Policy & Procedure Downloads¶
Every document in the Policies & Procedures section, collected here for download. These are the same files the buttons on each document page produce.
Import into your own GRC-ITSM instance
Every file below maps onto the GRC-ITSM KB article fields the same way, ready to paste into your instance's Knowledge Base. See Policies & Procedures for what that mapping covers.
Read before you import
Each card links to the document's page as well as its file. The pages carry the Organization-Defined Values tables and framework citations in a readable form; the downloads are for loading into an instance, not for reading.
Platform policies & procedures¶
The policies GRC-ITSM enforces and the procedures the platform executes.
-
The User Access Request lifecycle categories, CAB approval, machine validation evidence, and recertification.
-
Asset, Inventory & Assessment Scope
The live asset register, the records that carry the Minimum Assessment Scope, third-party resources, and the ports, protocols, and services inventory.
-
Certification Data Sharing & Trust Center
The FedRAMP-compatible trust center's portal surfaces, access model, access logging, and public information.
-
Certification Package & SDR Maintenance
The FedRAMP Certification Package and Security Decision Record, generated and maintained from live platform data.
-
The Change Request lifecycle, CAB approval, security impact analysis, and significant change notification.
-
Continuous Monitoring & Reporting
The KSI validation tree, automated validation evidence, recurring compliance tasks, and the Ongoing Certification Report and Quarterly Review.
-
Alert ingest, incident evaluation, PAIN ratings, the FedRAMP reporting chain, After Action Reports, and the FedRAMP Security Inbox.
-
Vulnerability Detection & Response
Vulnerability detection, evaluation, SLA-enforced remediation, deviations, and escalation to reportable incidents.
Client templates¶
Starting points for the compliance practices your organization owns and executes outside the platform. Fill the Organization-Defined Values and formally adopt each one before relying on it in an assessment. See the Client Template Library for what adoption involves.
-
Governance, Training & Secure Development
Security governance roles, role-based training, and secure development practices.
-
Backup, restoration testing, and recovery objectives for the systems you operate.
-
Baseline configuration standards and hardening guidance ownership.
-
Vendor and subservice evaluation, agreements, and ongoing supply chain risk management.
-
Vulnerability Disclosure Program
Receiving, triaging, and responding to vulnerability reports from external researchers.