Governance and the management system
The documents that say the management system exists: the top-level policy, who is responsible, how documents are controlled, how the system is audited and reviewed, and the register of the laws it answers to.
Policy types in this family
9- Compliance policy policy
How the organisation identifies its obligations, assigns them, checks them and reports breaches of them, across every regime it answers to. Required by none of the eight regimes quoted; owner legal or the compliance officer. - Document control procedure procedure
How every document in this register is drafted, approved, versioned, published, reviewed and withdrawn, and where the current copy lives. Required by ISO 27001, ISO 27701, ISO 22301; owner the information security lead (CISO or ISMS manager). - Information security policy policy
The top-level statement of intent and direction that every topic-specific document below it derives its authority from. Required by ISO 27001, ISO 27701, DORA, NIS2; owner top management (the board or the CEO), with the information security lead drafting. - Information security roles and responsibilities record
Who owns information security, privacy, continuity and AI decisions, with the authority each role carries and the committee that hears them. Required by ISO 27001, ISO 27701, ISO 42001, ISO 22301, DORA; owner the information security lead (CISO or ISMS manager). - Internal audit charter and programme plan
The mandate, independence, scope and schedule of the audits that test whether the documents in this register are followed. Required by ISO 27001, ISO 27701, ISO 22301; owner the head of internal audit, independent of the functions audited. - Legal and regulatory register record
The list of the laws, regulations and contractual terms the organisation answers to, with the owner of each and how compliance is shown. Required by ISO 27001, ISO 27701, ISO 22301; owner legal or the compliance officer. - Management review procedure procedure
How top management reviews the management system: the inputs it must see, the decisions it must record, and how often. Required by ISO 27001, ISO 27701, ISO 22301; owner the information security lead (CISO or ISMS manager). - Nonconformity and corrective action procedure procedure
How a failure to follow a document, an audit finding or an incident lesson becomes a recorded action with an owner and a closure. Required by ISO 27001, ISO 27701, ISO 22301; owner the information security lead (CISO or ISMS manager). - Risk management policy policy
How risks to information, systems, personal data and AI systems are identified, scored, treated and accepted, and by whom. Required by ISO 27001, ISO 27701, ISO 22301, DORA, NIS2; owner the information security lead (CISO or ISMS manager).
What reaches this family
| ISO 27001 | Expects: document control procedure, information security policy, information security roles and responsibilities, internal audit charter and programme, legal and regulatory register, management review procedure, nonconformity and corrective action procedure, risk management policy. Requires, by clause: ISO 27001 5.1, ISO 27001 5.37, ISO 27001 5.2, ISO 27001 5.31. |
|---|---|
| ISO 27701 | Expects: document control procedure, information security roles and responsibilities, internal audit charter and programme, management review procedure, nonconformity and corrective action procedure, risk management policy. Requires, by clause: ISO 27701 7.5.3, ISO 27701 5.2, ISO 27701 5.3, ISO 27701 9.2.2, ISO 27701 A.1.2.3, ISO 27701 9.3.2, ISO 27701 10.2, ISO 27701 6.1.2, ISO 27701 6.1.3. |
| ISO 42001 | Expects: information security roles and responsibilities. Requires, by clause: ISO 42001 A.3.2. |
| ISO 22301 | Expects: document control procedure, information security roles and responsibilities, internal audit charter and programme, legal and regulatory register, management review procedure, nonconformity and corrective action procedure. Requires, by clause: ISO 22301 7.5.3, ISO 22301 5.3, ISO 22301 9.2.2, ISO 22301 4.2.2, ISO 22301 9.3.2, ISO 22301 10.1, ISO 22301 8.2.3. |
| DORA | Expects: information security policy, information security roles and responsibilities, risk management policy. Requires, by clause: DORA Art. 5, DORA Art. 9, DORA Art. 6. |
| NIS2 | Expects: information security policy, risk management policy. Requires, by clause: NIS2 Art. 21(2)(a). |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register