Adapting policies to your organization
Implementing security policies that align with your organization’s specific needs is crucial for effective compliance. Our platform offers two types of policy templates to assist you in this process:
- Formal (Minimum Viable Policies): These templates cover essential security guidelines.
- Comprehensive: These are more detailed policies that include stricter requirements, ideal for organizations aiming to adopt comprehensive frameworks like ISO 27001 in the future.
Adapting Policies
Section titled “Adapting Policies”When customizing the templates, focus on adjusting the language to reflect your organization’s practices without altering the core intent of the policies. We recommend retaining most of the guidelines but adapting the wording to fit your organizational setup.
Example:
-
Original Policy Statement:
- Keys and key cards are provided to a subset of employees and are granted on a needs-oriented basis.
-
Adapted Policy Statement (if using pin codes instead of keys):
- Access pin codes are provided to a subset of employees and are granted on a needs-oriented basis.
This ensures the policy remains relevant and accurately represents your security measures.
For certifications like SOC 2 Type II, it’s essential to demonstrate that your organization follows its stated policies and procedures. Our platform’s controls are designed to guide you in providing the necessary evidence.
Filling in placeholders
Section titled “Filling in placeholders”Templates leave bracketed placeholders, like [fill in: the reporting channel], for details only your organization can supply, such as names, contact information, and the tools you use. Everything else in a template ships with a recommended default. Placeholders are highlighted in blue in the policy and in the editor. On the Policies page, a draft that still has placeholders shows how many next to its name, and the draft itself shows a note at the top with the count and a list of what’s left.
A policy can’t be published or submitted for review while it still has placeholders. If you choose Publish version or Submit for review before they’re all filled in, Oneleet lists the placeholders that are left, with a count for any that repeat. Choose View next to one to jump to it in the policy, or copy its text to search for it yourself.
If AI policy review is available, a review suggests values for the placeholders your program data can answer.
Publishing draft policies
Section titled “Publishing draft policies”During onboarding, choose Add policies (or Review with AI, or Maybe later, when AI policy review is available) to add the prepared policies to your policy library as drafts. Fill in each policy’s placeholders, then publish it from its own page or from the Policies page.
To publish several drafts at once, select them in the table on the Policies page and choose Publish in the toolbar. Only drafts that don’t require review are included. Open a review-required policy to submit it for review instead. If any selected draft still has placeholders, nothing is published, and Oneleet lists each of those policies with the placeholders left in it. Each policy and placeholder in that list links to the policy in a new tab, scrolled to the placeholder.
Reviewing Policy Changes
Section titled “Reviewing Policy Changes”When a policy is submitted for review, reviewers can compare it with the latest published version and leave comments on specific lines. The policy author and assigned reviewers can discuss a comment through replies, while the reviewer retains control over resolving or reopening the thread.
Open comments do not prevent approval, so reviewers should resolve completed discussions before publishing when possible. Resolved discussions remain visible in the policy review context.
Need Assistance?
Section titled “Need Assistance?”If you have questions about specific guidelines in the policies or need help applying anything to your organization, please don’t hesitate to reach out. We’re here to help ensure that your security program is both effective and tailored to your company’s unique needs.
Remember: The goal is to maintain best security practices while making policies practical and applicable to your organization’s environment.