Written for Administrators to look up the names
Policy
An internal document stating what the organisation commits to do. It has a lifecycle: draft, review, approval, publication, retirement.
Mandates many control objectives. Can have exceptions.
Fields
| Field | Type | Meaning | Example 1 | Example 2 |
|---|---|---|---|---|
number | autonumber | Unique identifier | POL-003 | POL-011 |
title | string | Policy name | Information Security Policy | Data Retention and Backup Policy |
owner | reference to auth_user | Accountable owner | Chief Information Security Officer | Head of IT Operations |
lifecycle_state | choice | Draft, in review, published or retired | Published | In review |
review_due | date | Next scheduled review | 2027-03-31 | 2026-11-30 |