A policy is easier to implement when its context is explicit. In CSFaaS the policy description is a full rich-text document, so the recommended practice is to open each policy with a set of contextual sections before the detailed requirements.
1. Recommended Sections
The following structure is a proven starting point; adapt it to your organisation's needs:
- Overview & Purpose: summarise the policy and explain its intent.
- Scope: define the boundaries and applicability of the policy.
- Policy Compliance: outline how the policy aligns with organisational and regulatory requirements.
- Compliance Measurement: describe how adherence will be monitored and evaluated.
- Exceptions: specify any exceptions and the conditions under which they apply.
- Non-compliance: detail the consequences of failing to adhere to the policy.
- Standards & Policies: reference related standards and policies.
- Definitions & Terms: define the specific terms used in the policy.
- Contacts: list the relevant contacts for questions or guidance.
2. How to Add Them
Select the policy in the tree, open Policy Details, click Edit and write the sections directly in the description using headings. The editor supports headings, lists, tables and links, and several members can write simultaneously. Categories, subcategories and controls each have their own description, so contextual information can live at whichever level it belongs.