Create, Edit or Revise a Policy
6 min
create a policy for the written guidelines that your organization communicates to its employees about how they execute security strategy policies formalize your organizational approach to achieving control requirements to create, edit or revise a policy, you must log in to as a grc manager to create a policy open the policy workspace click new grc policy to open a blank policy form enter the information into the fields as required owner email and business owner email auto populate based on the owner and business owner fields mandatory fields are marked with an asterisk click save in the details tab, enter the information into the fields as required you can also add attachments in the details tab use the policy documents , journals , risk assessments , audits , assets , compliances , exceptions , and linked policies tabs to add supporting records to the policy use the exceptions tab to create new exceptions, or click ( go to ) to fully open an existing exception record associated with a policy when creating a new exception from within a policy record, the exception type and audit fields are automatically populated in the exception record form you should not edit these fields use the control tab to create new controls you can restore hidden tabs using the plus sign (to the right of the tabs) use the approvers tab to link users who must approve the policy you must specify approvers before setting the policy status to pending approval when the policy is in pending approval status, the approval vote tracking tab appears the policy record is locked and cannot be edited when in pending approval status also note that linked records cannot be edited when opened from a link approvers select the appropriate approval on the approval vote tracking tab, and can select approve or deny if all the approvers approve the policy, the status changes to active if any approver denies the policy, the status changes to revision required the policy originator can go back and make the changes required for approval click save click refresh if changes you made or relevant tabs are not shown in the record after you have saved it edit a policy when a policy record's status is set to cancelled or retired , it can no longer be edited to edit a policy double click the policy to open the details edit the information as required click save revise a policy when a policy is revised, the existing policy is cloned and a new policy is created the information in the existing policy, including links (except those in the approvers and approvals tabs) and attachments, are copied over to the new policy the existing policy is retired, and can no longer be edited a policy must be approved or retired before it can be revised approve a policy on the approval vote tracking tab, which is displayed when the policy is in pending approval status when approved and the policy status is active , the revise policy button is displayed in the policy the revise policy button is also displayed in retired policies to revise a policy double click the policy to open the details click revise policy click yes
