Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a policy

A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.

Before you begin

Role required: sn_compliance.admin or sn_compliance.manager

Users with Compliance user (sn_compliance.user) role can also create policies.

Procedure

  1. Navigate to All > Policy and Compliance > Policies and Procedures > Policies.

  2. Click New.

  3. On the form, fill in the fields.

FieldDescription
NameThe name of the policy.
TypeList of options: - Policy - Procedure - Standard - Plan - Checklist - Framework - Template
Owning GroupGroup that owns the policy.
OwnerUser that owns the policy.
Compliance Score PercentageThe compliance score percentage assigned to this policy.
ParentThe policy containing this policy. If you create a control objective from within a policy, this field is automatically filled.
Policy categoriesClick the lock icon and select one or more categories for filtering policies. For example, select Vulnerability Response to view policies associated with that application.
State

The state is a read-only field. Possible choices are: - Draft In this state, all compliance users can modify the policy and control objectives. All compliance users can click Request review button. Enter a message in the Request review pop-up and click Request, which sets the state to Review. - Review In this state, the owner, owning group, and reviewers can modify the policy and control objectives. The owner, owning group, and reviewers move the policy back to Draft, by clicking Back to draft, as well.

Reviewers cannot request approval for a policy. However, the owner of the policy with sn_compliance.user, which is the minimum required role, and users with compliance manager role can request approval for a policy.

  • Awaiting approval In this state, the policy and control objectives are read- only for all. Approvers can approve the policy by updating the approval state in the Approvals Related List on the policy form, or by viewing My Approvals. If the policy is approved, the policy goes to the Published state. Otherwise, it goes back to the Review state.
  • Published In this state, the policy and control objectives are read-only for all. Admins can click Retire which sets the state of the policy to Retired
  • Retired In this state, the policy is read-only for all.
Valid fromSpecifies the date and time when the policy becomes effective.
Valid to

Specifies the date and time until which the policy remains valid.Note:

By default, when a policy expires, it doesn't automatically trigger a new approval process. Instead, it remains in the Publishedstate until the specified number of days (configured in the Policy and Compliance > Administration > Properties page) have passed.

After this period, the policy transitions to either the Review state (if reviewers are assigned) or the Draft state (if no reviewers are assigned).

The field specifying the number of days is labeled: Number of days after reaching a policy 'Valid to' date in which the expired policy will automatically move from its Published state back to a Draft/Review state.

ApproversThe users you want to be included in the approval process.
ReviewersSelect the users you want to be included in the review process.
DescriptionA general description of the policy.
Policy textA detailed description of the policy.
Knowledge Base
Knowledge baseThe knowledge base article related to this policy.
KB articleThe KB article number and link where the policy is published.
Article templateThe article template to use for the publication of this policy.
Acknowledgement Setup
AudienceSelect the default audience responsible for acknowledging this policy.
Reference Material URLClick the lock icon to add the URL for any needed reference materials, such as certification or training materials.
Allow users to decline policySelect this check box to give users the option of declining policy acknowledgements.
Allow users to request exceptionSelect this check box to give users the option of requesting exceptions for policy acknowledgements.
Exception Setup
Maximum exception duration \(days\)Enter the maximum number of days for which a policy exception can be requested for a given policy.
  1. Continue with one of the following options.

    • To save and submit the policy, click Submit.
    • To mark the policy ready for review, click Request review.

What to do next

If you are implementing the Policy and Compliance Management software, return to the Policy and Compliance Management setup checklist and proceed to the next step.

Parent Topic:Policy and Compliance Management mandatory setup

Parent Topic:Manage control objectives and policies