Skip to main content

Overview

Understand how to add compliance frameworks and regulations to your organization.

Updated over 3 weeks ago

The Frameworks and Regulations section contains baseline external controls and regulatory requirements to help your organization remain in compliance.

  • Dynamic Labels: By default, these are labeled "Frameworks" and "Controls," but can be renamed to "Regulations" and "Regulatory Requirements" in your Settings.

  • Versioning: Best practice is to use the latest version of a framework, though PolicyCo allows updating versions without losing linked work if the changes aren't meaningful. Simply email your specialists and notify them if you need a new version brought in or if the framework you need is not yet included.

Examples of Supported Frameworks

PolicyCo includes a wide range of standards. Some widely used examples available in the platform include:

  • SOC2

  • HIPAA

  • GDPR

  • ISO (e.g., ISO 27001, ISO 22301)

  • NIST (e.g., NIST CSF v1.1, NIST SP 800-53)

  • PCI DSS (e.g., PCI DSS v3.2.1)

How to Manage Controls

To Add Frameworks or Regulations:

  1. Go to Settings and click Frameworks (or Regulations).

  2. Select the specific Framework you need.

  3. Check the specific external controls that are in scope.

    • Note: You can "add all," but use caution as this action cannot be easily reversed to a previous state if you had specific selections.

To Remove Frameworks or Regulations:

  1. Go to Settings and click Frameworks.

  2. Uncheck the controls that are no longer in scope.

    • Note: If you remove a control that was linked to an article, PolicyCo remembers the association. If you add it back later, the link is restored.

Did this answer your question?