Document control procedure
How every document in this register is drafted, approved, versioned, published, reviewed and withdrawn, and where the current copy lives.
How the register reads it
| Also called | control of documented information, policy on policies, policy framework |
|---|---|
| Family | Governance and the management system |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it. |
| Template | Document control policy. |
Which standards require it, and what each expects it to contain
5 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.
ISO/IEC 27001:2022
Named, not quoted: 7.5named Documented information.
ISO 27001 5.1 Policies for information securityWrite, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
What the ISO 27002 guidance expects the document to say: Requires an information security policy together with supporting topic specific policies. These must be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed on a planned cycle and whenever significant change occurs.
Common gap: Policies not formally approved by senior management
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.37 Documented operating proceduresDocument operating procedures for information processing facilities and make them available to those who need them.
What the ISO 27002 guidance expects the document to say: Requires the operating procedures used to run information processing facilities to be written down and made available to the personnel who need them.
Common gap: outdated procedures still in use
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 7.5.3 Control of documented informationDocumented information required by the PIMS and by this document shall be controlled to ensure that it is available and suitable for use where and when needed and that it is adequately protected, for example from loss of confidentiality, improper use or loss of integrity. The organization shall address distribution, access, retrieval and use; storage and preservation including preservation of legibility; control of changes including version control; and retention and disposition. Documented information of external origin that the organization determines necessary for planning and operating the PIMS shall be identified as appropriate and controlled. Retention of previous versions of privacy policies and procedures, which the annex guidance calls for, is part of this control.
Common gap: Superseded privacy notices and procedures discarded, so the organization cannot show what applied at a given date
Source: ISO/IEC 27701:2025
ISO 22301:2019
ISO 22301 7.5.3 Control of documented informationControl the documented information the BCMS and the standard require so it is available and suitable for use where and when needed and adequately protected, addressing distribution, access, retrieval and use, storage and preservation including legibility, change control, and retention and disposition; documented information of external origin that the BCMS depends on must also be identified and controlled.
Common gap: Plans stored only on the corporate network, so they are unavailable in the scenario they exist for
Source: ISO 22301:2019
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register