TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Policies

Estimated reading: 11 minutes 5167 views

What is a policy?

A policy is a formal document that defines an organization’s approach, expectations, and intent regarding specific processes and procedures. It establishes guidelines that help maintain consistency, compliance, and operational efficiency.

Policies exist at different levels within an organization. High-level policies outline general principles and objectives, while more specific policies address particular areas such as remote access or data security.

Policies are often used alongside other documents, including:

  1. Procedures – Provide step-by-step instructions for implementing policies.
  2. Standards – Define specific rules or requirements to ensure compliance.
  3. Guidelines – Offer recommendations and best practices.

A policy primarily addresses what needs to be done and why it is necessary and provides some context for how it should be implemented. Detailed implementation steps are typically covered in procedures, standards, and guidelines.

Policies in TrustOps

TrustOps provides automatically generated policies based on the controls within your TrustCloud program. These policies define security, management, and compliance requirements, helping organizations maintain governance and regulatory compliance.

Viewing policies

You can view and manage policies on the “Policies” page in TrustOps.

TO - Policies

Automatically generated policies

TrustOps automatically personalizes the following policies based on your organization’s compliance requirements:

  1. Access Control Policy: Defines principles and guidelines for controlling access to organizational systems.
  2. Information Security Policy: Establishes an information security program to protect the confidentiality, integrity, and availability of data and assets.
  3. Authentication and Password Policy: Describes authentication requirements, including password generation, use, and protection.
  4. Security Incident Management Policy: Outlines procedures for reporting and responding to security incidents.
  5. Physical Security Policy: Establishes controls for facility access and data center security.
  6. Information Security Management System (ISMS) Policy: Defines the framework for an organization’s information security program.
  7. Backup Policy: Specifies controls for maintaining data backups to prevent accidental data loss.
  8. Vendor Management Policy: Defines processes for selecting, acquiring, and managing third-party vendors with access to sensitive data.
  9. Data Retention and Disposal Policy: Establishes guidelines for retaining and securely disposing of organizational and customer data.
  10. Audit Logging Policy: Outlines logging requirements for security monitoring and audit purposes.
  11. Encryption Policy: Defines encryption standards to protect sensitive data from unauthorized access.
  12. Internal Audit Policy: Details objectives, authority, and responsibilities for internal audits.
  13. Change Management Policy: Provides guidelines for managing changes across critical systems and products.
  14. Human Resource Policy: Defines requirements for hiring, training, and retaining employees to meet business and security objectives.
  15. Asset Management Policy: Establishes guidelines for protecting IT assets used to access sensitive data.
  16. Vulnerability Management Policy: Defines controls and processes for identifying and mitigating security vulnerabilities.
  17. Business Continuity Policy: Outlines plans for maintaining operations during disruptions, including natural disasters and cyber incidents.
  18. Acceptable Use Policy: Establishes rules for the appropriate use of organizational IT resources.
  19. Data Classification Policy: Defines a framework for classifying data based on sensitivity and risk.
  20. Risk Management Policy: Establishes a structured approach to risk assessment and mitigation.
  21. Compliance Program Management Policy: Describes the organization’s compliance program and its operational framework.

For more details, refer to the TrustOps documentation.

Policy attributes in TrustOps

Policies in TrustOps include key attributes that define their purpose, ownership, and compliance status. These attributes help organizations effectively manage policies and ensure they align with governance and compliance requirements.

General Policy Attributes

  1. Policy Name: The name assigned to the policy.
  2. Description: A brief overview of what the policy covers.
  3. Policy ID: A unique abbreviation representing the policy.
  4. Group: The organizational group associated with the policy.
  5. Linked controls: The number of controls that are linked to the policy.
  6. Status: Status of the policy if it is approved or pending approval.
  7. Risk: The calculated risk level based on control mapping.

These attributes provide visibility into policy ownership, compliance status, and associated risks, ensuring a structured approach to policy management in TrustOps.

The following screenshot shows the policy attributes.

TO - Policy attributes

Assigning policy ownership in TrustOps

Policy ownership and approval

In TrustOps, policies require continuous review and approval to ensure compliance. The policy owner, whether a specific individual or a job title, is responsible for maintaining and approving policies. TrustOps enables you with an approval record directly within the program, ensuring transparency and accountability in policy management.

Who is a policy owner?

A policy owner is typically a department head or a subject matter expert responsible for overseeing the policy’s content and ensuring its alignment with organizational requirements.

Approval process

As a part of approval process, you will receive an email notification about the task that is been assigned to you for approving the particular policy.

TO Policy Approval Notification

Click on the “View Task In TrustOps” button in the notification email to approve the policy.

Approval frequency

  1. Policies are typically approved annually or whenever changes occur.
  2. Some policies may require more frequent approval based on organizational needs or regulatory requirements.

Approval process in TrustOps

TrustOps allows users to:

  1. Assign policy approvers.
  2. Set review and approval frequencies.
  3. Track approval records for audit purposes.

By maintaining a structured approval process, organizations can ensure that their policies are consistently reviewed and kept up to date.

Steps to approve policies (if you are assigned a policy to approve)

From Tasks page, 

  1. In TrustOps, go to the “Tasks” page, click on the task to view it.
  2. Click on “Begin Task” to review and approve the policy.

From “Policies” page,

  1. Go to the policy details page.
    TO - Policy details
  2. Click on the policy and go to the approvals tab.
  3. Click on “Approve Now.”
    TO - Policies Approval
  4. You can view the approval history from here and also can remove approvals.

Steps to assign a policy owner

  1. Go to the “Policies” page.
  2. Click on a policy.
  3. On the policy details page, click on the “Owner” icon.
    TO - Policies - Assign owner
  4. Select the name and click on the “Assign to” button.
  5. You can assign your name as the owner by clicking on the “Assign to Yourself” button.
  6. You can click on the “Invite New Owner” button to invite people who are not present in the list.

Policy approval ensures that policies remain accurate, relevant, and compliant. It is a best practice to have one or more individuals review and approve policies at a set frequency.

Policy branding

Policies are typically shared across the organization with employees, with auditors during audits, and, in some cases, with customers during security reviews. It’s important to personalize your policies with your organization’s logo and other organization-related information.

To personalize policies according to branding,

  1. Go to “TrustCloud.”
  2. From the left-hand side menu, select “Platform Administration.”
  3. Click on “Branding.”
  4. In “Brand Elements” section, upload the company logo and company icon.
  5. In the “Policy Documents” section, you can opt for a header, footer and watermark. Depending on your selection, your company’s name or logo appears at the top of every page of every policy document in your program. All policy documents in your program include a standard footer that displays the policy’s last approval date, the page number, and the word “confidential.” When exported, your policy documents will include a watermark with the exporting user’s email address and the current timestamp.
    The following screenshot shows the branding on policy documents.
    TO - Policy branding

The following video will guide you to personalize your policies by adding your organization’s branding (like a logo, etc.) in TrustOps and sharing your personalized policies with customers and auditors:

The following video will show the steps to adding branding to a policy.

Video: How to add branding to a policy:

Creating a new policy

TrustCloud provides a set of pre-built policies. However, if your organization requires additional policies, you may need to create them manually.

Before creating a new policy, check with the support team to determine which policies are included in your plan.

Process to create a new policy

  1. Access the Policies Page – Navigate to the “Policies” section in TrustOps.
  2. Review Existing Policies – Ensure that the required policy does not already exist.
  3. Contact Support (If Needed) – If additional policies are needed, reach out to the TrustCloud support team for guidance.

By following this process, you can effectively manage and customize your organization’s policies within TrustOps.

To create a new policy,

  1. In TrustOps, go to the “Policies” page.
  2. Click on the “+ New Policy” button in the top-right corner. This will open a workflow that will guide you through policy addition and mapping.
  3. Upload, link, or create a new policy.
    TO - Add new policy
  4. Click on “Next” button.
  5. Enter title, ID, select group, security group, and policy description and click on “Next” button.
    TO - Add policy details
  6. Review details.
  7. Click on “Next” button.
  8. Select “Policy Owner” and click on “Finish” button.
  9. Edit or make changes to the policy and click on “Publish Changes.”
    TO Add New Policy Publish
  10. You can link controls or skip and do it later, click on “Publish” button.
  11. You can view the newly created policy on “Policies” page.

Linking controls to your policy

Control mapping in policies is an important factor in improving your GRC program and tracking adherence. You have the option of linking planned or adopted controls prior to publication. You can also edit this mapping at a later stage. Once you have mapped controls, publish the policy along with the version number. This new policy will be available on your policy lists across the platform.

To link controls to a policy,

  1. In TrustOps, go to the “Policies” page and go to “Linked Controls” tab.
    TO - Policies - Linking control 01
  2. Click on the “Link a Control” button. AI-assisted policy control matches when adding, editing or directly linking controls to policies.
    The following screenshot shows the linking of controls to a policy.
    TO - Policies - Link Controls to Your Policy
  3. Add the desired controls and click on the “Link Controls” button.

 

Editing policies

TrustCloud offers an Edit Policy menu option to customize existing text, write your own, or bring in the contents of an existing policy by pasting its text. This editor enables you to format your policy, choose whether or not (and where) to insert its approval log and related control list, and add TrustCloud control texts. TrustOps also supports smart variables; dynamic, auto-updating values representing key attributes of a policy, such as its owner, which you can use when composing your policy.

To edit policy,

  1. Go to the “Policies” page.
  2. Click on the policy.
  3. From the three-dot menu, select “Import/Edit Policy.”
    Policies
  4. Click on “Edit the existing template in TrustCloud’s editor” or “Start from scratch in TrustCloud’s editor.”
    The following screenshot demonstrates the editing of a policy in TrustOps.
    TO - Editing policy
  5. A template is provided to delete or add text to the policy. You can also add a smart element to the policy, such as a control or an owner, by dragging the smart element from the list into the policy.
  6. Click on the “Publish Changes” button at the top.
  7. Once you’ve made changes to a policy, you can choose to revert to TrustCloud’s policy by selecting the three-dot menu (…) and clicking on “Revert.”

The following video will help you use the “Smart Element” tool to edit your policies.

Video: How to edit a policy

If you’re only experimenting with policy editing, be assured that you can always get back to using a policy at any time.

Policy approvals

The policy approvals tab gives you the overall approval trail for the particular policy. You can remove approval or approve the policy from here.
TO - policy approvals

Policy versioning

Policy versioning allows you to keep track of how your policies evolve over time, so you can view editing history, changes, and versions with ease. Also, you can download historical copies just in case the new version doesn’t meet your goals.

To view policy versioning,

  1. Go to the “Policies” page.
  2. Click on the policy.
  3. Go to “Versions” tab.
    TO - Policy - Versions
  4. You can view the version details and also can download the versions.

Deleting a policy

To delete a policy,

  1. Go to the “Policies” page.
  2. Click on the policy.
  3. From the three-dot menu, select “Delete Policy.”
  4. A conformation window is shown.
    The following screenshot shows the delete confirmation window to delete a policy.
    TO Policies Delete Policy 16
  5. Select a reason for deleting a policy. Click on “Proceed” button.
    The following screenshot shows deleting the policy.
    TO Policies Delete Policy 17
  6. Click on “Delete Policy from your Program” button to confirm deleting the policy.

Sharing policies with customers

The TrustShare application in TrustCloud allows organizations to securely share policies and compliance information with customers.

Key Features

  1. Secure Access – Invite customers to view relevant policies in a controlled environment.
  2. Live Trust Portal – Provide customers with real-time visibility into security and privacy posture.
  3. Compliance Transparency – Share trust and compliance programs to build confidence with customers.

By using TrustShare, organizations can ensure customers have up-to-date insights into their security and compliance efforts.

Refer to the “Getting Started” guide in TrustShare to set up your TrustShare account.

Join the conversation

You might also be interested in

Custom Frameworks

TrustCloud supports several standards and frameworks out of the box, including SOC 2, CMMC,...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Systems

A system is a piece of software, either built by the organization or purchased...

Groups in Controls

TrustCloud provides you with a comprehensive set of controls to get certified against several...

Mapping a Control

TrustCloud’s common controls framework maps a comprehensive set of certified standards controls and your...

Sharing Controls with customers

The TrustShare application in TrustCloud makes it easy for startups, SMBs, and enterprises to...

Excluding a control, test or attestation

The exclusion allows you to remove certain resources, controls or tests from your program...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue