Skip to content

Policies & Procedures

These documents establish the policies GRC-ITSM enforces and the procedures by which the platform executes them. Each one states its policy as numbered, binding statements, carries an Organization-Defined Values table with framework defaults, and cites the FedRAMP Consolidated Rules it satisfies, along with the Key Security Indicators and CMMC practices where they apply.

Import into your own GRC-ITSM instance

Every document below carries a download button that produces a Markdown file mapped to the GRC-ITSM KB article fields -- Description, Resolution, Internal Memo, and Tags (including the KSIs, controls, and baselines it satisfies) -- ready to copy and paste into your instance's Knowledge Base.

How this section relates to the Operational Playbooks

Policies & Procedures describe what the platform does and why -- the governance layer an assessor reads. The Operational Playbooks describe how to execute those procedures in the product, click by click. Each document below links to its matching playbook where one exists.


Platform policies & procedures

Client templates

Some compliance practices are owned by your organization rather than executed by the platform. GRC-ITSM ships starting-point templates for those domains -- see the Client Template Library.