Policy Configuration Flashcards
What is the Policy record lifecycle?
Draft -> Review -> Awaiting approval -> Published -> Retired
When the policy record is in the review state, who can request approval?
the policy owner, members of the Owning group, sn_compliance.manager role, admin role
Which role is required to create policies?
sn_compliance.user
Who can move the policy into the Review state?
the policy owner, members of the Owning group, sn_compliance.manager role, admin role
What happens when a policy is approved?
Policy is published, KB article is created, associated control objectives are set to active
Who can retire a policy?
Policy owner or sn_compliance.manager
True or False: Control objectives have their own lifecycle
False
What happens when a Policy exceeds its valid to date and it has no reviewers?
Policy set to draft
What happens when a Policy exceeds its valid to date and it does have reviewers?
Policy set to Review
What is the default system property for when published policies revert to Review?
30 days after Valid To date