The Frameworks and Regulations section contains baseline external controls and regulatory requirements to help your organization remain in compliance.
Dynamic Labels: By default, these are labeled "Frameworks" and "Controls," but can be renamed to "Regulations" and "Regulatory Requirements" in your Settings.
Versioning: Best practice is to use the latest version of a framework, though PolicyCo allows updating versions without losing linked work if the changes aren't meaningful. Simply email your specialists and notify them if you need a new version brought in or if the framework you need is not yet included.
Examples of Supported Frameworks
PolicyCo includes a wide range of standards. Some widely used examples available in the platform include:
SOC2
HIPAA
GDPR
ISO (e.g., ISO 27001, ISO 22301)
NIST (e.g., NIST CSF v1.1, NIST SP 800-53)
PCI DSS (e.g., PCI DSS v3.2.1)
How to Manage Controls
To Add Frameworks or Regulations:
Go to Settings and click Frameworks (or Regulations).
Select the specific Framework you need.
Check the specific external controls that are in scope.
Note: You can "add all," but use caution as this action cannot be easily reversed to a previous state if you had specific selections.
To Remove Frameworks or Regulations:
Go to Settings and click Frameworks.
Uncheck the controls that are no longer in scope.
Note: If you remove a control that was linked to an article, PolicyCo remembers the association. If you add it back later, the link is restored.
