The Frameworks and Regulations section contains baseline external controls and regulatory requirements to help your organization remain in compliance.
Here is a quick rundown of how it works:
Customize your labels: By default, you'll see the terms "Frameworks" and "Controls." If you prefer, you can easily rename these to "Regulations" and "Regulatory Requirements" right in your Settings.
Stay up to date: It's always best practice to use the latest version of a framework. The good news? PolicyCo lets you update to newer versions without losing any of your previously linked work.
Add or update frameworks: Need a framework that isn't listed yet, or noticed an existing one needs an update? Just shoot a quick email to your PolicyCo Customer Success Manager and let them know what you need added!
Scope what matters to you: You're in the driver's seat. You have the power to scope only the controls that actually apply to your organization. Setting this up correctly helps you easily map your controls to your articles and use your dashboard to ensure all compliance gaps are completely closed.
What frameworks do we support?
PolicyCo handles a huge variety of industry standards. Some of the most popular ones already available on the platform include:
SOC2
HIPAA
GDPR
ISO (e.g., ISO 27001, ISO 22301)
NIST (e.g., NIST CSF v1.1, NIST SP 800-53)
PCI DSS (e.g., PCI DSS v3.2.1)
and many, many more!
