[Developers]

Security Policies

Organisations pursuing multiple compliance certifications simultaneously often end up with separate policy programmes for each framework: separate control libraries, separate evidence sets, separate audit preparation…

Category: ManagementLast Updated:
managementreal-timecomplianceblockchaingeospatial

Overview#

Organisations pursuing multiple compliance certifications simultaneously often end up with separate policy programmes for each framework: separate control libraries, separate evidence sets, separate audit preparation cycles. The Security Policies module collapses that redundancy by mapping a single set of organisational policies across multiple frameworks simultaneously, so SOC 2, ISO 27001, and HIPAA share controls rather than duplicating them.

Continuous automated monitoring means that control failures surface as they happen, not weeks later when an auditor discovers the drift.

Key Features#

  • Policy Lifecycle Management: Create, version, approve, and distribute security policies through structured workflows. Template-based authoring with automatic mapping to compliance frameworks accelerates policy creation. Multi-stage approval chains, digital signatures, and change tracking ensure governance at every step.

  • Multi-Framework Compliance: Pre-configured control frameworks for SOC 2 Type II, ISO 27001:2022, HIPAA Security Rule, PCI-DSS v4.0, and GDPR, with support for custom frameworks. A unified control library maps organisational policies across multiple standards simultaneously, eliminating duplicate work.

  • Policy Attestation and Distribution: Automated policy distribution to applicable personnel based on roles and departments. Track employee acknowledgement with digital signatures, comprehension testing, and automatic re-attestation when policies are updated.

  • Security Control Enforcement: Implement and enforce technical security controls across identity and access management, data protection, network security, and application security. Automated monitoring detects policy deviations and triggers remediation workflows to prevent configuration drift from becoming a compliance finding.

  • Content Security Policy Governance: The platform's sign-in surface applies the same evidence-driven rollout discipline the module prescribes for organisational controls. A staged migration to a strict, nonce-based browser Content Security Policy is under way: a fresh cryptographic nonce is generated per request, every response carries a parallel report-only strict policy (with no inline-script or eval allowances) alongside the enforced one, and a dedicated violation-report collector records what stricter enforcement would block. The collector is fail-open, size-capped, and logs sanitised reports only, so observation carries zero blocking risk, and regression tests ensure retired third-party script origins cannot creep back into either policy.

  • Sign-In Abuse Protection: Per-IP rate limiting on login attempts blunts credential-stuffing and automated password-guessing campaigns against operator accounts, complementing account-level authentication policy.

  • Uniform Edge Service Hardening: The fleet of edge services behind the platform is hardened as a set. Every internal endpoint requires authentication, so anonymous callers cannot poison error-report ingestion or read cache statistics and internal interface details. Default development hostnames are disabled on production services so traffic cannot bypass edge security controls, and cross-origin policies in production are exact-match and HTTPS-only, never wildcard-with-credentials.

  • Automated Evidence Collection: Integrate with identity providers, cloud infrastructure, security tools, development platforms, and HR systems to gather compliance evidence automatically. Reduce manual evidence assembly while maintaining a complete, audit-ready evidence repository.

  • Compliance Monitoring and Dashboards: Real-time dashboards showing compliance status by framework, control implementation progress, risk heat maps, and evidence collection completeness. Continuous monitoring detects control failures before audit cycles reveal them.

  • Audit Preparation: Pre-audit checklists, organised evidence packages, and automated report generation. A secure auditor portal provides real-time evidence access with finding management and remediation tracking.

  • Risk Management: Continuous risk assessment with threat modelling, vulnerability evaluation, and control gap analysis. Risk scoring prioritises remediation based on business impact and threat likelihood.

Supported Frameworks#

  • SOC 2 Type II: Trust Services Criteria covering control environment, risk assessment, control activities, logical and physical access, system operations, and change management
  • ISO 27001:2022: Organisational, people, physical, and technological controls across 93 control areas
  • HIPAA Security Rule: Administrative, physical, and technical safeguards for protected health information
  • PCI-DSS v4.0: Requirements for secure networks, cardholder data protection, access control, monitoring, and security policy
  • GDPR: Lawful processing, data subject rights, security of processing, privacy by design, and breach notification
  • Custom Frameworks: Define organisation-specific compliance requirements with full control mapping

Use Cases#

  • Government departments managing national-security-adjacent frameworks alongside standard commercial certifications from a single policy library.
  • Intelligence organisations maintaining ISO 27001 with sector-specific overlays without maintaining separate control libraries for each.
  • Financial institutions running SOC 2, PCI-DSS, and GDPR programmes simultaneously with shared controls and a single evidence repository.
  • Healthcare providers satisfying HIPAA administrative, physical, and technical safeguard requirements with automated evidence collection from clinical systems.
  • Critical infrastructure operators managing CMMC, NIST CSF, and sector-specific regulations with automated monitoring rather than periodic point-in-time assessments.

Open Standards#

  • ISO/IEC 27001:2022: The module maps organisational policies directly to the 93 controls across all four ISO 27001:2022 themes (Organisational, People, Physical, Technological), enabling automated evidence collection and control-status reporting against the standard.
  • NIST SP 800-53 (Rev. 5): Control families including AC-2 Account Management, AU-2 Event Logging, IA-2 Identification and Authentication, and SC-8/SC-13 Transmission Confidentiality and Cryptographic Protection are monitored and assessed as first-class compliance targets.
  • GDPR (Regulation (EU) 2016/679): Articles 25 (Data Protection by Design), 32 (Security of Processing), and 33 (Breach Notification) are encoded as auditable controls, with automated breach-notification deadlines tracked against the 72-hour reporting obligation.
  • NIS2 Directive (EU) 2022/2555: Articles 20 (governance accountability), 21 (cybersecurity risk-management measures), and 23 (incident reporting obligations) are supported as a mapped framework with automated deadline tracking for critical-entity notifications.
  • FIPS 140-2 (Level 2): All cryptographic operations used to protect evidence, digital signatures on policy attestations, and audit-log integrity are constrained to FIPS 140-2 approved algorithms (AES-256-GCM, RSA-3072/4096, SHA-256/384/512).
  • PCI DSS v4.0: Payment security requirements covering network controls, cardholder-data protection, access control, logging, and security policy are available as a pre-configured control framework with automated monitoring and evidence collection.
  • SCIM 2.0 (RFC 7643 / RFC 7644): The System for Cross-domain Identity Management protocol is used to synchronise user and group provisioning from external identity providers, ensuring policy-attestation assignments and access controls remain consistent with authoritative HR and directory sources.

Getting Started#

  1. Select Frameworks: Choose the compliance frameworks that apply to your organisation and configure their control requirements.
  2. Define Policies: Create security policies using templates and map them to applicable framework controls.
  3. Configure Enforcement: Activate technical security controls and set enforcement modes (audit or enforce).
  4. Connect Evidence Sources: Integrate with identity providers, cloud platforms, and security tools for automated evidence collection.
  5. Launch Attestation: Distribute policies to applicable personnel and begin tracking acknowledgement and compliance status.

Last Reviewed: 2026-07-16 Last Updated: 2026-07-16

Ready to Integrate?

Access NATO STANAG gateway documentation or contact our defence integration team for support.