Policies

🚧

Beta Feature

This is a beta feature that needs to be flagged on by your customer success rep. Reach out to them if this is something that would be beneficial for you to have enabled in your account.

What are policies?

Policies are the instructions that help you implement your controls. A control is an instruction that will tell you what needs to be done, while the policy tells you how to do the thing.

A policy can be instructions for many controls, and apply to many frameworks. To help you test once, and use everywhere policies are easily mapped to controls and automatically apply to the frameworks the control is mapped to.

1440

Creating Policies

Policies are provided for you when you use Comply's baseline ISMS. If you use your own ISMS or want to create a new policy it's simple.

  1. Navigate to the ISMS and click on the sub-navigation for Policies
  2. Click on Create Policy
1446

Click on Create Policy in the top right to create a new policy

  1. Give your policy a Name
  2. Give your Policy an Owner
  3. Put your Policy content in via the policy library or copy/paste with markdown
646

Input your Policy content in the policy library or copy/paste with markdown

Editing Policies

Policies in Comply can be quickly mapped to controls and edited.
To quickly map a policy to a control, from the Policies view, click the pencil in the controls column and type in the name of the control(s) to add them.

Alternatively you can click on "Controls" from within a policy to map there.

1440

Click the pencil in the controls column and type in the name of the control(s) to add them.

To edit a policy, click into the policy and click the pencil next to the "Policy Content"

1440

Click the pencil next to the "Policy Content" to edit

Policies Approval

Once you have reviewed all of the policies within the ISMS that map to your selected controls and frameworks, you are ready to approve the ISMS so that you have record and version control of the content.

  • Click on the ISMS tab
  • Select the Updated option in yellow on the far left hand navigation
  • Select the policies that you wish to approve just adding/removing the check box beside each
  • Include a version number and a description of the change
  • Select Approve Selected Policies
648

The approval modal filters to just the selected policy when clicking "Approve" from a Policy Detail View.

📘

Versioning your ISMS

Versioning your ISMS helps prove to your auditor that your organization knows what the effective version of the ISMS is at any point in time. We recommend using a familiar schema such as v1.0, v2.0, etc. You can keep track of minor changes to ISMS content in the form of v1.1, v1.2, etc.