Company Policies

The organization's adopted rules, standards, and guidance that steer behavior and decisions. Because user stories are written to align with current policies, any policy change can force updates to existing stories, acceptance criteria, and related delivery practices.

Key Points

  • Policies are organization-wide rules, principles, and guidelines that teams must follow.
  • They directly shape user stories, acceptance criteria, and the Definition of Done/Ready.
  • Policy changes require impact analysis, backlog updates, and possible reprioritization.
  • Clear communication and traceability to tests help ensure compliance and reduce risk.

Example

A company updates its data retention policy from 90 to 30 days. The team reviews in refinement, adds or updates user stories and acceptance criteria to reflect 30-day retention, adjusts the Definition of Done, and coordinates with the product owner to reprioritize affected items in the backlog.

PMP Example Question

Mid-sprint, corporate updates its privacy policy. What should the agile team do first?

  1. Assess the policy change, update the backlog and acceptance criteria with the product owner, and adjust plans as needed.
  2. Add the new policy work to the current sprint immediately without discussion.
  3. Ignore the change until the next release to avoid disrupting velocity.
  4. Escalate to the sponsor and wait for formal change control before acting.

Correct Answer: A — Evaluate the policy change and update backlog and criteria

Explanation: Company policy changes are organizational constraints. The team should first perform impact analysis and update user stories and acceptance criteria through backlog refinement with the product owner, then replan as needed.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Stop Managing Admin. Start Leading the Future!

HK School of Management helps you learn AI prompt engineering for project work. Move beyond status reports and risk logs with practical prompt frameworks for everyday tasks. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Enroll Now