workflow

Policy Lifecycle Management

Run one policy through its full lifecycle, anchored to a Policy item in the policy library — created at authoring for a net-new policy, enriched in place on each refresh cycle (never duplicated). In scope: authoring and control/authority linkage, stakeholder review, formal approval, publication and workforce attestation, acknowledgement tracking, disposition, and scheduled alignment refresh. Consumes read-only upstream: the enterprise risk assessment (Risk items), control design (Control items), and obligation mapping — this workflow neither produces nor edits them. Produces four named deliverables: the published policy version, a frozen workforce attestation completion record, a section-by-section alignment verdict, and a single approval-ready policy package. Out of scope: enterprise risk assessment, control design, and obligation mapping. The approved policy package is handed off to the Regulatory Compliance Attestation Cycle, which runs the recurring regulatory attestation; the acknowledgement campaign launched here is the one-time publication attestation and is explicitly flagged in the handoff as not-to-be-repeated downstream.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
compliance-legal
lineOfDefense
monitor

Details

teams
  • compliance-legal
  • executive
domains
  • grc
standards
  • iso-27001
  • cobit-2019
sourceTemplateId
workflow-library:grc-policy-lifecycle-management
releaseId
sha256:07f7c6423331d5325e268383c0375b4be4b9e74de04d1df3c1d3bb5ecf4dbbaa
canonicalUrl
https://workflow-library.com/all/?w=grc-policy-lifecycle-management
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-GOV-14
    • UC-TRAIN-04
    • UC-CONFIG-09
    • UC-GOV-29
    • UC-GOV-30
    • UC-GOV-31
    • UC-GOV-32
    • UC-GOV-34
    • UC-GOV-35
    • UC-GOV-36
    • UC-HR-07
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:07f7c6423331d5325e268383c0375b4be4b9e74de04d1df3c1d3bb5ecf4dbbaa

            Connections