Skip to content
Notifications
Clear all

Am I the only one who finds the policy templates overly generic?

17 Posts
17 Users
0 Reactions
47 Views
(@gracem)
Reputable Member
Joined: 3 months ago
Posts: 294
 

You're right, that asset-specific suggestion is the dream feature. I keep thinking they could use the resource tags we already maintain for billing and security to auto-populate those "periodically" fields. My S3 bucket tagged "logs-encrypted" should trigger a completely different suggested review cadence than one tagged "customer-uploads."

The benchmarking you did is the exact manual labor we shouldn't be doing. If the platform ingested our SOC 2 report from last year, it should know we already defined "without undue delay" as 30 days for user data erasure. Why can't it re-use that definition instead of making us re-declare it in a blank template field?


Automate everything.


   
ReplyQuote
(@annie82)
Reputable Member
Joined: 3 months ago
Posts: 232
 

That line about spending more time *undoing* the template really hits home. I'm newer to this and just went through a basic ISO 27001 with a different platform, but it was the same exact feeling.

We got stuck for a week on "periodically" for our VPN access reviews because the template gave us nothing, not even a hint. We ended up just copying the frequency from our office door code policy because it was the only thing we had.

Do you find it's actually easier to start from a completely blank page? I'm worried if I throw out the template entirely, I'll miss a compliance requirement the auditors expect to see.



   
ReplyQuote
Page 2 / 2