Policies & Procedures¶
These documents establish the policies GRC-ITSM enforces and the procedures by which the platform executes them. Each one states its policy as numbered, binding statements, carries an Organization-Defined Values table with framework defaults, and cites the FedRAMP Consolidated Rules it satisfies, along with the Key Security Indicators and CMMC practices where they apply.
Import into your own GRC-ITSM instance
Every document below carries a download button that produces a Markdown file mapped to the GRC-ITSM KB article fields -- Description, Resolution, Internal Memo, and Tags (including the KSIs, controls, and baselines it satisfies) -- ready to copy and paste into your instance's Knowledge Base.
How this section relates to the Operational Playbooks
Policies & Procedures describe what the platform does and why -- the governance layer an assessor reads. The Operational Playbooks describe how to execute those procedures in the product, click by click. Each document below links to its matching playbook where one exists.
Platform policies & procedures¶
-
The User Access Request lifecycle categories, CAB approval, machine validation evidence, and recertification.
-
Asset, Inventory & Assessment Scope
The live asset register, the records that carry the Minimum Assessment Scope, third-party resources, and the ports, protocols, and services inventory.
-
Certification Data Sharing & Trust Center
The FedRAMP-compatible trust center's portal surfaces, access model, access logging, and public information.
-
Certification Package & SDR Maintenance
The FedRAMP Certification Package and Security Decision Record, generated and maintained from live platform data.
-
The Change Request lifecycle, CAB approval, security impact analysis, and significant change notification.
-
Continuous Monitoring & Reporting
The KSI validation tree, automated validation evidence, recurring compliance tasks, and the Ongoing Certification Report and Quarterly Review.
-
Alert ingest, incident evaluation, PAIN ratings, the FedRAMP reporting chain, After Action Reports, and the FedRAMP Security Inbox.
-
Vulnerability Detection & Response
Vulnerability detection, evaluation, SLA-enforced remediation, deviations, and escalation to reportable incidents.
Client templates¶
Some compliance practices are owned by your organization rather than executed by the platform. GRC-ITSM ships starting-point templates for those domains -- see the Client Template Library.