Each policy goes through several stages in its compliance lifecycle. Each status reflects a specific stage of development, review, and deployment. Here's an explanation of each policy status in Scrut:
Not Uploaded: The "Not Uploaded" status indicates that the assignee has not yet added the policy. It might be in the process of being created, or it could be a policy intended for future use that has not been added to Scrut.
Draft: The "Draft" status indicates that the policy has been created or is in the process of development. It is still under review and has not been finalized for publication or implementation.
Approved: The "Approved" status indicates that the policy has undergone internal review and has been approved by designated approvers within your organization. However, the policy is still in a draft stage and has not been officially published for broader distribution. Hence, the associated controls are still non-compliant. This status is applicable only if the policy approval workflow is enabled.
Needs Review: The "Needs Review" status indicates that the policy needs to be reviewed and reuploaded to ensure regular compliance with evolving organization rules and policies. Policies move from the Published to the Needs Review status based on the configured recurrence cycle.
Published: The "Published" status indicates that the policy has been finalized, reviewed, and approved, and it is now ready for distribution and implementation across the organization. Policies in the "Published" status are considered official and applicable to relevant stakeholders. They are available for employees, contractors, and other relevant parties to access, read, understand, and adhere to in their activities.