Skip to main content

Policies and Documents

Overview

The Policies section helps you version, approve, and distribute security policies. Your vCISO drafts all required policies for you, tailored to your organization. You review them, request changes over Slack, and approve when ready.

Policy Lifecycle

DraftInitial creation orrevisionReviewStakeholder review andfeedbackApprovedFormally approved byauthorityDistributedSent to relevantemployeesAcknowledgedEmployees confirm receiptand understanding
DraftInitial creation or revision
ReviewStakeholder review and feedback
ApprovedFormally approved by authority
DistributedSent to relevant employees
AcknowledgedEmployees confirm receipt and understanding

How Policies Are Created

Your vCISO writes the policies required by your target compliance frameworks. They are drafted to match your organization's size, industry, and actual practices. The typical flow:

  1. Your vCISO drafts the policies and uploads them to CompliancePolicies
  2. You receive a notification to review
  3. Discuss changes or ask questions over Slack
  4. Approve when the policy reflects your organization accurately

Common policy types your vCISO will prepare:

  • Information Security Policy
  • Acceptable Use Policy
  • Access Control Policy
  • Incident Response Plan
  • Business Continuity Plan
  • Data Classification Policy
  • And more, depending on your frameworks
tip

You can also create additional policies yourself via Create Policy if you need custom internal documentation beyond what your frameworks require.

Policy Editor

The policy editor supports:

  • Rich Text - Formatting, lists, tables
  • Sections - Organized structure
  • Variables - Dynamic placeholders (company name, etc.)
  • Version Notes - Document changes between versions

Approval Workflow

Configuring Approvers

Each policy can have multiple approvers:

  1. Open the policy
  2. Click SettingsApprovers
  3. Add required approvers (e.g., CISO, Legal, HR)
  4. Set approval order (sequential or parallel)

Submitting for Approval

  1. Complete policy draft
  2. Click Submit for Review
  3. Approvers receive notification
  4. Track approval status in dashboard

Approval Actions

Approvers can:

  • Approve - Move policy forward
  • Reject - Return with feedback
  • Comment - Add notes without decision

Version Control

Versioning

Policies are automatically versioned:

  • Major versions (1.0, 2.0) - Significant changes
  • Minor versions (1.1, 1.2) - Small updates

Version History

View all versions:

  • Previous content
  • Change notes
  • Approval history
  • Distribution records

Comparing Versions

  1. Open policy
  2. Click Version History
  3. Select two versions
  4. Click Compare
  5. View highlighted differences

Distributing Policies

Distribution Methods

MethodUse Case
EmailSend policy with acknowledgment link
In-AppNotify users within Bastion
DownloadProvide PDF for external use

Creating a Distribution

  1. Ensure policy is approved
  2. Click Distribute
  3. Select audience:
    • All employees
    • Specific groups
    • Individual users
  4. Set acknowledgment deadline
  5. Customize message
  6. Send

Tracking Acknowledgments

Monitor acknowledgment progress:

  • Pending - Not yet acknowledged
  • Acknowledged - Confirmed receipt
  • Overdue - Past deadline

Send reminders to employees who haven't acknowledged.

Policy Library

Organizing Policies

Organize policies by:

  • Category - Security, HR, IT, etc.
  • Status - Draft, Approved, Archived
  • Owner - Responsible department
  • Framework - Related compliance requirements

Search and Filter

Find policies using:

  • Full-text search
  • Category filters
  • Status filters
  • Date ranges

Document Repository

Beyond policies, manage:

  • Procedures - Step-by-step instructions
  • Standards - Technical requirements
  • Guidelines - Best practices
  • Diagrams - Architecture and process flows

Compliance Mapping

Linking to Controls

Map policies to compliance controls:

  1. Open policy
  2. Click Compliance Mapping
  3. Select relevant framework controls
  4. Save mapping

This creates evidence links for audit purposes.

Best Practices

Keep Policies Concise

Long, complex policies are less likely to be read and followed. Focus on essential requirements.

Review Regularly

Set review cycles (typically annual) and stick to them. Outdated policies create compliance gaps.

Use Clear Language

Avoid jargon and legalese. Policies should be understandable by all employees.

Track Acknowledgments

Ensure all relevant employees acknowledge policies. Follow up on non-responses.

Next Steps