Agent Registry·Documentation·Policy Drafter
Documentationclaude-sonnet-4-6Open source · Free to copy

Policy Drafter

Writes complete IS policies from a single prompt. AUP, IR Plan, Access Control, and more.

Generates complete information security policies tailored to your organization size, industry, and target frameworks. Output includes purpose, scope, definitions, policy statements, exceptions process, and review schedule. Ready for leadership sign-off.

Tools:readwrite
Frameworks:ISO 27001SOC 2CMMCHIPAANIST CSF
Use case 1
Standing up a new compliance program and you need 15 to 20 policies from scratch
Complete policy library calibrated to your size and target frameworks, in days not months, with control IDs mapped to each statement
Use case 2
Existing policies are dated and an audit found gaps in coverage
Refreshed policies with current control mappings, modern provisions (AI tool use, BYOD, remote work, ransomware), and traceable revision history
Use case 3
M&A integration and you need to harmonize two policy stacks before the next audit cycle
Side-by-side comparison and a harmonized policy set that satisfies both parents' frameworks without duplication

Try a sample prompt:

policy-drafter · live demo · gemini-flash
◇ Curated sample output (real format)

Acceptable Use Policy

Document ID: ACME-POL-AUP-001 · Version: 1.0 · Effective Date: 2026-05-09

Approver: Chief Information Security Officer · Next Review: 2027-05-09

1. Purpose

This policy establishes the rules under which Acme employees, contractors, and authorized third parties may use Acme information systems, networks, and data. It supports Acme's commitments under SOC 2 Type II (CC1.1, CC1.4, CC6.1, CC6.6) and ISO/IEC 27001:2022 (A.5.10, A.6.3, A.8.1).

2. Scope

This policy applies to all personnel with access to Acme systems including full-time employees, part-time staff, contractors, interns, and third-party service providers. It covers all owned, leased, or BYOD endpoints; all SaaS platforms in the corporate identity provider; and all data classified Internal, Confidential, or Restricted per the Data Classification Policy (ACME-POL-DCL-001).

3. Definitions

1. Information System: Any computing resource owned, operated, or contracted by Acme.
2. BYOD Device: A personally owned device used to access Acme resources, registered in MDM per §6.
3. Restricted Data: Customer PII, payment card data, source code, financial reports, and HR records.

4. Policy Statements

4.1 Authorized Use

1. Personnel shall use Acme information systems only for legitimate business purposes. [SOC 2 CC6.1] [ISO 27001 A.5.10]
2. Personal use of corporate systems is permitted on a limited and incidental basis provided it does not interfere with job duties, consume excessive resources, or violate any provision of this policy.
3. Personnel shall not use Acme systems for any unlawful, harassing, defamatory, or fraudulent activity.

4.2 Authentication and Credentials

1. Personnel shall authenticate using their assigned Okta identity for all Acme resources. [SOC 2 CC6.1] [ISO 27001 A.8.5]
2. Multi-factor authentication is required for all Acme resources. Personnel shall not share, write down, or transmit credentials via unencrypted channels.
3. Personnel shall immediately report suspected credential compromise to security@acme.com.

4.3 Data Handling

1. Restricted data shall be stored only in approved repositories listed in the Data Inventory (Confluence: IT/Data-Inventory). [SOC 2 CC6.7] [ISO 27001 A.8.3]
2. Personnel shall not download Restricted data to personal devices, personal cloud accounts, or removable media.
3. Generative AI tools (ChatGPT, Claude, Gemini, etc.) shall not receive Restricted or Confidential data as input unless using the approved enterprise instance documented in the AI Tool Usage Standard (ACME-STD-AI-001).

4.4 Endpoint Security

1. Acme-owned and BYOD endpoints shall be enrolled in Acme's MDM (Microsoft Intune) and run the corporate EDR agent. [SOC 2 CC6.6] [ISO 27001 A.8.7]
2. Personnel shall not disable security software, alter security configurations, or attempt to circumvent endpoint controls.
3. Lost or stolen devices shall be reported to IT within 4 hours of discovery.

4.5 Network Use

1. Personnel shall not connect Acme systems to untrusted Wi-Fi without active VPN.
2. Personnel shall not run unauthorized scanning tools, penetration testing utilities, or traffic capture tools.

4.6 Email and Communications

1. Personnel shall not auto-forward Acme email to non-Acme addresses.
2. Acme retains the right to inspect any communication transmitted over corporate systems consistent with the Workplace Monitoring Notice.

5. Roles and Responsibilities

RoleResponsibility
PersonnelComply with this policy; report violations
ManagerReinforce policy in onboarding and reviews
ITEnforce technical controls; remediate violations
SecurityInvestigate incidents; recommend policy updates
CISOApprove policy revisions; final escalation

6. Exceptions

Exceptions require written approval from the CISO and shall be documented in the Exception Register (Confluence: Security/Exceptions). Exceptions are valid for a maximum of 12 months and require renewal review.

7. Enforcement

Violations may result in disciplinary action up to and including termination of employment or contract, in accordance with the Employee Handbook §8 and applicable contractor agreements. Suspected criminal activity will be referred to law enforcement.

8. Review and Maintenance

This policy is reviewed annually by the Information Security team and updated as needed. Material changes require CISO approval and re-acknowledgment by all personnel.

9. Related Documents

- ACME-POL-IAM-001 Identity and Access Management Policy

- ACME-POL-DCL-001 Data Classification Policy

- ACME-STD-AI-001 AI Tool Usage Standard

- Employee Handbook §8

10. Document Control

VersionDateAuthorDescription
1.02026-05-09CISOInitial release
Cmd+Enter to send