IT Procedure on Developing Procedures
Version 1.2
For Students, Faculty, Staff, Guests, Alumni
Purpose
This document is the procedure used when developing an IT Procedure that compliments related policies at Fordham University.
Scope
This IT document, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrative officials, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Procedure Statement
Initial Procedure Development
- A director (or above) who wishes to develop a procedure reaches out to the Senior Director of IT Security and Assurance (herein Director) to request a procedure.
- The requestor may create a procedure draft and send it to the Director or summarize what they are trying to accomplish.
- The Director has the Policy Analyst draft a procedure for review.
- The Director shares an initial draft, if provided, with Policy Analyst for edits.
- The Director sends the requestor a draft developed by the Policy Analyst to confirm the drafted procedure captures the essence of what is required by the procedure.
- The Director, working with the requestor, identifies areas impacted by the procedure within the Office of Information Technology.
- The Director coordinates with the directors of the impacted areas and with the requestor to gather feedback on the proposed procedure and incorporate changes, provided the changes do not undermine the requirements of the procedure.
- Once all feedback (e.g., requestor, business partners, departments) is incorporated, the Director has the Policy Analyst issue the final draft. This final draft includes the author and review frequency.
- The Policy Analyst sends the draft to the AVP/CISO for approval.
- If the procedure is not approved, the Director works with the requestor to resolve issues to gain approval.
- When the procedure is approved, the Policy Analyst publishes it to the IT Policy Library on the University’s website.
Procedure Review
- One month before the procedure expires, the Policy Analyst sends a notification via email to the responsible person that the procedure needs to be reviewed.
- If the responsible person feels no changes are required, they will respond in writing that no changes are necessary, and Director will note that no further action is required.
- The Policy Analyst notes the procedure was reviewed in the revision history section.
- Without a responsible person, the Director identifies the appropriate person to review the procedure.
- In the Director’s absence, the AVP/CISO identifies the appropriate person to review the procedure.
- If the procedure requires revision, it follows the Procedure Revision section’s steps below.
Procedure Revision
- The responsible person who wishes to modify their procedure reaches out to the Director to request the latest version of their procedure.
- The requestor may modify their procedure and send it to the Director or summarize what they are trying to accomplish and have the Policy Analyst draft an update for review.
- The Director shares an updated draft, if provided, with Policy Analyst for edits.
- The Director sends the requestor draft of the Policy Analyst’s updates to confirm the procedure has captured the essence of what is being modified.
- The Director, working with the requestor, identifies areas impacted by the procedure within IT based on the changes made.
- The Director calls a meeting with the directors of the impacted areas and with the requestor to gather feedback on the proposed procedure and incorporate changes, provided the changes do not undermine the requirements of the procedure.
- Once all feedback is incorporated, the Director has the Policy Analyst issue the final draft.
- The Director sends the draft to the AVP/CISO for approval.
- If the procedure is not approved, the Director works with the requestor to resolve issues to gain approval.
- Once the updated procedure is approved, the Policy Analyst publishes the latest version of the procedure to the IT Policy Library on the University’s website.
Service Level
Because of the nature of the development of policies and the coordination of impacted areas, it should be expected that initial procedure development and procedure revisions may take 30 business days from start to finish. The procedure review occurs one calendar month before the procedure expiration. If a modification to a procedure is required, the start of the procedure revision begins at the time the Director is notified of the fact that changes are to be made, not at the time the procedure review commenced.
Definitions
IT Resources include computing, networking, communications, application, telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and related materials and services.
Related Policies and Procedures
Implementation Information
Review Frequency: | Triennial |
---|---|
Responsible Person: | Senior Director of IT Security and Assurance |
Approved By: | CISO |
Approval Date: | August 29, 2016 |
Revision History
Version: | Date: | Description: |
1.0 | 08/29/2016 | Initial document |
1.1 | 08/30/2017 | Updated procedure statement |
1.0.2 | 05/23/2019 | Updated scope |
1.2 | 03/05/2021 | Updated purpose and statement |
Need Help?
IT Service Desk
Fordham.edu/ITHelp
Online Support
718-817-3999
[email protected]