Policy Register

Document control procedure

How every document in this register is drafted, approved, versioned, published, reviewed and withdrawn, and where the current copy lives.

How the register reads it

Also calledcontrol of documented information, policy on policies, policy framework
FamilyGovernance and the management system
Document typeProcedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it.
TemplateDocument control policy.

Which standards require it, and what each expects it to contain

5 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.

ISO/IEC 27001:2022

Named, not quoted: 7.5named Documented information.

ISO 27001 5.1 Policies for information security

Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.

What the ISO 27002 guidance expects the document to say: Requires an information security policy together with supporting topic specific policies. These must be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed on a planned cycle and whenever significant change occurs.

Evidence an auditor accepts: The approved information security policy, showing the approving authority and the date of approval; the set of topic specific policies beneath it, such as access control, cryptography, backup, acceptable use and supplier security, each with an owner; evidence of publication and of communication to personnel and to relevant interested parties, such as intranet publication records or distribution lists
Common gap: Policies not formally approved by senior management
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.37 Documented operating procedures

Document operating procedures for information processing facilities and make them available to those who need them.

What the ISO 27002 guidance expects the document to say: Requires the operating procedures used to run information processing facilities to be written down and made available to the personnel who need them.

Evidence an auditor accepts: The set of documented operating procedures for information processing facilities, covering routine operation, backup, monitoring, incident handling and restart; evidence procedures are available to the personnel who need them, including during an outage of the primary system that hosts them; version control and review records, showing procedures are current against the systems they describe
Common gap: outdated procedures still in use
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 7.5.3 Control of documented information

Documented information required by the PIMS and by this document shall be controlled to ensure that it is available and suitable for use where and when needed and that it is adequately protected, for example from loss of confidentiality, improper use or loss of integrity. The organization shall address distribution, access, retrieval and use; storage and preservation including preservation of legibility; control of changes including version control; and retention and disposition. Documented information of external origin that the organization determines necessary for planning and operating the PIMS shall be identified as appropriate and controlled. Retention of previous versions of privacy policies and procedures, which the annex guidance calls for, is part of this control.

Evidence an auditor accepts: Access, distribution and change controls on PIMS documentation; retention schedule for PIMS records and superseded document versions; control of external documents such as customer contracts and regulator guidance
Common gap: Superseded privacy notices and procedures discarded, so the organization cannot show what applied at a given date
Source: ISO/IEC 27701:2025

ISO 22301:2019

ISO 22301 7.5.3 Control of documented information

Control the documented information the BCMS and the standard require so it is available and suitable for use where and when needed and adequately protected, addressing distribution, access, retrieval and use, storage and preservation including legibility, change control, and retention and disposition; documented information of external origin that the BCMS depends on must also be identified and controlled.

Evidence an auditor accepts: Access and distribution controls with evidence of enforcement; storage and preservation arrangements including offline or alternate site availability; version control history and retention and disposition schedule
Common gap: Plans stored only on the corporate network, so they are unavailable in the scenario they exist for
Source: ISO 22301:2019

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Compliance policy · Information security policy