Policy Review
What is Policy Review?
The periodic evaluation of existing policies to ensure they remain current, relevant, effective, and aligned with regulatory requirements.
Terms that appear alongside policy review
Each of these is named in at least one of the same controls as policy review. The number is how many controls name both.
- policy 12 shared controls
- information security 7 shared controls
- nist 2 shared controls
Frameworks that govern policy review
What the standards actually require on policy review
Requirements naming policy review across 6 standards, quoted from the control text.
Review every relevant organisational policy and its supporting procedures at least annually and whenever the organisation changes substantially.
CCM-GRC-03 · Organizational Policy Reviews →The institution must monitor the date each policy or procedure was last revised, the date it next falls due for review, and who is responsible for that review.
CPS220-P36 · Monitoring of Policy Review Dates and Ownership →Policy review and update procedures. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.
ISO27043-03 · Policy review and update procedures →Policy review and update procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.
ISO21434-03 · Policy review and update procedures →Review and codify organizational security policy as foundation for incident handling program
PICERL-P1 · Security Policy Review →Ensure service provider contracts include security requirements. Example requirements may include minimum security program requirements, security incident and/or data breach notification and response, data encryption requirements, and data disposal commitments...
CIS-15.4 · Ensure Service Provider Contracts Include Security Requirements →Questions people ask about policy review
What is Policy Review?
Why is Policy Review important for compliance?
Which compliance frameworks address Policy Review?
Where can I learn more about Policy Review?
See how Policy Review applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.