Zum Hauptinhalt springen

Structure and release the content of a rule set

Rule sets such as your information security policy are maintained in the “Contents” tab: General, Association and Text content with a selectable section numbering. This guide shows how the content is structured, how you edit it in the slide-over and which actions are available up to the release.

Last updated:

In a rule set — for example your information security policy — you document internal specifications centrally and with version control. This guide shows how the content of a rule set is structured, how you edit it in the structured editor and how you release it from the action bar. In ISMS audits based on ISO 27001 or BSI IT-Grundschutz, the released and versioned rule set serves as evidence of appropriate organization.

Prerequisites

  • You are logged into a team that uses the “Rule sets” module.
  • You have permission to view rule sets. To edit, release or delete them, you additionally need the respective permission.
  • You have opened a rule set from the left-hand menu via “Collateral securities → Rule sets” and are in its “Contents” tab.

Contents of a rule set

The “Contents” tab divides the rule set into three sections:

  • “General”“Designation”, “Status”, “Document ID”, “Created on” and “Description”.
  • “Association” — the “Organisations” to which the rule set is assigned.
  • “Text content” — under “Display” the “Section numbering” with the default value Standard (I. 1. a.), and under “Sections” the “Contents” field with the actual body text. If no sections have been entered yet, the note “No section available.” appears.

Edit the rule set

  1. In the “Contents” tab, click “Edit”. A slide-over opens with the rule set form.
  2. Maintain the fields under “General” (“Designation”, “Status”, “Document ID”, “Description”), the “Organisations” under “Association”, and in particular the “Text content” with the text of the rule set.
  3. If you want the rule set to be accessible outside your team, use the “Link (current revision)” option in the “Publication” section to provide a public link to the current revision.
  4. In the “Text content” section under “Display”, select a different “Section numbering” if required (“No numbering” or “Standard (I. 1. a.)”) if the specified scheme does not match your internal standard. Use the “New” button under “Edit text content” to add individual sections.
  5. Click “Save”. The arrow icon next to it also provides “Save and close” and “Save and create new”. Use “Cancel” to discard the changes.

When you save, a new revision is created, the process is logged in the activity history, and observers as well as assigned editors receive a notification. Earlier versions are available in the “Revisions” tab.

Execute actions

The “Actions” button at the top right of the “Contents” tab offers further actions: “Edit”, “Change affiliation”, “Delete”, “Watch”, “Release”, “Download as PDF”, “Download as DOCX”, “Duplicate” and “Create linked document”. Which actions are offered depends on status and permissions.

  • “Release” puts the reviewed version into force — the basis for everyone working from the same state.
  • “Preview” opens a read-only preview of the rule set before you release it.
  • “Download as PDF” and “Download as DOCX” provide an export for audits or external coordination.

Practical tip: Structure extensive rule sets consistently using section numbering. Consistent numbering makes it possible to refer to individual points in “Tasks”, “Comments” and “Training courses” (for example “see section II.3.b of the IT security policy”) — without this stability, cross-references would become unusable after every change.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.