Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Mandatory ISMS Documentation Checklist

Lists every document and record the standard requires, with the common substitutions auditors accept and the gaps they reliably find.

Available soon

Format
Excel
Size
74 KB
Length
10 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Required Documents
  • Annex A Documents
  • Summary & Sign-off
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Scope: check against your approved ISMS scope (clause 4.3). Every row on the Required Documents sheet applies to every organisation. On the Annex A Documents sheet, answer N/A for a control your Statement of Applicability excludes, and give the reason in the notes.
2For each row, enter your document or record in 'Your document or record' (reference and title, or where the records are kept). Where one document covers several items, name it in each.
3Answer the four checks from the drop-down lists: Yes, Partly, No, or N/A where the check does not apply (a record is not approved like a policy; a document not yet in use cannot show evidence of use). 'Pass when' says what an auditor needs to see.
4Read the Result and 'What is missing'. For every Fail or Missing, name an owner and a target date, and copy the item into the ISMS Gap & Remediation Tracker.
5Record the evidence you looked at in the last column (for example 'register entry, approval minutes 2026-05-11'), so the next check, and the Stage 1 auditor, can follow it.
6Summary & Sign-off: read the counts, then have the person who carried out the check and the ISMS manager sign off with the date. Repeat the check before Stage 1 and before Stage 2.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The four checks (IS-04: "Every required document and record (MANDATORY) must exist, be approved and be kept under document control."):

Exists? — Yes: it exists and covers the whole item. Partly: it exists in draft or covers part. No: nothing exists (the result is Missing).

Approved? — Yes: approved by the person or body it names as approver. Partly: some parts or some documents are approved. No: a draft. N/A: a record, which is kept rather than approved.

Under document control? — Yes: identified, versioned, stored where the right people can find it, with access, retention and a review date that has not passed (clause 7.5.3). Partly: some of that, or past its review date. No: none.

Evidence of use? — Yes: the auditor could sample it being followed or produced over at least [[3]] months. Partly: in use for less than that. No: not yet in use.

Result — Pass: exists, and every other check is Yes or N/A. Fail: exists, but at least one check is Partly or No. Missing: does not exist. N/A: the control is excluded in your Statement of Applicability (give the reason). Not answered: the Exists check is blank.

The EXAMPLE rows are a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30, about six months into its ISMS project. Its policies are the Security Policy Management (P04) example register; its other ISMS documents are ISMS-01 to ISMS-08. Document control shows Partly where a document is approved but past its review date (AUP-001, BKP-001), and No where it has never been approved (the Supplier Security Policy, P04 register SUP-001): a document awaiting approval is not yet under control. Owners and target dates come from the same readiness position as the Certification Readiness Self-Assessment. To clear the example, delete the contents of the 'Row' column and every yellow column; the item text stays.

Tailoring — small organisation: one short ISMS manual can hold the scope, roles, the risk method and the objectives; name it against each item. What matters is that each item is there, approved and used, not that it is a separate document.

Tailoring — regulated entity: ISO/IEC 27001:2022 certification is evidence for a supervisor, not compliance with NIS2 or DORA in itself. Keep the register of legal requirements (Annex A 5.31) complete, since supervisors and auditors both start there; the regulator may expect documents this checklist does not list.

Tailoring — IT run by a service provider: documents the provider keeps count only if you can see them and they are covered by your document control, or by the contract. Name the provider's document and where you hold your copy; ask for its records for the period the auditor will sample.

Required Documents

The 16 items of documented information the standard requires, by clause (number and title only; read the standard for the requirement). Yellow columns are yours.

RowItem IDClauseClause titleDocumented information (in our words)Document or recordTypical formSubstitutions auditors commonly acceptGaps auditors reliably findPass whenCISO Times template that helpsYour document or recordExists?Approved?Under document control?Evidence of use?ResultWhat is missingOwnerTarget dateEvidence reference and notesAction order (working)
EXAMPLEMD-014.3Determining the scope of the information security management systemScope of the ISMSDocumentA scope statement of one or two pages, often a section of an ISMS manual, with a diagram of locations and interfaces.A scope section inside the ISMS manual or the policy, if it is approved and says everything a scope statement must.Interfaces and dependencies on other organisations missing; exclusions with no reason; cloud services not mentioned; the scope on the certification application differs from the approved one.Names the organisation, locations, services, interfaces and exclusions with reasons (IS-02); approved by top management (IS-01).ISO 27001 Implementation Methodology & Project Plan (this pack)ISMS-01 ISMS Scope Statement (Approved 2026-05-11)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEMD-025.2PolicyInformation security policyDocumentA short top-level policy signed by top management, with topic-specific policies beneath it.A combined policy with an information security section, if it contains the commitments the standard asks for and is communicated.No objectives or framework for setting them; no commitment to continual improvement; signed by someone other than top management; not available to the people it applies to; review date passed.Approved by top management, communicated and acknowledged, and within its review date.P04-A04 Security Policy Document Template; P04-A02 Policy Framework StandardInformation Security Policy (P04 register ISP-001) v3.0 (Approved, review 2027-03-12)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEMD-036.1.2Information security risk assessmentRisk assessment processDocumentA risk methodology: the criteria for accepting risk and for performing assessments, how risks are identified, analysed and evaluated, and who owns them.A group-wide enterprise risk method, if it covers information security risk and states the acceptance criteria.Acceptance criteria missing or not measurable; a method that gives different results when repeated; risk owners not named.Sets acceptance criteria and a method that gives consistent, comparable results; approved.P05-A02 Risk Assessment Methodology & Scoring Model; P05-A03 Risk Identification & Assessment Operating ProcedureISMS-02 Risk Management Methodology (Approved 2026-06-15)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEMD-046.1.3Information security risk treatmentRisk treatment processDocumentUsually part of the same methodology: treatment options, how controls are chosen and compared with Annex A, who approves the plan and accepts residual risk.The same document as the risk assessment process.No record that chosen controls were compared with Annex A; residual risk not accepted by the risk owners.Describes how treatment is chosen, compared with Annex A and approved; risk owners accept residual risk.P05-A02 Risk Assessment Methodology & Scoring Model; P05-A07 Risk Treatment PlanISMS-02 Risk Management Methodology (Approved 2026-06-15)YesYesYesPartlyFailIn use for less than 3 months.Head of Information Security24 Nov 2026EXAMPLE — In place in the readiness assessment.2007
EXAMPLEMD-056.1.3Information security risk treatmentStatement of ApplicabilityDocumentA table of all 93 Annex A controls: applicable or not, why, and implemented or not, each linked to a risk or requirement.An export from a tool, if it holds every control, the justification and the implementation status, and is under version control.Exclusions justified only with 'not relevant'; implementation status out of date; controls included with no link to a risk (IS-03); a different version from the one sent to the certification body.Every control listed with applicability, justification and status; approved; status current.Statement of Applicability Template (this pack)ISMS-03 Statement of Applicability (Approved 2026-08-24)YesYesYesPartlyFailIn use for less than 3 months.Head of Information Security24 Nov 2026EXAMPLE — In place in the readiness assessment.2008
EXAMPLEMD-066.1.3Information security risk treatmentRisk treatment planDocumentA list of treatment actions: the risk, the action, owner, due date and the residual risk, with the risk owners' approval.A section of the risk register, or the gap tracker, if each action links to a risk and the approval is recorded.Actions without owners or dates; no record that risk owners approved the plan; the plan not updated as actions close.Every treatment action owned and dated; approved by the risk owners; kept up to date.ISMS Gap & Remediation Tracker (this pack); P05-A07 Risk Treatment PlanISMS-04 Risk Treatment Plan (Approved 2026-08-24)YesYesYesPartlyFailIn use for less than 3 months.Head of Information Security24 Nov 2026EXAMPLE — In place in the readiness assessment.2009
EXAMPLEMD-076.2Information security objectives and planning to achieve themInformation security objectivesDocumentFive to ten objectives, each with a measure, a target, an owner, the resources, a date and how results will be evaluated.Objectives in the policy or a board paper, if they are measurable and monitored.Objectives that cannot be measured; no evidence they are monitored; not communicated to the people who deliver them.Measurable, owned and dated; approved and communicated; results monitored.ISO 27001 Implementation Methodology & Project Plan (this pack)ISMS-05 Information Security Objectives (Draft)YesNoNoNoFailNot approved. Not under document control. No evidence of use yet.Head of Information Security21 Oct 2026EXAMPLE — Planned in the readiness assessment.2010
EXAMPLEMD-087.2CompetenceEvidence of competenceRecordCompetence requirements for each ISMS role, and training records, certificates, CVs or appraisals showing the people meet them.HR system or training platform records, if they cover the ISMS roles, including contractors.No competence requirements for the ISMS manager, internal auditor or control owners; nothing for contractors; no check that training worked.Requirements set for every ISMS role, and evidence that each person meets them.—HR system training and competence recordsYesN/AYesPartlyFailIn use for less than 3 months.HR Director1 Dec 2026EXAMPLE — In place in the readiness assessment.2011
EXAMPLEMD-097.5.1GeneralDocumented information the organisation decides it needs for the ISMS to be effectiveDocumentA document register listing every policy, procedure and record the ISMS relies on, with owner, version and review date.A policy register extended to procedures and records.Procedures that policies refer to do not exist; documents past their review date; drafts in use.Every document the ISMS relies on is listed, approved, in date and under control.P04-A06 Policy Register & Review Schedule; P04-A05 Security Policy Hierarchy & Document MapP04 policy register; ISMS-01 to ISMS-08YesPartlyPartlyYesFailApproval incomplete. Document control incomplete or review overdue.Head of Information Security24 Nov 2026EXAMPLE — In place in the readiness assessment.2012
EXAMPLEMD-108.1Operational planning and controlEvidence that processes have been carried out as plannedRecordThe records the processes and controls produce: tickets, logs, change records, minutes, reports.System logs and tickets, if they can be retrieved for the period the auditor samples.Records for only part of the period; outsourced processes with no records the organisation can see.Records exist for every planned process over the period an auditor samples.—Service desk tickets, change records and backup logsYesN/AYesPartlyFailIn use for less than 3 months.Head of Information Security6 Oct 2026EXAMPLE — In place in the readiness assessment.2013
EXAMPLEMD-118.2Information security risk assessmentResults of risk assessmentsRecordThe risk register with dated assessments, and records of reassessment at planned intervals or after a significant change.A dated export from a risk tool.Only one assessment ever carried out; no reassessment after a significant change.Dated results, reassessed at the planned interval and after significant change.P05-A05 Information Security Risk Register; P05-A06 Risk Assessment WorkbookISMS-07 Information Security Risk Register (Approved 2026-07-20)YesYesYesPartlyFailIn use for less than 3 months.Head of Information Security20 Oct 2026EXAMPLE — In place in the readiness assessment.2014
EXAMPLEMD-128.3Information security risk treatmentResults of risk treatmentRecordRisk register updates showing the treatment done and the residual risk, accepted by the risk owner.Tracker entries linked to the risk references.Treatment marked complete with no evidence; residual risk not re-scored.Each completed treatment recorded with evidence and the residual risk accepted.P05-A07 Risk Treatment Plan; P05-A08 Risk Acceptance Form & Approval RecordISMS-04 progress entriesPartlyN/AYesNoFailCovers only part of the item, or is a draft. No evidence of use yet.Head of Information Security2 Dec 2026EXAMPLE — Planned in the readiness assessment.2015
EXAMPLEMD-139.1Monitoring, measurement, analysis and evaluationResults of monitoring and measurementRecordA measurement plan (what is measured, how, when, and who analyses it) and the periodic reports.Dashboard exports, if dated and kept.Measures defined but never analysed or evaluated; no record of who reviewed the results.Results recorded, analysed and evaluated at the planned frequency.—NoMissingCreate it, have it approved and put it under document control.Head of Information Security23 Dec 2026EXAMPLE — Planned in the readiness assessment.1016
EXAMPLEMD-149.2.2Internal audit programmeInternal audit programme and audit resultsRecordThe audit programme (frequency, methods, responsibilities, criteria and scope), the audit plans, reports and findings.A contracted auditor's report, if the programme is the organisation's own and the auditor is independent (IS-07).Audits that cover Annex A but not clauses 4 to 10; auditors auditing their own work; findings not followed up.An approved programme covering the whole ISMS, and at least one complete audit with its report (IS-06).ISMS Internal Audit Programme & Procedure (this pack)ISMS-08 Internal Audit Programme (Draft)PartlyNoNoNoFailCovers only part of the item, or is a draft. Not approved. Not under document control. No evidence of use yet.Head of Information Security23 Dec 2026EXAMPLE — Planned in the readiness assessment.2017
EXAMPLEMD-159.3.3Management review resultsResults of management reviewsRecordMinutes showing every required input was considered, and the decisions on improvement and change.Executive committee or board minutes, if every required input was considered and the decisions are recorded.Required inputs missing from the minutes (for example changes in interested parties' needs, or audit results); decisions with no actions.At least one review held, every input covered, decisions and actions recorded (IS-06).Management Review Meeting Pack (this pack)NoMissingCreate it, have it approved and put it under document control.Chief Operating Officer6 Jan 2027EXAMPLE — Planned in the readiness assessment.1018
EXAMPLEMD-1610.2Nonconformity and corrective actionNonconformities, actions taken and results of corrective actionRecordA log of nonconformities: what happened, the correction, the root cause, the corrective action, owner, date and the effectiveness check.The gap tracker or a ticket queue, if it records the root cause and the effectiveness check.No root cause recorded; effectiveness never checked; only audit findings logged, not incidents or complaints.Every nonconformity logged with root cause, correction, corrective action and an effectiveness check (IS-09).ISMS Gap & Remediation Tracker (this pack)Incident log: post-incident actions onlyPartlyN/AYesNoFailCovers only part of the item, or is a draft. No evidence of use yet.Head of Information Security11 Nov 2026EXAMPLE — Planned in the readiness assessment.2019

Annex A Documents

Documented information auditors commonly expect for Annex A controls, where the control usually produces a document or record (control number and title only). Answer N/A for a control your Statement of Applicability excludes.

RowItem IDControlControl titleDocumented information commonly expected (in our words)Document or recordCISO Times template that helpsYour document or recordExists?Approved?Under document control?Evidence of use?ResultWhat is missingOwnerTarget dateEvidence reference and notesAction order (working)
EXAMPLEAD-01A.5.1Policies for information securityThe information security policy and the topic-specific policiesDocumentP04-A01 Security Policy Management Pack — Guide; P04-A02 Policy Framework StandardInformation Security Policy (P04 register ISP-001) v3.0 (Approved, review 2027-03-12); Acceptable Use Policy (P04 register AUP-001) v2.1 (Review overdue, review 2026-07-01); Access Control Policy (P04 register ACP-001) v2.0 (Approved, review 2027-01-20); Incident Management Policy (P04 register INC-001) v1.2 (Approved, review 2027-05-04); Supplier Security Policy (P04 register SUP-001) v1.0 (Awaiting approval)YesPartlyPartlyYesFailApproval incomplete. Document control incomplete or review overdue.Head of Information Security18 Nov 2026EXAMPLE — Operating in the readiness assessment. Fixed with the clause 7.5.3 gap (overdue reviews).2004
EXAMPLEAD-02A.5.2Information security roles and responsibilitiesSecurity roles and responsibilitiesDocumentP02-A09 Exception & SoD Responsibility Matrix; P04-A09 Policy Development & Approval Responsibility MatrixISMS-06 ISMS Manual (processes, roles and responsibilities) (Approved 2026-08-03)YesYesYesPartlyFailIn use for less than 3 months.Head of Information Security3 Nov 2026EXAMPLE — In place in the readiness assessment.2005
EXAMPLEAD-03A.5.9Inventory of information and other associated assetsInventory of information and other assets, with ownersRecordP01-A05 Scan Coverage & Asset Scope Register; P07-A04 Access Review Scope & System InventoryAsset inventory (configuration management database export)YesN/AYesPartlyFailIn use for less than 3 months.Head of IT20 Oct 2026EXAMPLE — In place in the readiness assessment.2006
EXAMPLEAD-04A.5.10Acceptable use of information and other associated assetsRules for acceptable useDocumentComing: P24 AI Security Governance & Acceptable UseAcceptable Use Policy (P04 register AUP-001) v2.1 (Review overdue, review 2026-07-01)YesYesPartlyYesFailDocument control incomplete or review overdue.Head of Information Security18 Nov 2026EXAMPLE — Operating in the readiness assessment. Fixed with the clause 7.5.3 gap (overdue reviews).2007
EXAMPLEAD-05A.5.12Classification of informationClassification schemeDocumentComing: P15 Information Classification & Handling; P24 AI Security Governance & Acceptable UseInformation classification schemeYesYesYesPartlyFailIn use for less than 3 months.Head of Information Security17 Nov 2026EXAMPLE — In place in the readiness assessment.2008
EXAMPLEAD-06A.5.15Access controlRules for access controlDocumentP07-A02 Access Review MethodologyAccess Control Policy (P04 register ACP-001) v2.0 (Approved, review 2027-01-20)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEAD-07A.5.18Access rightsRecords of access rights granted, changed, reviewed and removedRecordP07-A01 User Access Review Pack — Guide; P07-A02 Access Review MethodologyQuarterly access review recordsYesN/AYesPartlyFailIn use for less than 3 months.Head of IT3 Nov 2026EXAMPLE — In place in the readiness assessment.2010
EXAMPLEAD-08A.5.19Information security in supplier relationshipsRules for managing information security risk from suppliersDocumentP06-A01 Third-Party Security Risk Pack — Guide; P06-A02 Third-Party Security PolicySupplier Security Policy (P04 register SUP-001) v1.0 (Awaiting approval)YesNoNoNoFailNot approved. Not under document control. No evidence of use yet.Head of Procurement7 Oct 2026EXAMPLE — Planned in the readiness assessment.2011
EXAMPLEAD-09A.5.20Addressing information security within supplier agreementsSecurity requirements in supplier agreementsDocumentP06-A02 Third-Party Security Policy; P06-A07 Supplier Contract Security Clause LibrarySecurity clauses in Tier 1 supplier contractsPartlyN/APartlyNoFailCovers only part of the item, or is a draft. Document control incomplete or review overdue. No evidence of use yet.Head of Procurement4 Nov 2026EXAMPLE — Planned in the readiness assessment.2012
EXAMPLEAD-10A.5.24Information security incident management planning and preparationIncident management plan: roles, procedures and communicationDocumentComing: P09 Security Incident Management; P10 Cyber Incident Exercises & Tabletop Scenario LibraryIncident Management Policy (P04 register INC-001) v1.2 (Approved, review 2027-05-04)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEAD-11A.5.26Response to information security incidentsRecords of incidents and how they were handledRecordComing: P09 Security Incident Management; P10 Cyber Incident Exercises & Tabletop Scenario LibraryIncident logYesN/AYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEAD-12A.5.30ICT readiness for business continuityICT continuity plans and records of their testsDocumentComing: P10 Cyber Incident Exercises & Tabletop Scenario Library; P21 DORA ICT Risk & Resilience ReadinessICT recovery plan (not yet tested)YesYesYesNoFailNo evidence of use yet.IT Operations Manager28 Oct 2026EXAMPLE — Planned in the readiness assessment.2015
EXAMPLEAD-13A.5.31Legal, statutory, regulatory and contractual requirementsRegister of legal, statutory, regulatory and contractual requirementsRecordComing: P12 NIS2 Implementation & Readiness; P18 Regulatory Incident Notification & ReportingNoMissingCreate it, have it approved and put it under document control.Legal Counsel28 Oct 2026EXAMPLE — Planned in the readiness assessment.1016
EXAMPLEAD-14A.5.34Privacy and protection of PIIRecords of processing of personal dataRecordComing: P09 Security Incident Management; P10 Cyber Incident Exercises & Tabletop Scenario LibraryRecords of processing activitiesYesYesYesPartlyFailIn use for less than 3 months.Legal Counsel6 Oct 2026EXAMPLE — In place in the readiness assessment.2017
EXAMPLEAD-15A.5.36Compliance with policies, rules and standards for information securityRecords of compliance checks and approved exceptionsRecordP01-A02 Vulnerability & Exposure Management Standard; P02-A01 Security Exception, Waiver & SoD Toolkit — GuideSecurity Exception & Waiver Standard (P04 register EXC-STD) v1.0 (Approved, review 2027-09-10)YesYesYesPartlyFailIn use for less than 3 months.Head of Information Security10 Dec 2026EXAMPLE — In place in the readiness assessment.2018
EXAMPLEAD-16A.5.37Documented operating proceduresDocumented operating procedures for IT operationsDocumentP04-A03 Policy Lifecycle Operating ProcedureBackup Standard (P04 register BKP-001) v1.3 (Review overdue, review 2026-08-15); IT operating proceduresYesYesPartlyPartlyFailDocument control incomplete or review overdue. In use for less than 3 months.IT Operations Manager24 Nov 2026EXAMPLE — In place in the readiness assessment.2019
EXAMPLEAD-17A.6.1ScreeningRecords of background checksRecord—HR screening recordsYesN/AYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEAD-18A.6.3Information security awareness, education and trainingRecords of awareness and training completedRecordP04-A07 Policy Attestation & Acknowledgement Tracker; P07-A05 Reviewer Instruction Pack & Campaign CommunicationsAwareness campaign completion recordsYesN/AYesPartlyFailIn use for less than 3 months.Head of Information Security14 Dec 2026EXAMPLE — In place in the readiness assessment.2021
EXAMPLEAD-19A.6.5Responsibilities after termination or change of employmentLeaver and mover procedure and its recordsDocumentComing: P10 Cyber Incident Exercises & Tabletop Scenario Library; P13 Joiner-Mover-Leaver & Access ProvisioningJoiner, Mover, Leaver Procedure (P04 register JML-PRC) v2.2 (Approved, review 2027-02-03)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEAD-20A.6.6Confidentiality or non-disclosure agreementsSigned confidentiality or non-disclosure agreementsRecord—Signed confidentiality agreementsYesYesYesPartlyFailIn use for less than 3 months.HR Director6 Oct 2026EXAMPLE — In place in the readiness assessment.2023
EXAMPLEAD-21A.6.7Remote workingRules for remote workingDocument—Remote Working Guideline (P04 register RMT-GDL) v1.1 (Approved, review 2027-11-18)YesYesYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.
EXAMPLEAD-22A.8.8Management of technical vulnerabilitiesRules for technical vulnerability management, and scan and remediation recordsDocumentP01-A01 Vulnerability Management Operating Pack — Guide; P01-A02 Vulnerability & Exposure Management StandardVulnerability & Exposure Management Standard (P04 register VMS-001) v1.0 (Approved, review 2027-09-10)YesYesYesPartlyFailIn use for less than 3 months.Head of IT10 Dec 2026EXAMPLE — In place in the readiness assessment.2025
EXAMPLEAD-23A.8.9Configuration managementApproved baseline configurationsDocumentP01-A07 Vulnerability Scanner Configuration Review ChecklistNoMissingCreate it, have it approved and put it under document control.Head of IT11 Nov 2026EXAMPLE — Planned in the readiness assessment.1026
EXAMPLEAD-24A.8.13Information backupBackup rules and records of restore testsDocumentComing: P22 Cyber Resilience & Recovery; P23 Backup & Restore AssuranceBackup Standard (P04 register BKP-001) v1.3 (Review overdue, review 2026-08-15)YesYesPartlyYesFailDocument control incomplete or review overdue.Head of Information Security18 Nov 2026EXAMPLE — Operating in the readiness assessment. Fixed with the clause 7.5.3 gap (overdue reviews).2027
EXAMPLEAD-25A.8.15LoggingLogging rules and log retentionDocumentComing: P14 Privileged Access ManagementPlatform logging and retention settingsYesYesYesPartlyFailIn use for less than 3 months.Head of IT10 Nov 2026EXAMPLE — In place in the readiness assessment.2028
EXAMPLEAD-26A.8.24Use of cryptographyRules for cryptography and key managementDocument—Cryptography rules in the engineering handbookYesYesYesPartlyFailIn use for less than 3 months.Head of IT24 Nov 2026EXAMPLE — In place in the readiness assessment.2029
EXAMPLEAD-27A.8.25Secure development life cycleSecure development rulesDocumentComing: P25 Generative AI SecuritySecure development procedure in the engineering handbookYesYesYesPartlyFailIn use for less than 3 months.Head of Engineering24 Nov 2026EXAMPLE — In place in the readiness assessment.2030
EXAMPLEAD-28A.8.32Change managementChange management procedure and change recordsRecordComing: P17 Patch Management; P29 Secure Configuration, Hardening & BaselinesPull request and deployment recordsYesN/AYesYesPassNothing: keep it in date.EXAMPLE — Operating in the readiness assessment.

Summary & Sign-off

Summary and sign-off

The results as counts, the items to act on, and the sign-off. Everything above the sign-off is calculated.

EXAMPLE: the example organisation, as at 2026-09-30. Clear the EXAMPLE answers to use your own.

Results

AreaPassFailMissingN/ANot answeredResult
Required by the clauses3112003 of 16 items pass
Commonly expected for Annex A7192007 of 28 items pass

Items with no Item ID are not counted. N/A items are left out of the total they are measured against.

Required documents to act on — missing first

ItemResultOwnerTarget dateMap rowWhat is missing
MD-13 9.1 — Results of monitoring and measurementMissingHead of Information Security23 Dec 202613Create it, have it approved and put it under document control.
MD-15 9.3.3 — Results of management reviewsMissingChief Operating Officer6 Jan 202715Create it, have it approved and put it under document control.
MD-04 6.1.3 — Risk treatment processFailHead of Information Security24 Nov 20264In use for less than 3 months.
MD-05 6.1.3 — Statement of ApplicabilityFailHead of Information Security24 Nov 20265In use for less than 3 months.
MD-06 6.1.3 — Risk treatment planFailHead of Information Security24 Nov 20266In use for less than 3 months.
MD-07 6.2 — Information security objectivesFailHead of Information Security21 Oct 20267Not approved. Not under document control. No evidence of use yet.
MD-08 7.2 — Evidence of competenceFailHR Director1 Dec 20268In use for less than 3 months.
MD-09 7.5.1 — Documented information the organisation decides it needs for the ISMS to be effectiveFailHead of Information Security24 Nov 20269Approval incomplete. Document control incomplete or review overdue.
MD-10 8.1 — Evidence that processes have been carried out as plannedFailHead of Information Security6 Oct 202610In use for less than 3 months.
MD-11 8.2 — Results of risk assessmentsFailHead of Information Security20 Oct 202611In use for less than 3 months.
MD-12 8.3 — Results of risk treatmentFailHead of Information Security2 Dec 202612Covers only part of the item, or is a draft. No evidence of use yet.
MD-14 9.2.2 — Internal audit programme and audit resultsFailHead of Information Security23 Dec 202614Covers only part of the item, or is a draft. Not approved. Not under document control. No evidence of use yet.
MD-16 10.2 — Nonconformities, actions taken and results of corrective actionFailHead of Information Security11 Nov 202616Covers only part of the item, or is a draft. No evidence of use yet.

Annex A documents to act on — missing first

ItemResultOwnerTarget dateMap rowWhat is missing
AD-13 A.5.31 — Register of legal, statutory, regulatory and contractual requirementsMissingLegal Counsel28 Oct 202613Create it, have it approved and put it under document control.
AD-23 A.8.9 — Approved baseline configurationsMissingHead of IT11 Nov 202623Create it, have it approved and put it under document control.
AD-01 A.5.1 — The information security policy and the topic-specific policiesFailHead of Information Security18 Nov 20261Approval incomplete. Document control incomplete or review overdue.
AD-02 A.5.2 — Security roles and responsibilitiesFailHead of Information Security3 Nov 20262In use for less than 3 months.
AD-03 A.5.9 — Inventory of information and other assets, with ownersFailHead of IT20 Oct 20263In use for less than 3 months.
AD-04 A.5.10 — Rules for acceptable useFailHead of Information Security18 Nov 20264Document control incomplete or review overdue.
AD-05 A.5.12 — Classification schemeFailHead of Information Security17 Nov 20265In use for less than 3 months.
AD-07 A.5.18 — Records of access rights granted, changed, reviewed and removedFailHead of IT3 Nov 20267In use for less than 3 months.
AD-08 A.5.19 — Rules for managing information security risk from suppliersFailHead of Procurement7 Oct 20268Not approved. Not under document control. No evidence of use yet.
AD-09 A.5.20 — Security requirements in supplier agreementsFailHead of Procurement4 Nov 20269Covers only part of the item, or is a draft. Document control incomplete or review overdue. No evidence of use yet.
AD-12 A.5.30 — ICT continuity plans and records of their testsFailIT Operations Manager28 Oct 202612No evidence of use yet.
AD-14 A.5.34 — Records of processing of personal dataFailLegal Counsel6 Oct 202614In use for less than 3 months.
AD-15 A.5.36 — Records of compliance checks and approved exceptionsFailHead of Information Security10 Dec 202615In use for less than 3 months.
AD-16 A.5.37 — Documented operating procedures for IT operationsFailIT Operations Manager24 Nov 202616Document control incomplete or review overdue. In use for less than 3 months.
AD-18 A.6.3 — Records of awareness and training completedFailHead of Information Security14 Dec 202618In use for less than 3 months.
AD-20 A.6.6 — Signed confidentiality or non-disclosure agreementsFailHR Director6 Oct 202620In use for less than 3 months.
AD-22 A.8.8 — Rules for technical vulnerability management, and scan and remediation recordsFailHead of IT10 Dec 202622In use for less than 3 months.
AD-24 A.8.13 — Backup rules and records of restore testsFailHead of Information Security18 Nov 202624Document control incomplete or review overdue.
AD-25 A.8.15 — Logging rules and log retentionFailHead of IT10 Nov 202625In use for less than 3 months.
AD-26 A.8.24 — Rules for cryptography and key managementFailHead of IT24 Nov 202626In use for less than 3 months.
AD-27 A.8.25 — Secure development rulesFailHead of Engineering24 Nov 202627In use for less than 3 months.

Sign-off

RoleNameDateSignature or approval reference
Checked by[[Name]][[YYYY-MM-DD]][[Reference]]
Reviewed by (ISMS manager)[[Name]][[YYYY-MM-DD]][[Reference]]
Next check due[[Before Stage 1 / before Stage 2]][[YYYY-MM-DD]]

Lists

CheckCheckNACheckExistsItemTypeResult
YesYesYesDocumentPass
PartlyPartlyPartlyRecordFail
NoNoNoMissing
N/AN/AN/A

Not answered

Definitions

Definitions

TermMeaning in this workbook
Documented informationInformation the organisation must control and keep, and the medium it is on (clause 7.5): documents that say what will be done, and records that show what was done.
DocumentDocumented information that says what will be done, such as a policy, a procedure or the scope. It is approved and reviewed.
RecordDocumented information that shows something was done, such as an audit report or training record. It is kept, protected and retained, not approved.
Document controlIdentification, versioning, review and approval, distribution, access, storage, retention and disposal (clause 7.5.2 and 7.5.3).
Evidence of useProof that a document is followed or a record is produced, over long enough for an auditor to sample: this checklist uses [[3]] months (IS-05).
Statement of Applicability (SoA)The document listing every Annex A control, whether it is applied and why (clause 6.1.3): see the Statement of Applicability Template.
Stage 1 auditThe first part of the certification audit, which reviews the ISMS documents and readiness; missing required documents are usually found here.
EXAMPLEValues for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity) as at 2026-09-30. Replace them with your own.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 7.5 — Documented informationWhole workbook: the documented information the ISMS needs, and the four checks
ISO/IEC 27001:2022Clause 7.5.3 — Control of documented informationCheck 3: under document control
ISO/IEC 27001:2022Clause 4.3 — Determining the scope of the information security management systemItem MD-01: the scope
ISO/IEC 27001:2022Clause 6.1.3 — Information security risk treatmentItems MD-04 to MD-06: risk treatment process, Statement of Applicability and risk treatment plan
NIST CSF 2.0GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed”Annex A Documents: the register of legal, regulatory and contractual requirements (AD for 5.31)

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0