Policies & controls
Assessments tell you what to do; policies and controls are how you show you’re doing it. This section covers generating policies, storing them, and maintaining the controls library that ties everything to your frameworks.
Policy Generator
Section titled “Policy Generator”Create audit‑ready policies — acceptable use, password, incident response, data protection, and more — tailored with your organisation’s context:
- Go to Policy & Process → Policy Generator (or start from a template in the Policy Vault).
- Pick the policy type and confirm your organisation details.
- Review the draft, then export to PDF — branded with your logo and an ownership block, delivered via a secure download link.
Policy Vault
Section titled “Policy Vault”The Policy Vault stores your policies with draft and active status, so you always know which version is current. Templates provided out of the box (such as Acceptable Use, Data Protection and Incident Response) follow a review and approve workflow before they go active.
Controls Vault
Section titled “Controls Vault”The Controls Vault is your security controls library:
- Create controls and describe how you meet them.
- Tag each control to frameworks — and let AI validation check that a control genuinely satisfies the framework requirement it claims.
- Link controls to the assets and people they apply to, and attach evidence.
Because controls are tagged to frameworks, they feed straight back into your compliance scores and cross‑mapping — so the work you do on one control is visible everywhere that control is relevant, and the evidence you attach to it can be reused against every framework that asks the same question.
How it fits together
Section titled “How it fits together”- Assessments identify gaps.
- Controls record how you close them, tagged to frameworks and linked to assets/people.
- Evidence proves it.
- Policies document the rules behind it.
Together these produce a defensible, self‑maintaining compliance position rather than a folder of stale documents.
Why it matters
Section titled “Why it matters”For everyday security: clear, current policies set expectations for your team, and a controls library keeps your safeguards documented rather than tribal knowledge.
For compliance: policies and a mapped controls library, with evidence, are exactly what an assessor asks for. The branded PDF export, versioning and approval workflow give you auditable artefacts on demand.
Next: Reports →