Policies and agreements formalize expectations across every business relationship, from employees and customers to vendors and partners. This content covers the key documents used to define roles, responsibilities, and acceptable behavior in each of those contexts.
Policies & Agreements
When we don't have things written down, it doesn't become formal. That is, there's a lot of room for interpretation. So by writing it down and refining it, we make very clear what's expected and how it's expected. Policies and agreements do exactly that. They get things in writing so we really understand what the roles and responsibilities are and what we are allowed to do.
There are a lot of different types of policies and agreements, and a lot of it has to do with the relationship to the business. What do I mean by that? Number one, a business has employees. There's internal people within the company that are using internal business systems, so the way we treat those people and the contracts and the agreements and the policies are all going to be written towards what their use case is.
We also have customers. We need to make sure that the customers understand what the expectation is between us and the customers, so the customers know exactly what's going on. So we've got the customers and the clients, people who we're providing services or products to.
Then we have our vendors. The vendors are who we are in partner with, or who we are purchasing from, who we're getting products and services from. So just like we as a business have customers that come to us, we actually are customers of other businesses, and so those are the vendors. There are certain agreements and certain things that we agree upon when we're doing business with other vendors, and you can imagine that what we have working with other vendors is going to be very similar to what we have for our clients. There's similar types of agreements there.
And then we have partnerships. Partnerships are when two businesses come together and they're saying, hey, let's do something together.
So let's tackle the first of these. That would be the customers that are coming to us for services or products, or any kind of external users, so even those who are just visiting our site. There are agreements for people who visit our site and never even purchase from us.
The first of those, and the most important I would say, is the privacy policy. I say most important, I guess, because everybody should have a privacy policy. Every company that's doing business should have some sort of privacy policy. So we have a privacy policy of how we're going to treat people's data, because when they come to our site we're probably going to be collecting some sort of data, like where are they coming from and what site directed them towards us. We're going to be collecting marketing data. So just because they visited our site, we need to have a privacy policy.
And then if they become a customer, we might want to up that and have some sort of terms of service or terms of use. So if they're using our product and services, then we're going to maybe have some sort of terms with that that says this is how you can use that, this is what's expected of you, this is how we will work with you, this is what's expected of us. It just lays that all out. Terms of service and terms of use is a lot of times when we're using something like software. So if I go and use a cloud software as a service, then I would sign some sort of terms of service or some sort of terms of use, or at least agree to it. A lot of times it's just a little check box: I agree to the terms of service. And now I'm bound by that, and I won't be able to have access to those services unless I agree upon the terms of those.
Then we have things like, if I'm buying a product then there's a warranty with that. So maybe there's some sort of warranties. If it's a physical product, that's still the same type of an agreement that I get when I buy that, of how long it will last, how long I can actually use it for and expect to use it before it breaks.
Then there are service providers who maybe I bring in to provide some sort of service. Maybe it's internet services. Maybe it's some sort of cloud service. Maybe they're coming in and helping me out with help desk. Maybe it's a managed service provider like help desk. So there are different services that somebody might be providing me, and we need this overall umbrella of how we're going to do business together. That's the master service agreement. The master service agreement is the umbrella agreement that determines everything else. Usually you just sign the master service agreement once and it's good for years and years and years. Whether we're doing business or not, it's still good. It just sits there, and we only go back and change it and address it when we need to.
And then if they are carrying out some sort of function for us, like maybe they're helping us out with a project, then at that point that's a statement of work. At that point in time we look at the project and what's expected of both people, what is going to be deliverable, and how much is it going to cost. So the statement of work gets specific to the actual work that's going to be done.
This all has to deal with customers that we're providing services for, but it also applies for vendors and service providers that we're using, just as we have customers that are reporting it for us. We're asking for services from some sort of vendor, and they're giving us services, and so we're working with those vendors and service providers. They're going to have the same type of contracts depending on what kind of service provider or product provider there is. Generally with IT products it's more like warranties. If it's some sort of software as a service, then it's more like a terms of service. Or if they're like a managed service provider, then it's more like an MSA or S that we are going to agree upon.
A big focus also for these policies is going to be for employees and internal users of our systems, people who are signing on to our back-end business systems.
First of all, we need to have some sort of acceptable use policy. This is kind of the overall policy of what's expected of them if they're using our services. Maybe we're giving them a username and password, an account to log into our systems. They're going to be in our systems, and if they were to do something illegal or something that is against what the company has, but we don't have something like an acceptable use policy, there's not a lot of legal recourse. What it does is it protects us. We put this AUP out there and it says this is what you're supposed to be doing and how you're supposed to be behaving. And when they break that, then we can fire them, or we can punish them, or we can actually even bring maybe a legal suit against them if it's grievous enough. So there's this acceptable use policy of: okay, you're using our systems, you're not going to abuse those systems. It sets the ground rules for that. An acceptable use policy is extremely important for your employees and your internal users.
Then we also, accompanied with that, might have a password policy. This could be a separate policy from the acceptable use policy, or a component within the AUP, but it just outlines what's expected of user accounts and what's expected of passwords and how they need to form their passwords. Passwords is an extremely important thing when it comes to cyber security, so being able to agree upon a set of rules when it comes to passwords is extremely important.
And then we have data handling policies. What this has to deal with is that it's more and more important that we keep privacy within our company: privacy for our employees, privacy for our customers, privacy for any data that we're handling that's about somebody else. Not only that, but we have internal documents that are sensitive to the company. So having a clear understanding of how we handle data within the company, and what's confidential and what's not confidential, is going to be extremely important. That way everybody's on the same page and we treat that data as it should be treated.
And then we have a lot of other types of policies. By no means are these exhaustive lists; these are just some examples, some highlights of some policies. But one of them is the bring your own device policy. Sometimes companies don't want you to bring your own device, because now you're taking an unknown element of whatever this device is. Let's say it's a laptop, and you're plugging it into the network and into company resources, and they don't know if data is being put onto that laptop, or whatever that device is. They don't know what's happening, if that device has the proper antivirus. So bring your own device is kind of scary for a lot of security professionals. We don't necessarily want that on our network, but there are tools and things that are better now that help us allow this to happen. There's going to be some employees that just want to bring their own device, and there are some advantages to the company, like they don't have to then pay for that device. So in that scenario, maybe we have a bring your own device policy that allows them to bring their own devices and use their own devices, and how are we going to treat that, and it lays out exactly what that looks like. A bring your own device policy is very common for a lot of businesses.
Then we've got that other relationship, working with partners. So we maybe need some sort of partnership agreement. Maybe there's a partnership contract that we sign. But a partnership contract is going to be very detailed, and we have lawyers look at it, and it's going to be very legalistic. So there are steps that we can actually do before we actually get to the contract level. The thing is, a lot of times when you get to the contract level, you've already spent years in negotiation, or at least months, and there's already been a big investment, and that's a long ways away to have this legal document. So leading up to it, we might want to put some protection in place.
A memorandum of agreement, or an MOA, is something that we can put in place before we get to the full contract, something that just says, hey, this is what we're agreeing upon. There is some legal binding to it, that is, that I can take somebody to court, or a business can take somebody to court, if somebody crosses the lines. But really what it does is it just protects the assets and it protects the companies, that this is the direction we're heading. We're leading up to a contract and there's some legal grounding with that.
But sometimes we're not even to that point where we want that legal grounding, where we just want an understanding between two parties of what we're guiding to, what we're going to. And so that's the memorandum of understanding. There's not as much legal backing to this, but at least we've got a document that outlines what this relationship is going to look like. So a lot of times we'll start out with this memorandum of understanding, so that way we've got this good understanding of what we're heading towards and what we have, and then we move to maybe a memorandum of agreement or a partnership where it has a little more legal boundaries with it, of exactly how the partnership is going to work.
There are a lot more policies and things that we create, but these are the major categories that they mostly fall into: those who are internal to the company, those who are clients of us, those who we are clients or customers of, and then partners that the business is partnering with. We want to make sure that there is a good understanding with all of these entities, with all these different groups, with all these users, with all these stakeholders, whoever the case may be. We want to make sure that there's a good understanding of what is expected as we move forward with these agreements and partnerships and moving forward with that relationship.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →