Finance
Purchasing Approval Matrix
20 approved policy statements are activated from this source.
DOC-FIN-0003 · SRC-5636F94E1DA4FF8CE9D9C95FD0CDPROOF SPACE
See how SALARA turns a policy document into activated Organizational Intelligence, then ask a question and Replay the evidence behind the answer.
Policy document experiences
Each available document is backed by activated Organizational Intelligence.
Finance
20 approved policy statements are activated from this source.
DOC-FIN-0003 · SRC-5636F94E1DA4FF8CE9D9C95FD0CDHuman Resources
54 approved policy statements are activated from this source.
DOC-HR-0005 · SRC-1DE734B79FD1BA337ED2D3E066EEInformation Security
19 approved policy statements are activated from this source.
DOC-IT-0003 · SRC-594156BCE10E5BB8CEFC271A91E2Information Security
20 approved policy statements are activated from this source.
DOC-SEC-0004 · SRC-565D08896030A88C111A7224DF98Information Security
31 approved policy statements are activated from this source.
DOC-SEC-0005 · SRC-6E538DE827A73F0439799AD79070IT Operations
58 approved policy statements are activated from this source.
DOC-OPS-0003 · SRC-5991452A065397B573265DC07B98Document content
These approved statements are the content Runtime can use. Answers stay inside this activated boundary.
Information Security · Activated document
- Export-controlled technical data requires an export determination before storage.
ASSERT-1A70DB26514B0B175AA05D4834D2FD99 · v1- This standard is reviewed each January by the CISO.
ASSERT-21C9995A563AADC0D342E9F2FE009158 · v1- An unmarked deliverable may not leave a Compass One system boundary.
ASSERT-2536D8D31E98EE88E3F2DEC27D1FCA94 · v1- Compass One prohibits storage of export-controlled technical data in shared drives.
ASSERT-2D24D8B1AE3BCFB72EB3ED97CB95CB15 · v1- A covered defense information incident requires Government reporting within seventy two hours.
ASSERT-3DDA2EB9C68AC6078C955D285523C908 · v1- External sharing of commercial information requires data owner approval.
ASSERT-4987E2F685AC43EE41526B8684E32201 · v1- A non-disclosure agreement must exist before any external sharing of proprietary information.
ASSERT-4B26B58164B62B941E1C5F6069778511 · v1- Every information asset must carry one of seven Compass One information classes.
ASSERT-55A9BF474619AE2D17883694EB7C87DA · v1- Every report must follow the incident reporting procedure in DOC-SEC-0002.
ASSERT-5937B802C55DC77ECAC6EE0A993DE66F · v1- Transmission of controlled unclassified information requires an approved encrypted channel.
ASSERT-6BEC15C8852C4BC3C1F87B68AA544F09 · v1- A contract instruction overrides this standard whenever the contract is stricter.
ASSERT-6CE521344337D502879C400804256FF0 · v1- Compass One prohibits storage of controlled unclassified information in chat platforms.
ASSERT-6E1462E38F79B981C06809060C59CFE0 · v1- The marking must cite the contract clause that imposes the control.
ASSERT-7019A23F71B73794B33B7DA2B82588F9 · v1- Controlled unclassified information must reside in an approved enclave.
ASSERT-7403477E8FAD5D7625A341CF69AB1757 · v1- Marking is applied by the document author at creation.
ASSERT-7A90AFB21D8324252AC793FF6ECFE66F · v1- A suspected disclosure of controlled unclassified information must be reported within one hour.
ASSERT-93A7EF042F3C8D5635CA1C125F50A951 · v1- Covered defense information must reside in a program approved enclave.
ASSERT-A27DDFD546E9140D6A873CA4DA501A28 · v1- The owning department owns the classification of internal proprietary information.
ASSERT-A299A30431865F94C956C3A552BD27CF · v1- Compass One retains federal contract information for the full contract retention period.
ASSERT-AA788408CB56930E02F2AED849CDF989 · v1- Physical media holding controlled unclassified information must be shredded by approved means.
ASSERT-AD4A415D1D0B9F0573BE4FE38E03246D · v1- A named access list is required for every controlled unclassified information repository.
ASSERT-B7A97286B4BF74F38E41838E4AF82E64 · v1- Unmarked information is treated as internal proprietary information by default.
ASSERT-B8F2F436774AD1B977DB070A96ED8882 · v1- The Compliance function owns the classification of controlled unclassified information.
ASSERT-BEC9C5C6AFC7A04B7A66A3950B112AB8 · v1- Personal email accounts are prohibited for every Compass One information asset.
ASSERT-BFF725D5D3703AECCB1B695C7BE68A26 · v1- Access to program-scoped information is granted by program boundary rather than job title.
ASSERT-C79E206B7D054CC8D526AA5B7F82B7E8 · v1- Disposal of controlled unclassified information requires a recorded certificate of destruction.
ASSERT-C7A297E8C35745985004E4A67006685B · v1- Internal proprietary information may reside in the standard document repository.
ASSERT-CE0EC19389DDB7BFF9EBC58DBB53FBAD · v1- Every document containing controlled unclassified information must carry a visible marking.
ASSERT-DAD7FDAF220DE0F3C861CB629A2FE3B2 · v1- The CISO owns this standard.
ASSERT-DEBF8C8BB3C9A8D2F04A671F75A7C59C · v1- Contract-delivered federal material is treated as federal contract information by default.
ASSERT-F47534367768226E75D8B49CEE47BA98 · v1- This standard applies to all employees, contractors, and temporary workers.
ASSERT-FBEDAAA9129B76A4D86EC0D907FC4CBB · v1From the activated intelligence
These examples are derived deterministically from approved Assertions in the active compiled artifact.
What does the policy say about - Export-controlled technical data requires an export determination before storage?
Ask this questionWhat does the policy say about - This standard is reviewed each January by the CISO?
Ask this questionWhat does the policy say about - An unmarked deliverable may not leave a Compass One system boundary?
Ask this questionWhat does the policy say about - Compass One prohibits storage of export-controlled technical data in shared drives?
Ask this questionWhat does the policy say about - A covered defense information incident requires Government reporting within seventy two hours?
Ask this questionWhat does the policy say about - External sharing of commercial information requires data owner approval?
Ask this questionOne discipline, four ways to explore