Creating from a Template
LowerPlane includes 15+ policy templates that cover the most common compliance requirements. Templates are the fastest way to create policies because they come pre-written, pre-mapped to framework controls, and include all required sections.Select a Template
Browse the template library and select the policy you want to create. Each template shows which frameworks it applies to and how many controls it maps to.
Customize the Content
The template opens in the editor with pre-written content. Customize the following:
- Organization name and specific details (placeholders are highlighted)
- Roles and responsibilities for your team structure
- Review frequency (annually, semi-annually, quarterly)
- Approval authority (who signs off on the policy)
- Framework-specific sections (additional paragraphs for HIPAA, GDPR, PCI-DSS if applicable)
Review Control Mappings
Template policies are automatically mapped to relevant controls. Review the Linked Controls section to verify the mappings are appropriate for your organization.
Available Templates
| Template | Frameworks | Controls Mapped |
|---|---|---|
| Information Security Policy | All | 12+ |
| Access Control Policy | All | 8+ |
| Data Protection & Privacy Policy | All | 10+ |
| Incident Response Policy | All | 6+ |
| Acceptable Use Policy | ISO, SOC 2, HIPAA | 5+ |
| Change Management Policy | ISO, SOC 2, PCI-DSS | 7+ |
| Business Continuity Policy | ISO, SOC 2 | 5+ |
| Vendor Management Policy | All | 6+ |
| Risk Management Policy | All | 5+ |
| Encryption Policy | All | 4+ |
| Physical Security Policy | ISO, HIPAA, PCI-DSS | 4+ |
| Human Resources Security Policy | ISO, SOC 2, HIPAA | 6+ |
| Network Security Policy | ISO, SOC 2, PCI-DSS | 5+ |
| Data Retention Policy | ISO, GDPR, HIPAA | 4+ |
| Password Policy | All | 3+ |
Using the Built-in Editor
For custom policies that do not fit a template, use the built-in rich text editor.Create a New Policy
Go to Policies and click Create Policy. Select Blank Policy instead of a template.
Set Policy Metadata
Enter the policy title, description, and select the applicable frameworks. Choose a policy category to help with organization.
Write Your Policy
The editor supports:
- Headings (H1 through H4) for document structure
- Bold, italic, and underline for emphasis
- Bullet and numbered lists for procedures and requirements
- Tables for structured information
- Links to reference external resources
- Code blocks for technical configurations
Link to Controls
Manually link your custom policy to relevant controls using the Linked Controls panel. This ensures the policy contributes to your compliance readiness score.
Uploading Documents
If you have existing policies in PDF or DOCX format, you can upload them directly to LowerPlane.Upload Your File
Drag and drop or browse to select your file. Supported formats are PDF and DOCX. Maximum file size is 25 MB.
Add Metadata
Enter the policy title, description, owner, and applicable frameworks. This metadata is used for searching, filtering, and control mapping.
Linking External Documents
For policies managed in external platforms, LowerPlane supports linking to documents hosted on Google Drive, Dropbox, OneDrive, or any accessible URL.Provide the URL
Paste the URL of your external document. LowerPlane validates that the URL is accessible.
Configure Access
Ensure the linked document is accessible to all team members who need to review or acknowledge it. LowerPlane does not manage permissions on external documents.
Linked documents are managed externally but tracked internally. LowerPlane handles the approval workflow, version tracking (via URL updates), and acknowledgment process for linked documents.
Policy Preview
Before submitting a policy for approval, use the Preview feature to see how it will appear to reviewers and employees:- Click Preview from the policy editor or detail view
- The preview shows the formatted policy as it will appear in the Employee Portal
- For uploaded documents, the preview renders the PDF or DOCX inline
- For linked documents, the preview opens the external URL in a new tab
Best Practices
Start with templates
Start with templates
Templates save significant time and come with pre-built control mappings. Even if you need to customize heavily, starting from a template gives you a solid structure and ensures you do not miss required sections.
Customize for your organization
Customize for your organization
Replace all placeholder text with your organization’s specific details. Generic policies with obvious placeholders left in place will raise questions during audits.
Keep policies concise
Keep policies concise
Policies should be clear and actionable. Avoid excessive legal jargon or unnecessarily long documents. Employees are more likely to read and follow concise policies.
Plan your policy set
Plan your policy set
Before creating individual policies, review the full list of templates and plan which policies you need. This prevents overlap between policies and ensures complete coverage of your compliance requirements.