Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update policy documentation to use plain language #162

Open
1 of 3 tasks
frangrit opened this issue Apr 18, 2023 · 5 comments
Open
1 of 3 tasks

Update policy documentation to use plain language #162

frangrit opened this issue Apr 18, 2023 · 5 comments
Assignees

Comments

@frangrit
Copy link

frangrit commented Apr 18, 2023

Proposed changes

  • Explain acronyms on first use

  • Use simple words and terms when possible

  • Change to active voice where appropriate

  • Include or link to instructions for for software set-ups and settings changes

  • Create a new branch

  • Create a PR with the handbook changes and link it to this issue.

  • Review the PR with the security team

@frangrit frangrit self-assigned this Apr 18, 2023
@q0rban
Copy link
Member

q0rban commented Apr 18, 2023

I wonder if there's a "plain language" automation we could add, so it could fail a PR if things get over a certain grade reading level or something.

@q0rban
Copy link
Member

q0rban commented Apr 18, 2023

Looks like syllable has an automated-readability formula.

@frangrit
Copy link
Author

That's fun. It'll be tricky, though, because by nature a security policy is going to have a lot of big words. This will probably cause us fail a readability test—but the big words might be necessary. It could be a good first step? Would require some fine-tuning.

@frangrit
Copy link
Author

So for stuff like the quote below, I wonder whether the language is intended to be formal for legal reasons, or if it can be made a bit more friendly.

As such, all employees must ensure they adhere to the guidelines in this policy at all times. Should any employee be unclear on the policy or how it impacts their role they should speak to their manager or IT security officer.

Friendly version:

All employees must adhere to the guidelines in this policy at all times. If you are unclear on the policy or how it impacts your role, you should speak to your manager or someone on the security team.

@deviantintegral
Copy link
Member

The original policy was written using https://www.iso.org/isoiec-27001-information-security.html as a reference, so much of the terminology comes from there. While this policy is used for employees, it is also given to clients who usually ask for it. So while we'll want to be careful about some of the terminology, we certainly can remove or simplify the verbose language.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants