Edit page or add comments

Change of Policy Procedure

Keywords

Planning, information security, consistency, ISO27001, change management

Policy: mandatory, formalised requirements that apply to a specific area, situation or task

Communication plan: how the policy or policy change will be communicated to dxw, as a policy that nobody knows exists is pointless.

Process for changing or creating new policy

  1. The policy owner or ISMS team will create the new policy, or make changes to the existing policy, in line with the change management policy and this procedure. This will result in a draft policy and a communication plan that outlines how information about the policy will be delivered to people in scope.
  2. The Executive Board, Operational Leadership Team, and Heads of, as relevant, will be consulted. This consultation will continue until a final draft is ready.
  3. When the final draft is ready, the approvers will be informed. They will consider the policy and communications plan, giving one of these replies. That the:
  4. policy has been approved, can be implemented and the communication plan carried out. 
  5. policy has been approved and will be implemented, but at a defined time in the future. This should be reflected in the communication plan.
  6. policy will not be implemented. Perhaps more consultation is needed, or more evidence collected. If so, the policy writer should be given feedback to inform their next steps.
  7. The Operational Leadership Team delegates responsibility for this policy to the board of directors. This must be done if the policy makes a fundamental or significant change to the way dxw works.

Last updated: 22 September 2026