Skip to content

Policies

A policy is a document that states what is expected of people: an acceptable-use policy, a password standard, a data-classification scheme, an incident-response procedure. In CyberGuard a policy is a special kind of applied control, so it inherits everything an applied control has — a domain, an owner, a status, links to the requirements it satisfies, evidence — while getting its own page so the published corpus can be managed apart from the broader action plan.

Governance → Policies in the sidebar.

The Policies page lists every applied control whose category is policy. Anything you can do to an applied control you can do to a policy: set its Status, Priority, Owner, ETA and Expiry date, attach Evidences, and link it to the requirement assessments it satisfies across your audits. Because the link is many-to-many, one policy can substantiate requirements in several frameworks at once — which is exactly what makes a single access-control policy answer NIST, ISO and CMMC requirements together.

The status lifecycle is the applied-control lifecycle: Undefined, To do, In progress, On hold, Active, Degraded, Deprecated. Active means the policy is published and in force. Retire a superseded policy by setting it to Deprecated rather than deleting it, so past audits keep their evidence trail.

Creating a policy from a reference control in the policy category pre-fills its name, description and framework linkage. This keeps naming consistent across domains and makes it obvious which policies a newly loaded framework expects you to have.

The policy record is the management wrapper; the text itself lives in a managed document attached to it. From a policy’s detail page you can author the document in the built-in editor, upload an existing file, or link to one held in another system. Each route carries the same revision history and the same lifecycle — Draft, In review, Change requested, Validated, Published, Deprecated — and each saved change produces a new numbered revision you can read and diff against any earlier one.

Use the add button to create a policy, then set its domain, owner and status. The list supports search and filters by status, priority, owner and domain, so you can answer “which policies in this domain have no owner” or “which are due for review this quarter” directly from the table.

  • Policy creation — generate, sign and distribute a policy from a template.
  • Applied controls — the underlying object and its full field set.
  • Documents — the authoring, versioning and publication workflow.
  • Evidences — what proves a policy is applied, not just written.
  • Governance model — how policies relate to the rest of the governance objects.