBBD ICT Strategy Report 2013-17Fayzan Rehman
 
It governance practices and enterprise effectiveness in zimbabwe a case of a ...
It governance practices and enterprise effectiveness in zimbabwe a case of a ...It governance practices and enterprise effectiveness in zimbabwe a case of a ...
It governance practices and enterprise effectiveness in zimbabwe a case of a ...Alexander Decker
 
CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...
CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...
CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...ijait
 
Business process and is lecture 2
Business process and is lecture 2Business process and is lecture 2
Business process and is lecture 2Raphael Wanjiku
 
INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...
INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...
INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...Tonmoy zahid Rishad
 
Stream C_Ross Agnew Ursula Bryan
Stream C_Ross Agnew Ursula BryanStream C_Ross Agnew Ursula Bryan
Stream C_Ross Agnew Ursula BryanBecarAsset
 
Research evolution on implementation and adoption behaviour of information sy...
Research evolution on implementation and adoption behaviour of information sy...Research evolution on implementation and adoption behaviour of information sy...
Research evolution on implementation and adoption behaviour of information sy...LenaFrau
 
Governance Of Enterprise Information Technology V3
Governance Of Enterprise Information Technology V3Governance Of Enterprise Information Technology V3
Governance Of Enterprise Information Technology V3pjmartinez
 

What's hot (20)

Ahlan, arshad, ajayi 2014 - it governance in a malaysian public institute o...
Ahlan, arshad, ajayi   2014 - it governance in a malaysian public institute o...Ahlan, arshad, ajayi   2014 - it governance in a malaysian public institute o...
Ahlan, arshad, ajayi 2014 - it governance in a malaysian public institute o...
 
WP1 - Planning and Budgeting Systems
WP1 - Planning and Budgeting SystemsWP1 - Planning and Budgeting Systems
WP1 - Planning and Budgeting Systems
 
Conceptualizing Information Technology Governance Model for Higher Education:...
Conceptualizing Information Technology Governance Model for Higher Education:...Conceptualizing Information Technology Governance Model for Higher Education:...
Conceptualizing Information Technology Governance Model for Higher Education:...
 
Structured Approach To Implementing Information And Records Management (Idrm)...
Structured Approach To Implementing Information And Records Management (Idrm)...Structured Approach To Implementing Information And Records Management (Idrm)...
Structured Approach To Implementing Information And Records Management (Idrm)...
 
IT Governance Made Easy
IT Governance Made EasyIT Governance Made Easy
IT Governance Made Easy
 
Financial Management Information System within Government Institution and Sup...
Financial Management Information System within Government Institution and Sup...Financial Management Information System within Government Institution and Sup...
Financial Management Information System within Government Institution and Sup...
 
Corporate governance of INFORMATION TECHNOLOGY (IT)
Corporate governance of INFORMATION TECHNOLOGY (IT)Corporate governance of INFORMATION TECHNOLOGY (IT)
Corporate governance of INFORMATION TECHNOLOGY (IT)
 
What Is It Governance Introduction
What Is It Governance   IntroductionWhat Is It Governance   Introduction
What Is It Governance Introduction
 
MIS Chapter 3
MIS Chapter 3MIS Chapter 3
MIS Chapter 3
 
Protecting business interests with policies for it asset management it-tool...
Protecting business interests with policies for it asset management   it-tool...Protecting business interests with policies for it asset management   it-tool...
Protecting business interests with policies for it asset management it-tool...
 
LBBD ICT Strategy Report 2013-17
LBBD ICT Strategy Report 2013-17LBBD ICT Strategy Report 2013-17
LBBD ICT Strategy Report 2013-17
 
It governance practices and enterprise effectiveness in zimbabwe a case of a ...
It governance practices and enterprise effectiveness in zimbabwe a case of a ...It governance practices and enterprise effectiveness in zimbabwe a case of a ...
It governance practices and enterprise effectiveness in zimbabwe a case of a ...
 
Accounting informationsystem
Accounting informationsystemAccounting informationsystem
Accounting informationsystem
 
CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...
CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...
CHANGE MANAGEMENT: IMPLEMENTATION AND BENEFITS OF THE CHANGE CONTROL IN THE I...
 
Business process and is lecture 2
Business process and is lecture 2Business process and is lecture 2
Business process and is lecture 2
 
INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...
INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...
INFORMATION SYSTEMS, ORGANIZATIONS, AND STRATEGY for management information s...
 
MIS Chapter 1
MIS Chapter 1MIS Chapter 1
MIS Chapter 1
 
Stream C_Ross Agnew Ursula Bryan
Stream C_Ross Agnew Ursula BryanStream C_Ross Agnew Ursula Bryan
Stream C_Ross Agnew Ursula Bryan
 
Research evolution on implementation and adoption behaviour of information sy...
Research evolution on implementation and adoption behaviour of information sy...Research evolution on implementation and adoption behaviour of information sy...
Research evolution on implementation and adoption behaviour of information sy...
 
Governance Of Enterprise Information Technology V3
Governance Of Enterprise Information Technology V3Governance Of Enterprise Information Technology V3
Governance Of Enterprise Information Technology V3
 

Similar to Policy management framework_for_managing

Harrisburg UniversityISEM 547 IT PolicyOb.docx
Harrisburg UniversityISEM 547  IT PolicyOb.docxHarrisburg UniversityISEM 547  IT PolicyOb.docx
Harrisburg UniversityISEM 547 IT PolicyOb.docxshericehewat
 
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementchristophefeltus
 
8367 collaborative policy-administration-pdf
8367 collaborative policy-administration-pdf8367 collaborative policy-administration-pdf
8367 collaborative policy-administration-pdfChinnu SD
 
Technology Implementation Paper
Technology Implementation PaperTechnology Implementation Paper
Technology Implementation PaperDeb Birch
 
Policy Framework
Policy FrameworkPolicy Framework
Policy FrameworkLai En Xin
 
CHAPTER 5 Security Policies, Standards, Procedures, a
CHAPTER  5 Security Policies, Standards, Procedures, aCHAPTER  5 Security Policies, Standards, Procedures, a
CHAPTER 5 Security Policies, Standards, Procedures, aMaximaSheffield592
 
ISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptxISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptxjojo82637
 
71 Information Governance Policy Development .docx
71 Information Governance Policy Development      .docx71 Information Governance Policy Development      .docx
71 Information Governance Policy Development .docxsleeperharwell
 
Strategic Advocacy Framework (1)
Strategic Advocacy Framework  (1)Strategic Advocacy Framework  (1)
Strategic Advocacy Framework (1)Faisal Hassan, MPP
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachMohammad Reda Katby
 
K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-
K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-
K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-christopher corlett
 
Modern Workspace Based Policy Management with Automated Keyword Extraction an...
Modern Workspace Based Policy Management with Automated Keyword Extraction an...Modern Workspace Based Policy Management with Automated Keyword Extraction an...
Modern Workspace Based Policy Management with Automated Keyword Extraction an...ijtsrd
 
So you want to go digital
So you want to go digitalSo you want to go digital
So you want to go digitalMichael Burgess
 
Vskills manufacturing technology management professional sample material
Vskills manufacturing technology management professional sample materialVskills manufacturing technology management professional sample material
Vskills manufacturing technology management professional sample materialVskills
 
Corporate Strategy And Project Management
Corporate Strategy And Project ManagementCorporate Strategy And Project Management
Corporate Strategy And Project ManagementSusan Cox
 

Similar to Policy management framework_for_managing (20)

Harrisburg UniversityISEM 547 IT PolicyOb.docx
Harrisburg UniversityISEM 547  IT PolicyOb.docxHarrisburg UniversityISEM 547  IT PolicyOb.docx
Harrisburg UniversityISEM 547 IT PolicyOb.docx
 
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
 
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
 
Agile Policy Making
Agile Policy MakingAgile Policy Making
Agile Policy Making
 
8367 collaborative policy-administration-pdf
8367 collaborative policy-administration-pdf8367 collaborative policy-administration-pdf
8367 collaborative policy-administration-pdf
 
Technology Implementation Paper
Technology Implementation PaperTechnology Implementation Paper
Technology Implementation Paper
 
Policy Framework
Policy FrameworkPolicy Framework
Policy Framework
 
CHAPTER 5 Security Policies, Standards, Procedures, a
CHAPTER  5 Security Policies, Standards, Procedures, aCHAPTER  5 Security Policies, Standards, Procedures, a
CHAPTER 5 Security Policies, Standards, Procedures, a
 
Mafi Work Plan 2013, short version (March 2013)
Mafi Work Plan 2013, short version (March 2013)Mafi Work Plan 2013, short version (March 2013)
Mafi Work Plan 2013, short version (March 2013)
 
ISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptxISO27001_COBIT_Students.pptx
ISO27001_COBIT_Students.pptx
 
71 Information Governance Policy Development .docx
71 Information Governance Policy Development      .docx71 Information Governance Policy Development      .docx
71 Information Governance Policy Development .docx
 
Strategic Advocacy Framework (1)
Strategic Advocacy Framework  (1)Strategic Advocacy Framework  (1)
Strategic Advocacy Framework (1)
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic Approach
 
Whitepaper - ISO 27001 implementation
Whitepaper - ISO 27001 implementationWhitepaper - ISO 27001 implementation
Whitepaper - ISO 27001 implementation
 
Information Management Workshop
Information Management WorkshopInformation Management Workshop
Information Management Workshop
 
K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-
K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-
K-MEANS MAP REDUCE ALGORITHS Guidebook_FINAL-
 
Modern Workspace Based Policy Management with Automated Keyword Extraction an...
Modern Workspace Based Policy Management with Automated Keyword Extraction an...Modern Workspace Based Policy Management with Automated Keyword Extraction an...
Modern Workspace Based Policy Management with Automated Keyword Extraction an...
 
So you want to go digital
So you want to go digitalSo you want to go digital
So you want to go digital
 
Vskills manufacturing technology management professional sample material
Vskills manufacturing technology management professional sample materialVskills manufacturing technology management professional sample material
Vskills manufacturing technology management professional sample material
 
Corporate Strategy And Project Management
Corporate Strategy And Project ManagementCorporate Strategy And Project Management
Corporate Strategy And Project Management
 

Recently uploaded

Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetChandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meetpriyashah722354
 
Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...
Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...
Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...gragteena
 
Basics of Anatomy- Language of Anatomy.pptx
Basics of Anatomy- Language of Anatomy.pptxBasics of Anatomy- Language of Anatomy.pptx
Basics of Anatomy- Language of Anatomy.pptxAyush Gupta
 
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetCall Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meetpriyashah722354
 
Hot Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In Ludhiana
Hot  Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In LudhianaHot  Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In Ludhiana
Hot Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In LudhianaRussian Call Girls in Ludhiana
 
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★indiancallgirl4rent
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...Gfnyt.com
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Memriyagarg453
 
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In FaridabadCall Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabadgragmanisha42
 
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...gurkirankumar98700
 
Call Girls Thane Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Thane Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Thane Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Thane Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅gragmanisha42
 
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋Sheetaleventcompany
 
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in FaridabadNepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabadgragteena
 
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking ModelsDehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Modelsindiancallgirl4rent
 
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...Niamh verma
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...Vip call girls In Chandigarh
 

Recently uploaded (20)

Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetChandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
 
Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...
Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...
Call Girls Service Charbagh { Lucknow Call Girls Service 9548273370 } Book me...
 
Basics of Anatomy- Language of Anatomy.pptx
Basics of Anatomy- Language of Anatomy.pptxBasics of Anatomy- Language of Anatomy.pptx
Basics of Anatomy- Language of Anatomy.pptx
 
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetCall Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
 
Hot Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In Ludhiana
Hot  Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In LudhianaHot  Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In Ludhiana
Hot Call Girl In Ludhiana 👅🥵 9053'900678 Call Girls Service In Ludhiana
 
#9711199012# African Student Escorts in Delhi 😘 Call Girls Delhi
#9711199012# African Student Escorts in Delhi 😘 Call Girls Delhi#9711199012# African Student Escorts in Delhi 😘 Call Girls Delhi
#9711199012# African Student Escorts in Delhi 😘 Call Girls Delhi
 
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
Enjoyment ★ 8854095900 Indian Call Girls In Dehradun 🍆🍌 By Dehradun Call Girl ★
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
 
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In FaridabadCall Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
 
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Kolkata Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
Russian Call Girls Lucknow ₹7.5k Pick Up & Drop With Cash Payment 8923113531 ...
 
Call Girls Thane Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Thane Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Thane Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Thane Just Call 9907093804 Top Class Call Girl Service Available
 
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
 
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
💚😋Chandigarh Escort Service Call Girls, ₹5000 To 25K With AC💚😋
 
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in FaridabadNepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
Nepali Escort Girl * 9999965857 Naughty Call Girls Service in Faridabad
 
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking ModelsDehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
Dehradun Call Girls Service 08854095900 Real Russian Girls Looking Models
 
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤7710465962 VIP Call Girls Chandi...
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
 

Policy management framework_for_managing

  • 1. Abstract—Policy management in organizations became rising issue in the last decade. It’s because of today’s regulatory requirements in the organizations. To manage policies in large organizations is an imperative work. However, major challenges facing organizations in the last decade is managing all the policies in the organization and making them an active documents rather than simple (inactive) documents stored in computer hard drive or on a shelf. Because of this challenge, organizations need policy management program. This policy management program can be either manual or automated. This paper presents suggestions towards managing policies in organizations. As well as possible policy management solution or program to be utilized, manual or automated. The research first examines the models and frameworks used for managing policies from various perspectives in the literature of the research area/domain. At the end of this paper, a policy management framework is proposed for managing enterprise policies effectively and in a simplified manner. Keywords—Policy, policy management, policy management program, policy repository. I. INTRODUCTION OLICY can be defined as plan of action used by an organization to give instructions from its senior management to those who make decisions to take actions, and perform other duties on behalf of the organization’s context [1]. Major challenge facing organizations in the last decade is how to distribute all their policies to target employees. And to keep them read, understand and comply with all policies in the organization [3]. Because of this challenge, there is a strong demand in organizations for some kind of policy management solution. This policy management solution can be either manual or automated [3]. Policy management in the context of this paper is the conversion of policies into practical and enforceable [3] documents, rather than simple documents in which employees neglect or don’t read it, that can be implemented in the organization as whole. However, most organizations manage their policies manually. Weisman quoted “Developing a manual policy management solution is creating a set of procedures that reflects the purpose of the policy. Keep the policies as high level as possible; the procedures and guidelines will provide the details necessary D. A. Ga’al is with the Information Systems Department, Universiti Teknologi Malaysia, Johor, Malaysia (daaha_isme@yahoo.com). W. Zainal Abidin, is an associate professor at the Advanced Informatics School, Universiti Teknologi Malaysia, International Campus, 54100, Kuala Lumpur, Malaysia (wardah@utm.my). for day-to-day operations” [3]. Managing policies manually is good for small organizations, but large organizations should have software solutions to manage their policies in a way that is quick, online and reliable. II. POLICY Policy can be defined as plan of action used by an organization to give instructions from its management to those who perform day to day duties on behalf of the organization context [1]. It can also be defined as organizational rules and regulations that define acceptable and unacceptable behavior within the organization [1]. Policy is typically written document that defines a plan or course of action to guide decisions and achieve rational outcome(s) in organization [2]. III. POLICY MANAGEMENT In the last decade, policy management became an imperative issue in organizations, because of modern regulatory requirements. Therefore, policy management entails, managing the life cycle of the policy from drafting until archival. According to [4], there are five key stages of policy management: • Establishing policy requirements - Investigating all the “relevant law, regulatory requirements, guidelines and best practice” [4] which is necessary to identify the business requirements. • Drafting policy – is to come up with statements, those sounds fine in legality, in simple English [4]. • Policy deployment - Sharing and distributing policies around the organization. • Testing understanding & affirming acceptance - To make sure that employees understand the policy and ready to abide by it. • Auditing policy penetration - Reviewing policy and generating report to the [4] management on compliance status. IV. POLICY REPOSITORY Another important issue which was examined in this research is policy repository. It is a shared database where all policy documents are stored for ease of access. In large organizations, a huge number of policy documents are used; and those documents need management solution. Thus, management starts from storing them in a single database where everyone in the organization is able to access them any Policy Management Framework for Managing Enterprise Policies Dahir A. Ga’al and Wardah Zainal Abidin P World Academy of Science, Engineering and Technology 70 2010 136
  • 2. time. Policy repository is the main important component of policy management program. However, this component will be used as part of the proposed policy management framework. V.POLICY MANAGEMENT PROGRAM To implement policy management across the organization, a policy management program should be developed. As discussed earlier, policy can be managed manually or automated way. Based on this, there are two approaches for developing policy management program [3]; manual or automated. For the manual, there is human involvement to manage the policies. For the automated approach, software tools are used instead [3]. The manual way of policy management program is good for small organizations because of their limited number of policies which people can manage easily. But large organizations need software solution to manage the large number of policies across the organization. VI. POLICY MANAGEMENT MODELS In order to propose a policy management framework, several existing related frameworks were studied and the IETF/DMTF Policy Framework is deemed most suitable to be investigated in depth. VII. THE IETF/DMTF POLICY FRAMEWORK The IETF/DMTF policy framework is introduced by IETF (Internet Engineering Task Force) and DMTF (Distributed Management Task Force) and is shown in figure 1. This framework is being used as the basis for the efforts of designing a policy management framework. It consists of four components namely: policy management tool, policy repository, policy decision point and policy enforcement point. Fig. 1 The IETF/DMTF policy framework [5] The policy management tool is a graphical user interface where the users or policy readers can use it to access the organization’s policies. This tool provides the mechanism to retrieve policies from the policy repository. Within this tool the management users can also draft new policies, review existing ones within specified time frame, or simply view policies that are stored in the policy repository. The policy repository is used for the storage of policies, after they have been drafted and approved by the approvers of that policy by using policy management tool. It is a database, which is connected to the Policy Management Tool for the storage of the policies. Lastly, Policy Decision Point is the final point where management users can approve newly drafted policies and allow them to be accessed by the normal users or staff. VIII.UNIVERSITI TEKNOLOGI MALAYSIA: CASE STUDY Universiti Teknologi Malaysia (UTM) is one of Malaysia’s leading universities in engineering, science and technology. It is located in Johor Bahru, the southern city of Malaysia [6]. It is famous [6] for being at the forefront of engineering and Technological knowledge in Malaysia. Interest in policy management began when the University’s legal affairs department decided to have a software tool to use for managing policy documents all over UTM because of the existing huge policy documents. The department needs to make all UTM policies in digital format, rather than printed documents kept on shelves, to ease access. To digitize UTM policies, they need to have web base policy management tool. This will consist of policy repository, for the storage of all policies, and policy management for retrieval, drafting, reviewing and storing policies. The legal department also needs to keep all staffs updated on the current and old policies by providing online policy management tool. This tool can give them access to all policies online which is very easy for them to read understand and to keep them updated on new policies. After the problems have been identified, an interview was conducted with top officers of the legal department in UTM to get deep understanding on the state of the problem. The result from the interview showed that there is a need for policy management software to use as a solution for the problem. However, policy management framework was proposed as a solution for the problem regarding on how to make all policies online and how to keep staff to read and understand organization’s policies. IX. PROPOSED POLICY MANAGEMENT FRAMEWORK As discussed above, IETF/DMTF policy framework is used as the basic concept in order to design policy management framework as a solution for the policy management need in organizations. The proposed framework will give organizations policy management solution and is shown in figure 2. Policy Repository Policy management Tool Policy decision Point Policy enforcement point World Academy of Science, Engineering and Technology 70 2010 137
  • 3. Fig. 2 Proposed Policy management framework As shown in the above figure, the proposed framework consists of the following components: 1. Policy Reviewers 2. Policy Approver, Readers and Owner 3. Browser 4. Policy Management Tool a. User Interface Manager b. Policy Editor c. Policy Decision Point 5. Policy Approvers 6. Policy Repository Policy Repository Policy Reviewers Policy Readers Browser Policy Management Tool Policy Decision Point UI Manager Policy Editor Policy Approvers Retrieve Policies Draft / Review existing Policies Retrieve newly drafted Policies Approve Store approved policy Policy Owners World Academy of Science, Engineering and Technology 70 2010 138
  • 4. TABLE I SUMMARY OF PROPOSED POLICY MANAGEMENT FRAMEWORK DESCRIPTION Policy Approver, Readers and Owner These three components are the users of the policy management framework. Policy approver is the person who approves the policy after it has been drafted by the policy creator or owner. Policy readers are the target groups in the organization those required to read the policy. Lastly, policy owner is the person(s) drafted the policy or created it. Browser This is the first component that helps users to access the policy management tool by using web browser. Policy Management Tool The second component is the Policy management tool. This component consists of three sub components which are User Interface Manager, Policy Editor and Policy Decision Point. User Interface Manager The User Interface Manager is the front end of the policy management tool where the users may be able to view the existing policies. Policy Editor The second component of policy management tool is the policy editor. This component allows the user to view, draft and review the policies and save it to the repository. Policy Decision Point The final component of the policy management tool is the Policy decision Point where the administrator or top level management users can release the newly approved policies and allow them to be accessed by the target staff. Policy Approvers The third component of the proposed model is the Policy Approvers, where the administrator or top level management users can approve the newly drafted policies so the readers will be able to view. X.CONCLUSION There is not a clear and complete definition of policy management in the past literature. However, this paper presented what is meant by policy management according to the researcher’s view. And also IETF/DMTF policy framework is used as basic idea in designing policy management framework, which is the main result of the paper. This proposed policy management framework was designed to help large organizations to manage their policies and keep their employees read and understand all policies across the organization. In the near future, to implement the framework presented in the paper, a policy management tool is needed to develop. The tool can be used to manage all policies in organization, in order to proof the concept presented in this paper. This policy management tool will be a website that has all policy management need across the organization. ACKNOWLEDGMENT The authors would like to thank University Teknologi Malaysia (UTM) for their sincere help and cooperation in making this paper successful. The authors are also indebted to the Ministry of Science, Technology and Innovation (MOSTI) of Malaysia, under the FRGS (Fundamental Research Grant Scheme) (Vot: 78654). This research is still ongoing. REFERENCES [1] Micheal E. Whithman and Herpert J. Mattord. (2005). Principles of Information Security. (2nd Ed). Canada: Thomson Learning. [2] Wikipedia. Policy. http://en.wikipedia.org/wiki/Policy. (Last accessed on April 30, 2010). [3] Harris Weisman. (2006). Policy management: Manual vs. automated tools. Information Security magazine. [4] PolicyMatter - White Paper: the Freedom of Information Act - Why effective policy management is crucial. 05/01/2005 available: http://www.policymatter.com/news/news050105/. [5] Dinesh C. Verma & IBM Thomas J Watson Research Centre (2002). Simplifying Network Administration Using Policy-Based Management. IEEE Network, 02, 0890-8044. [6] UTM. (2010). Introduction. http://www.utm.my/aboututm/about- utm.html (accessed on: 19 May 2010). Ga’al, Dahir Abdi (Mr.) received his B.sc. in Science in Information Technology from Somali Institute of Management and Administration Development (SIMAD), Mogadishu, Somalia in 2007 and M.sc. in IT Management from University Technology Malaysia (UTM), Malaysia in 2009. Currently he is a PhD student in Faculty of Computer & Information Sciences, University Technology Petronas (UTP), Malaysia. Wardah Zainal Abidin (Assoc. Prof) is an associate professor at the Advanced Informatics School, UTM. She obtained her first degree at Universiti Kebangsaan Malaysia (UKM), in 1981, in Pharmacology. After that she pursued her studies in Computer Science in Universiti Teknologi Malaysia (UTM), first taking her Advanced Diploma and later Masters in Computer Science. On 30th August 1984, her life as an academician at UTM began and she has not looked back ever since. Computer Science and later Information Technology have never ceased to amaze her although her first degree was in biological sciences. Apart from teaching at the Department, she had the opportunity to be involved with several consultancy groups mostly involving government agencies and government-linked companies since 1992. World Academy of Science, Engineering and Technology 70 2010 139