You're right, that asset-specific suggestion is the dream feature. I keep thinking they could use the resource tags we already maintain for billing and security to auto-populate those "periodically" fields. My S3 bucket tagged "logs-encrypted" should trigger a completely different suggested review cadence than one tagged "customer-uploads."
The benchmarking you did is the exact manual labor we shouldn't be doing. If the platform ingested our SOC 2 report from last year, it should know we already defined "without undue delay" as 30 days for user data erasure. Why can't it re-use that definition instead of making us re-declare it in a blank template field?
Automate everything.
That line about spending more time *undoing* the template really hits home. I'm newer to this and just went through a basic ISO 27001 with a different platform, but it was the same exact feeling.
We got stuck for a week on "periodically" for our VPN access reviews because the template gave us nothing, not even a hint. We ended up just copying the frequency from our office door code policy because it was the only thing we had.
Do you find it's actually easier to start from a completely blank page? I'm worried if I throw out the template entirely, I'll miss a compliance requirement the auditors expect to see.