Online security policy acceptance
Publish your security policy and record who read and accepted it, with name, date, UTC time and IP in an immutable log.
How the flow runs and what is recorded
The current policy enters as a document. New version, new acceptance. History is not rewritten.
From their portal, not from an email thread. They read. They accept. The gesture is tied to that version.
The record is immutable. There is no “soft delete” toggle of the acceptance. If the auditor asks for the trail, it is there.
The log of who changed a course or a permission lives in compliance and security. This is the roster accepting a PDF.
The policy is accepted and a record remains — not a PDF on a drive
Security-policy acceptance, here, is the flow in which the admin
It is not an email with “reply OK”. It is not a spreadsheet. It is the evidence the auditor asks for when they ask who read the current policy and when.
Training talks about courses and adoption
This is not a course. It is an acceptance act with a trail. Mixing it with the ISO quiz is the error: the quiz proves training happened; this record proves the published document was accepted.
The strong link is compliance
This is policy acceptance. Compliance is program evidence.
What it is for when the auditor asks for the trail
It is for ISO, for internal policies, for onboarding that cannot be “we
It is for when legal asks who accepted the March version, not the 2021 one. It is for a distributed roster with no paper signature.
It is not training
Publishing the policy does not replace the standard’s course. It is not a DPA. Account data processing lives in legal and the Trust Center.
How it connects to training and compliance
Adaptive security awareness training can coexist: the joiner takes the course and accepts the policy. Two gestures. The employee portal is the place; portal detail is a pillar anchor, not a new URL. Compliance exports program evidence. Here is the acceptance act. The course PDF certificate does not replace this record, or the other way around.
How this module is used
Questions about policy acceptance
What is recorded?
Can an acceptance be deleted?
Does it replace the standard’s course?
Where does the auditor see it?
Is there a product screenshot?
Publish the policy and leave the trail the auditor asks for
In the demo we look at the PDF, the portal and the record with UTC time and IP. No paper signature from the branch.