Policy as a Service

What if you could monitor compliance with your policies in real time?

What if every security incident — no matter how trivial — were checked against your written stances on shadow IT, software installation, removable media, and more? Adversarial makes policy come to life: centralized best-practice policy, enriched for your organization, and adjudicated in real time as risks and incidents are processed.

Adjudicate in real time

Every incident, checked against what you actually wrote down.

Review every security incident — no matter how trivial — to see whether people really are complying with your written stances on shadow IT, software installation, removable media, and so much more. Not once a year at audit time. Continuously, in the same pass that scores your risks and grades your incidents.

Because your policy lives in the same platform that reads every risk and incident, compliance stops being a once-a-year survey and becomes a standing observation.

Your written stances
  • Shadow IT and unsanctioned tools
  • Software installation
  • Removable media and USB drives
  • BYOD and personal devices
  • Wifi, network, and remote access
  • Identity and access management
  • AI acceptable use
One body of policy, adjudicated in real time.
What you'll find

We already know the answer.

Not unlike risk management and incident-response adjudication, the moment your policy has to run against reality you start finding things. Two kinds of things — and the second is the one most programs never get to.

Holes in the policy
Aspirational bits nobody's aware of. Conflicts that are impossible to comply with. That enigmatic paragraph legal rushed through in a kneejerk reaction to a Ted Talk four years ago.
Opportunity
Simple behavioral measures you can draft and educate on that meaningfully move your incident activity — the changes you couldn't see until policy met the data.

The same engine that adjudicates your risks and incidents, pointed at the rules you set for people.

Policy as a Service

Adversarial makes policy come to life.

Our structured policy engine enjoys the benefits of Policy as a Service: centralized, best-practice policies — enriched with customized options and suggestions based on your threat profile.

Why should every organization on the planet rewrite a BYOD policy from scratch? Adversarial knows what works, what doesn't, and the organizational characteristics that make one option the right fit over another.

Organizational supplements

Use it out of the box — then make it yours.

Many organizations can adopt our suggestions and wording as-is. But we know you'll always need the ability to inject organization-specific language.

Organizational supplements let you tweak any area of policy — including the components that feed real-time AI adjudication — without giving up the benefit of centrally maintained best practice.

How it comes together

Best practice in. Your language on top. Real-time out.

01 · START
Industry-standard statements
Begin with the best industry-standard policy statements, drawn from decades of hands-on programs — not a blank page.
02 · INHERIT
Updates from us
Inherit revisions when major technology or regulatory changes demand them — surfaced, explained, and versioned, never silent.
03 · CUSTOMIZE
Your supplements, live
Finish with your organization-specific customizations, and deliver it all in real time as risks and incidents are processed.
Governed intelligently

Every change, summarized for governance — with the trend line attached.

It's all governed intelligently, with AI summaries of policy changes you can take straight into governance for approval.

Including actual and previewed trends on how your workforce compliance will look — and where to prioritize education and awareness.

Inside the CISP: Network Security Policy

One of fifteen sections, shown in full. Real approved policy language — not a template with your name dropped into the header — generated for your threat profile and kept current as it moves.

CISP Policies 15 sections

11 Network Security Policy

Network devices must be configured and deployed in accordance with platform-specific security build requirements to be maintained by deployment teams and reviewed by the security team at least annually. Deployment procedures must use automated processes to ensure consistency and compliance with requirements when more than 5 systems of a given platform are to be deployed.

System Accounts. Built-in or other local accounts should be eliminated where possible. All default passwords must be changed to 48-character randomized strings stored in an approved centralized password vault with restricted access. Where configurable platforms should use the strongest cryptographic hashing function available for local passwords.

User Provisioning. Systems should use an approved centralized company authentication protocol and service such as TACACS or RADIUS in lieu of local accounts for all users, administrative and otherwise. Approval and provision processes must be documented in approved procedures.

MFA. Elevated credentials including privileged accounts as well as “become” or “sudo” passwords must require a one-time password.

Network Registration. Public network registration with Internet providers or whois registries should use aliased department-leven contact information affiliated with $company. Dedicated specific SMTP addresses should be used that can have membership later modified internally to the company to reflect changing individual responsibilities. Contacts should always distribute incoming messages to at least two active personnel. Where available, the ability to share contacts for abuse reporting should be utilized with a dedicated but generic alias that delivers to the security group in addition to responsible network individuals.

Reverse DNS. Reverse DNS entries for company-owned Internet space shall have generic number-related entries in company-owned domains by default, but should not expose system or service-level information unless it is required by specific services such as mail transfer agents.

WiFi

Internet-Only. Wireless networks must be provisioned with only Internet access. Internal wireless networks with direct routing and access to internal networks are prohibited.

VPN Required. Connections to an on-site or otherwise company-managed wireless network should not grant any additional privileges over a public network, and both should require additional authentication and protection via a VPN or equivalent service before corporate resources can be accessed.

No Public Usage. Wireless networks should have mechanisms deployed to restrict usage to authorized personnel to mitigate the threat of company networks being used to access illegal material, attack other Internet resources, or otherwise represent company networks across the Internet without authority.

Access Credentials. A random but pronounceable SSID-level password shared across all company wireless networks may be used provided it is rotated at least monthly. This password may be shared on internal-only communication systems or via placards displayed in company facilities but not in public-facing resources. Unique individual logins are not required at the SSID level or via a captive portal.

Guest and Visitor Access. Wireless access may be provisioned to guests and visitors.

The whole thing is Adversarial.

Policy as a Service lives inside Compliance — but underneath it is one deterministic system of record covering threats, risks, incidents, and compliance.