Policies are established to guide us doing things in achieving the purposes, e.g. safety measure to avoid fatality, control measure to enforce cybersecurity from business interruption. The tricky part is that the policies won’t be able to cover all cases because real world is complex.

What should we handle such situation? There should be mechanism setup to deal with cases that are not covered by the policies context.

By setting up a published mechanism, this will result into a consistent governance process to deal with odd situation objectively rather than subjectively manipulated by some indiviual.

I saw someone simply put a clause as “to deal with on a case-by-case situation”. This is the worst part in the policies.

Leave a Reply