Client Template Library¶
Not every compliance practice runs inside GRC-ITSM. Recovery planning, supply chain risk, workforce training, secure configuration guidance, and vulnerability disclosure are owned and executed by your organization. For those domains, GRC-ITSM delivers starting-point templates written in the same style as the platform policies and procedures: sample policy text you replace with your real practice, an Organization-Defined Values table, and the Key Security Indicator and FedRAMP rule statements each practice answers.
Templates require adoption
Each template is a starting point, not a finished policy. Fill the Organization-Defined Values, remove framework rows you are not pursuing, and formally adopt the document as your own before relying on it in an assessment.
-
Governance, Training & Secure Development
Security governance roles, role-based training, and secure development practices.
-
Backup, restoration testing, and recovery objectives for the systems you operate.
-
Baseline configuration standards and hardening guidance ownership.
-
Vendor and subservice evaluation, agreements, and ongoing supply chain risk management.
-
Vulnerability Disclosure Program
Receiving, triaging, and responding to vulnerability reports from external researchers.