Companies without IT usage rules are at risk: 5 minimum internal rules you should establish
"We're a small company, so we don't need those kinds of regulations."
"We can just think about it if a problem occurs."
"I trust my employees, so I haven't set any specific rules."
There are actually many business owners who think this way.
However, most IT-related problems occur because "there were no rules in place." The reality is that cases where information leaks or operational problems are caused by employees' good intentions or unconscious actions are overwhelmingly more common than those caused by malicious behavior.
You don't need a difficult set of regulations.
By just deciding on these 5 minimum rules, your company's IT risk will be significantly reduced.
5 internal IT rules you should establish
Rule 1: Standardize the storage location for business data
Companies where storage locations are scattered, such as "individual PCs," "USB memory sticks," or "personal Google Drives," should be careful. When a person in charge is suddenly absent or resigns, it becomes impossible to know where the data is.
What to decide:
Save only to company-designated cloud storage (OneDrive, Google Drive, etc.).
Rule 2: Clarify the rules for using personal devices for work
"Can I check work emails on my personal smartphone?"
"Is it okay to work on my home PC?"
Many companies leave these decisions up to the employees.
Since personal devices are outside the company's control, the risk of information leakage increases significantly.
What to decide:
Clearly state whether or not the use of personal devices for work is permitted, and if so, the conditions for doing so.
Rule 3: Establish password rules
"Everyone uses the same password"
"Company name + numbers"
"Haven't changed it in years"
These types of passwords are typical targets for attackers.
You don't need complex rules, but just setting minimum standards will greatly reduce risk.
What to decide:
Set a minimum requirement of 8 or more characters, including both letters and numbers. Explicitly prohibit the reuse of passwords.
Rule 4: Establish a flow for deleting accounts of resigned employees
There are more companies than you might imagine where email accounts or access rights to cloud services for resigned employees remain active.
The ability to log in even after resignation becomes a gateway for information leakage.
What to decide:
Clearly state who is responsible for deleting accounts and revoking access upon resignation, and when this should be done.
Rule 5: Establish a reporting contact for when IT trouble occurs
You clicked on a phishing email, your PC broke, data was deleted—
In companies where employees don't know who to contact in these situations, the initial response is delayed, and the damage spreads.
What to decide:
Inform everyone of the primary contact person (manager or owner) and the method of communication to use when trouble occurs.
Rules only need to be summarized on a single sheet of paper
There is no need to create difficult manuals or thick rulebooks.
To start, it is enough to simply list the five points above on a single sheet of paper and post it where it can be seen in the office or place it in a shared folder.
The important thing is to create a situation where everyone knows the rules.
That alone can prevent the majority of IT troubles.
Summary: In this day and age, the lack of rules is a risk in itself
Now that IT usage has become commonplace, "not having rules" is the same as saying "anything goes." To protect your employees and your company, start putting things in order little by little starting today.
First, please start by checking these five points.
📖 Recommended reading
💬 Click here for consultations
At IT Work Lab, we provide support for small and medium-sized enterprises with:
Support for establishing internal IT rules and policies
Status checks and improvement proposals for security systems
Creation of IT usage guidelines for employees
and more.
Please feel free to contact us even if you are at the stage where you don't know where to start.
いいなと思ったら応援しよう!
いつも読んでいただき、ありがとうございます。
役に立った!と感じていただけたら、チップで応援していただけるとうれしいです。今後の記事づくりに活用させていただきます。