For organisations with unique requirements, CSFaaS enables the creation of custom policies tailored to specific business practices, compliance mandates or risk management strategies.

1. Quick Reminder

Information security policies are commonly categorised into three main types:

  • Program policies: high-level directives that establish the organisation's security programme.
  • Issue-specific policies: focused on particular concerns, such as email usage or access control.
  • System-specific policies: detailed guidance on the security requirements of individual systems.

CSFaaS supports all three, offering the flexibility to create, edit and manage policies that suit your organisation's structure.

2. Steps to Create a Single Policy

  1. Navigate to the Policies section.
  2. In the Policy structure panel, click the add (+) button.
  3. In the drawer, under "What would you like to add?", choose Policy (a top-level document grouping categories and controls).
  4. Fill in the requested information:
    • Displayed policy code: a unique identifier; a code is suggested automatically and you can adjust it.
    • Policy name: a clear, descriptive title.
    • Policy description: the purpose and scope of the policy; this is a rich-text field you can develop into the full policy content later.
  5. Click Create policy.

The new policy appears in the tree, ready to receive categories, subcategories and controls.