Skip to content

theopenlane/policy-hub

Openlane Policy Hub

This repository contains template organizational policies to help teams establish a strong foundation for compliance, governance, and risk management.

Each policy is written in Markdown and includes standardized frontmatter metadata so it can be easily imported, remixed, or adapted for your organization.

Instructions

For each policy section

  • Consider if this section and its corresponding risks apply to you. If it does not, remove it and/or replace it with your organization’s corresponding practices
  • Replace any text in braces e.g. {{company_name}} with the appropriate name, date, frequency
  • Update any language in angeled brackets with language specific to your organization; each policy should have something like: [^1]: All fields in this document marked by angled brackets < > and highlighted must be filled in.
  • Rewrite the policy language such that it reflects the practices of your organization

Policy completion checklist

  1. Use Find to make sure that all text in braces is replaced
  2. Proofread your policy for spelling and grammar mistakes
  3. Confirm that the policy’s content reflects your organizations practices
  4. Add any company-specific letterhead, branding, and formatting

More questions?

A good rule-of-thumb is to keep your language at a high enough level such that it stays representative for at least a year. If you have more questions about how to use this template, please reach out to support@theopenlane.io or your auditor for additional guidance.

File Structure

  1. All files should be in valid markdown
  2. Organization name placeholder {{company_name}} can be used, and when uploaded into Openlane, it will be replaced with the organization's name
  3. Frontmatter should include a minimum of title
  4. All policies should include:
    1. Purpose and Scope
    2. Background
    3. Policy Details

Tip

Use the template.md as a starting place to follow the same format as other policies

Contributing

We welcome contributions to improve or extend these examples

  1. Use valid YAML frontmatter
  2. Keep filenames in kebab-case (e.g. access-control-policy.md)
  3. Keep titles in Title Case
  4. Use neutral, vendor-agnostic language
  5. Submit pull requests with a short description of your changes
  6. Ensure the precommit hook is installed, which will ensure formatting of yaml files, as well as wrong a spellchecker

See the contributing guide for more information.

About

Example Policies and Procedures for use in Openlane or any compliance program; helpful for SOC2, ISO27001l and more

Topics

Resources

License

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors