Short Policy Title¶
Controls: A.X.Y · Owner: Name · Applies to: who/what · Review: annual
Why (1 line): the risk this manages.
Rules — these must always be true¶
- Rule 1 — specific and checkable (e.g. "All production data is encrypted at rest with AES-256").
- Rule 2 — …
- Rule 3 — …
How we prove it (evidence)¶
- Rule 1 → where the evidence lives (console/screenshot/config path) —
TODO(owner) - Rule 2 → …
If a rule isn't true¶
Raise it as a nonconformity (ISMS-DOC-10-1) or a risk (ISMS-DOC-06-3), assign an owner, fix it.
Checklist policy — keep it to one screen. Full background lives in the linked context/risk docs, not here.