Policy Coverage Gap Assessment
Identifies which required policy topics are missing, duplicated or out of date against a chosen framework baseline.
Available soon
- Format
- Excel
- Size
- 70 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Your Profile
- Assessment
- Example Answers
- Results by Topic
- Summary & Actions
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Your Profile: choose your profile in D6 and answer D7 (in-house software development), as in the Security Policy Hierarchy & Document Map. Put the date of the assessment in D8. |
| 2 | Assessment: for each topic marked 'Yes' in 'Required for your profile?', name the document or documents that cover it (reference and title from your register), then answer the five questions from the drop-down lists. Topics marked 'No' need no answers. |
| 3 | Answer from the evidence, not from memory: the register, the approval record, the review date and the acknowledgement figures. Note the evidence in the last column. |
| 4 | Your Profile: change D5 from 'Example organisation' to 'My answers'. The Results by Topic and Summary & Actions sheets now describe your organisation. |
| 5 | Summary & Actions: read the counts and work down the action list. It puts missing documents first — Core topics, then Regulated, then Growing — and then documents that need work, in the same order. |
| 6 | Record each action in your plan with an owner and a date. New or changed documents follow the Policy Lifecycle Operating Procedure; record each in the Policy Register & Review Schedule. |
| 7 | Export: select the Results by Topic table, copy, and paste as values into your records. Repeat the assessment at least once a year and after any trigger for review, and compare. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The five questions and what each answer means:
1. Document exists? Yes: one or more documents cover the whole topic. Partly: a document covers some of it, or covers it at a lower tier than it needs (for example a procedure with no policy). No: nothing written covers it.
2. Approved at the right tier? (PF-03) Yes: the document is at the tier the Document Map recommends (or the tier you chose and recorded), and was approved by that tier's approver. No: it was approved by someone else, is still a draft or awaiting approval, or sits at a lower tier (a guideline where a standard is needed). Rule PF-03: "Each tier is approved at the level set for it; a document is not in force until approved and published."
3. In date? (PF-06) Yes: approved, and its next review date has not passed. No: past its review date, or never approved (so it has no review date). Rule PF-06: "Every document is reviewed by its tier's maximum interval, and sooner on any trigger; a review that changes nothing is still recorded."
4. Acknowledged? (PF-09) Asked only for topics at the Policy tier: only Policy-tier documents are acknowledged individually. Yes: at least 95% of the people it applies to have a current acknowledgement (the PM-03 target). No: below that, or no document at that tier yet. For topics at other tiers the answer is 'Not applicable', filled in for you, and the results ignore anything typed there.
5. Duplicated by another document? Yes: another document covers the same ground, so people could follow two different rules. No: it is the only one.
Results. Not required: your profile does not need the topic. Missing: no document. Duplicated: two documents overlap (fix this first for the topic, even if other checks fail). Needs work: covers only part of the topic, or one check fails. Covered: a document exists, at the right tier, in date, acknowledged where required and not duplicated. Not answered: a question on a required topic is blank.
The worked example: while D5 says 'Example organisation', results come from the Example Answers sheet: the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity), profile Regulated, as at 2026-09-30. Topics in its register excerpt are answered from the register; the rest are marked ASSUMED. To clear the example, set D5 to 'My answers' and replace the EXAMPLE date in D8. Keep the Example Answers sheet: the results read it whenever D5 is set back to the example.
Tailoring — small organisation: the Core profile needs about seven topics; several may share one short document. A document that covers two topics is not a duplicate: duplication means two documents saying different things about the same topic.
Tailoring — regulated entity (NIS2, DORA): the management body approves the risk-management measures (NIS2 Art 20(1)); under DORA every ICT security policy records its approval date by the management body and the documentation to be maintained (RTS Art 2(2)(b), (f)). Answer 'Approved at the right tier?' No where the management body has not approved a document that needs it.
Tailoring — IT run by a service provider: a provider's document can cover an operational topic only if the contract makes it binding on the provider and you can see it. Answer Partly where you rely on the provider but cannot show the document, and keep ownership of the topic in your organisation.
Limitations: this assesses whether the right documents exist and are governed, not whether what they say is good or whether people follow them. A topic can be Covered by a weak policy. Test what the documents say against the Security Policy Document Template, and whether they are followed through audit and the effectiveness assessment (PT-18).
Your Profile
Your profile
Choose which answers the results use, your profile and whether you develop software in-house. Yellow cells are yours.
| Results use | Example organisation | EXAMPLE — change to 'My answers' once you have answered the Assessment sheet. | |
| Your profile | Core: every organisation. Growing: over about [[50]] people. In-house development adds PT-12 to any profile (D7). Regulated: an NIS2 essential or important entity, or a DORA financial entity. | ||
| Do you develop software in-house? | 'Yes' adds PT-12 (Secure development and change management) whatever the profile. | ||
| Date of the assessment | 30 Sep 2026 | EXAMPLE — the example organisation's as-at date. Replace with today's date, or =TODAY(). | |
What the results use
| Setting | Value | Where it comes from | |
|---|---|---|---|
| Profile | Regulated | EXAMPLE — the example organisation's profile | |
| In-house software development | Yes | EXAMPLE — the example organisation's answer | |
| Example organisation's profile | Regulated | EXAMPLE — a software services company with 240 staff in two offices, an NIS2 important entity. | |
| Example organisation develops software | Yes | EXAMPLE — a software services company. | |
Assessment
Your answers, one row per topic. Answer the topics marked Yes in column E. The five questions are explained on the Instructions sheet.
| Topic ID | Topic | Tier (recom-mended) | Needed from | Required for your profile? | Document(s) that cover it (reference and title) | 1. Document exists? | 2. Approved at the right tier? (PF-03) | 3. In date? (PF-06) | 4. Acknowledged? (PF-09, Policy tier only) | 5. Duplicated by another document? | Notes or evidence |
|---|---|---|---|---|---|---|---|---|---|---|---|
| PT-01 | Information security policy (the top policy) | Policy | Core | Choose a profile | |||||||
| PT-02 | Acceptable use of information and technology | Policy | Core | Choose a profile | |||||||
| PT-03 | Access control and identity | Policy | Core | Choose a profile | |||||||
| PT-04 | Asset management and information classification | Policy | Core | Choose a profile | |||||||
| PT-05 | Incident management | Policy | Core | Choose a profile | |||||||
| PT-06 | Backup and recovery | Standard | Core | Choose a profile | Not applicable | ||||||
| PT-07 | Vulnerability and patch management | Standard | Core | Choose a profile | Not applicable | ||||||
| PT-08 | Supplier and third-party security | Policy | Growing | Choose a profile | |||||||
| PT-09 | Remote working and mobile devices | Standard | Growing | Choose a profile | Not applicable | ||||||
| PT-10 | Cryptography and key management | Standard | Growing | Choose a profile | Not applicable | ||||||
| PT-11 | Logging and monitoring | Standard | Growing | Choose a profile | Not applicable | ||||||
| PT-12 | Secure development and change management | Standard | Growing | Choose a profile | Not applicable | ||||||
| PT-13 | Physical and environmental security | Standard | Growing | Choose a profile | Not applicable | ||||||
| PT-14 | People security (joiners, movers, leavers, training) | Policy | Growing | Choose a profile | |||||||
| PT-15 | Security exceptions and waivers | Standard | Growing | Choose a profile | Not applicable | ||||||
| PT-16 | Business continuity and ICT resilience | Policy | Regulated | Choose a profile | |||||||
| PT-17 | Information security risk management | Policy | Regulated | Choose a profile | |||||||
| PT-18 | Effectiveness assessment of security measures | Procedure | Regulated | Choose a profile | Not applicable |
Example Answers
EXAMPLE — the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity), profile Regulated, as at 2026-09-30. Rows marked ASSUMED are not in its register excerpt.
| Example | Topic ID | Topic | Tier (recom-mended) | Needed from | Document(s) that cover it (reference and title) | 1. Document exists? | 2. Approved at the right tier? (PF-03) | 3. In date? (PF-06) | 4. Acknowledged? (PF-09, Policy tier only) | 5. Duplicated by another document? | Basis of the example answer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | PT-01 | Information security policy (the top policy) | Policy | Core | ISP-001 Information Security Policy | Yes | Yes | Yes | Yes | No | From the example register: ISP-001 Information Security Policy v3.0, a Policy, status Approved; next review 2027-03-12; 231 of 240 people acknowledged (96%, target 95%). |
| EXAMPLE | PT-02 | Acceptable use of information and technology | Policy | Core | AUP-001 Acceptable Use Policy | Yes | Yes | No | No | No | From the example register: AUP-001 Acceptable Use Policy v2.1, a Policy, status Review overdue; next review 2026-07-01, 91 calendar days overdue as at 2026-09-30; 214 of 240 people acknowledged (89%, target 95%). |
| EXAMPLE | PT-03 | Access control and identity | Policy | Core | ACP-001 Access Control Policy | Yes | Yes | Yes | Yes | No | From the example register: ACP-001 Access Control Policy v2.0, a Policy, status Approved; next review 2027-01-20; 229 of 240 people acknowledged (95%, target 95%). |
| EXAMPLE | PT-04 | Asset management and information classification | Policy | Core | No | ASSUMED — the asset list is kept in the IT service desk tool, but no policy says who owns assets or how information is classified. | |||||
| EXAMPLE | PT-05 | Incident management | Policy | Core | INC-001 Incident Management Policy | Yes | Yes | Yes | Yes | No | From the example register: INC-001 Incident Management Policy v1.2, a Policy, status Approved; next review 2027-05-04; 233 of 240 people acknowledged (97%, target 95%). |
| EXAMPLE | PT-06 | Backup and recovery | Standard | Core | BKP-001 Backup Standard | Yes | Yes | No | Not applicable | No | From the example register: BKP-001 Backup Standard v1.3, a Standard, status Review overdue; next review 2026-08-15, 46 calendar days overdue as at 2026-09-30. |
| EXAMPLE | PT-07 | Vulnerability and patch management | Standard | Core | VMS-001 Vulnerability & Exposure Management Standard | Yes | Yes | Yes | Not applicable | No | From the example register: VMS-001 Vulnerability & Exposure Management Standard v1.0, a Standard, status Approved; next review 2027-09-10. |
| EXAMPLE | PT-08 | Supplier and third-party security | Policy | Growing | SUP-001 Supplier Security Policy | Yes | No | No | No | No | From the example register: SUP-001 Supplier Security Policy v1.0, a Policy, status Awaiting approval; not yet approved, so not in force and with no review date. |
| EXAMPLE | PT-09 | Remote working and mobile devices | Standard | Growing | RMT-GDL Remote Working Guideline | Yes | No | Yes | Not applicable | No | From the example register: RMT-GDL Remote Working Guideline v1.1, a Guideline, status Approved; next review 2027-11-18; the topic calls for a Standard. |
| EXAMPLE | PT-10 | Cryptography and key management | Standard | Growing | Cryptography standard (assumed; outside the register excerpt) | Yes | Yes | Yes | Not applicable | No | ASSUMED — a current, approved cryptography standard exists; only Policy-tier documents are acknowledged. |
| EXAMPLE | PT-11 | Logging and monitoring | Standard | Growing | No | ASSUMED — each system team sets its own log retention and review; nothing is written down. | |||||
| EXAMPLE | PT-12 | Secure development and change management | Standard | Growing | Secure development standard (assumed; outside the register excerpt) | Yes | Yes | Yes | Not applicable | No | ASSUMED — a software services company; a current, approved secure development standard exists. |
| EXAMPLE | PT-13 | Physical and environmental security | Standard | Growing | Physical security standard (assumed; outside the register excerpt) | Yes | Yes | Yes | Not applicable | No | ASSUMED — a current, approved standard covers both offices. |
| EXAMPLE | PT-14 | People security (joiners, movers, leavers, training) | Policy | Growing | JML-PRC Joiner, Mover, Leaver Procedure | Partly | No | Yes | No | No | From the example register: JML-PRC Joiner, Mover, Leaver Procedure v2.2, a Procedure, status Approved; next review 2027-02-03; the topic calls for a Policy; judged Partly: a procedure for joiners, movers and leavers, but no people security policy covering screening, training and discipline. |
| EXAMPLE | PT-15 | Security exceptions and waivers | Standard | Growing | EXC-STD Security Exception & Waiver Standard | Yes | Yes | Yes | Not applicable | No | From the example register: EXC-STD Security Exception & Waiver Standard v1.0, a Standard, status Approved; next review 2027-09-10. |
| EXAMPLE | PT-16 | Business continuity and ICT resilience | Policy | Regulated | Business continuity policy and IT disaster recovery policy (assumed) | Yes | Yes | Yes | Yes | Yes | ASSUMED — two approved policies both set recovery times for the same services, and the times differ. |
| EXAMPLE | PT-17 | Information security risk management | Policy | Regulated | No | ASSUMED — the risk method exists only as a slide deck that was never approved. | |||||
| EXAMPLE | PT-18 | Effectiveness assessment of security measures | Procedure | Regulated | No | ASSUMED — controls are tested by the external auditor only; there is no internal procedure. |
Results by Topic
Calculated: one row per topic, from the answers the Your Profile sheet selects. This table is the export — copy it and paste as values. Do not type in it.
| Topic ID | Topic | Tier (recommended) | Needed from | Required? | Document(s) | Exists | Right tier | In date | Acknow-ledged | Dupli-cated | Result | What was found | What to do | Priority group | Sort key |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PT-01 | Information security policy (the top policy) | Policy | Core | Yes | ISP-001 Information Security Policy | Yes | Yes | Yes | Yes | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-02 | Acceptable use of information and technology | Policy | Core | Yes | AUP-001 Acceptable Use Policy | Yes | Yes | No | No | No | Needs work | Past its review date, or never approved. Acknowledgements below 95%. | Review it and record the review (PF-06). Collect acknowledgements from everyone it applies to (PF-09). | 4 | 4005 |
| PT-03 | Access control and identity | Policy | Core | Yes | ACP-001 Access Control Policy | Yes | Yes | Yes | Yes | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-04 | Asset management and information classification | Policy | Core | Yes | No | Missing | No document covers this topic. | Write a policy on this topic from the Security Policy Document Template, have it approved by executive management (the management body, or its delegate for the top policy) (PF-03), and add it to the register (PF-11). | 1 | 1007 | |||||
| PT-05 | Incident management | Policy | Core | Yes | INC-001 Incident Management Policy | Yes | Yes | Yes | Yes | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-06 | Backup and recovery | Standard | Core | Yes | BKP-001 Backup Standard | Yes | Yes | No | Not applicable | No | Needs work | Past its review date, or never approved. | Review it and record the review (PF-06). | 4 | 4009 |
| PT-07 | Vulnerability and patch management | Standard | Core | Yes | VMS-001 Vulnerability & Exposure Management Standard | Yes | Yes | Yes | Not applicable | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-08 | Supplier and third-party security | Policy | Growing | Yes | SUP-001 Supplier Security Policy | Yes | No | No | No | No | Needs work | Not approved at the Policy tier. Past its review date, or never approved. Acknowledgements below 95%. | Issue it as a policy approved by executive management (the management body, or its delegate for the top policy) (PF-01, PF-03). Once approved, set its next review date (PF-06) and collect acknowledgements from everyone it applies to (PF-09). | 6 | 6011 |
| PT-09 | Remote working and mobile devices | Standard | Growing | Yes | RMT-GDL Remote Working Guideline | Yes | No | Yes | Not applicable | No | Needs work | Not approved at the Standard tier. | Issue it as a standard approved by Head of Information Security (the document owner is consulted) (PF-01, PF-03). | 6 | 6012 |
| PT-10 | Cryptography and key management | Standard | Growing | Yes | Cryptography standard (assumed; outside the register excerpt) | Yes | Yes | Yes | Not applicable | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-11 | Logging and monitoring | Standard | Growing | Yes | No | Not applicable | Missing | No document covers this topic. | Write a standard on this topic from the Security Policy Document Template, have it approved by Head of Information Security (the document owner is consulted) (PF-03), and add it to the register (PF-11). | 3 | 3014 | ||||
| PT-12 | Secure development and change management | Standard | Growing | Yes | Secure development standard (assumed; outside the register excerpt) | Yes | Yes | Yes | Not applicable | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-13 | Physical and environmental security | Standard | Growing | Yes | Physical security standard (assumed; outside the register excerpt) | Yes | Yes | Yes | Not applicable | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-14 | People security (joiners, movers, leavers, training) | Policy | Growing | Yes | JML-PRC Joiner, Mover, Leaver Procedure | Partly | No | Yes | No | No | Needs work | Covers only part of the topic. Not approved at the Policy tier. Acknowledgements below 95%. | Extend the document, or add one, so the whole topic is covered. Issue it as a policy approved by executive management (the management body, or its delegate for the top policy) (PF-01, PF-03). Once approved, collect acknowledgements from everyone it applies to (PF-09). | 6 | 6017 |
| PT-15 | Security exceptions and waivers | Standard | Growing | Yes | EXC-STD Security Exception & Waiver Standard | Yes | Yes | Yes | Not applicable | No | Covered | A document exists at the right tier, in date, acknowledged where required and not duplicated. | None: keep it on its review cycle. | ||
| PT-16 | Business continuity and ICT resilience | Policy | Regulated | Yes | Business continuity policy and IT disaster recovery policy (assumed) | Yes | Yes | Yes | Yes | Yes | Duplicated | Another document covers the same ground. | Merge the overlapping documents into one, retire the other (PF-08) and correct the register (PF-11). | 5 | 5019 |
| PT-17 | Information security risk management | Policy | Regulated | Yes | No | Missing | No document covers this topic. | Write a policy on this topic from the Security Policy Document Template, have it approved by executive management (the management body, or its delegate for the top policy) (PF-03), and add it to the register (PF-11). | 2 | 2020 | |||||
| PT-18 | Effectiveness assessment of security measures | Procedure | Regulated | Yes | No | Not applicable | Missing | No document covers this topic. | Write a procedure on this topic from the Security Policy Document Template, have it approved by Head of Information Security (the process owner is consulted) (PF-03), and add it to the register (PF-11). | 2 | 2021 |
Summary & Actions
Summary and actions
The results in words and as 'x of y', and the actions in the order to take them. Everything here is calculated.
EXAMPLE: results for the example organisation (profile Regulated), as at 2026-09-30. Choose 'My answers' on the Your Profile sheet to see your own.
Overall
| Overall result | Core gaps: start with the missing Core topics | ||||
|---|---|---|---|---|---|
| Covered | 8 of 18 required topics | ||||
| Needs work | 5 of 18 required topics | ||||
| Duplicated | 1 of 18 required topics | ||||
| Missing | 4 of 18 required topics | ||||
| Not answered | 0 of 18 required topics | ||||
| Core topics covered | 4 of 7 required Core topics | ||||
| Growing topics covered | 4 of 8 required Growing topics | ||||
| Regulated topics covered | 0 of 3 required Regulated topics |
Actions, in the order to take them
| No. | Topic ID | Topic | Result | Needed from | What to do | Map row |
|---|---|---|---|---|---|---|
| 1 | PT-04 | Asset management and information classification | Missing | Core | Write a policy on this topic from the Security Policy Document Template, have it approved by executive management (the management body, or its delegate for the top policy) (PF-03), and add it to the register (PF-11). | 4 |
| 2 | PT-17 | Information security risk management | Missing | Regulated | Write a policy on this topic from the Security Policy Document Template, have it approved by executive management (the management body, or its delegate for the top policy) (PF-03), and add it to the register (PF-11). | 17 |
| 3 | PT-18 | Effectiveness assessment of security measures | Missing | Regulated | Write a procedure on this topic from the Security Policy Document Template, have it approved by Head of Information Security (the process owner is consulted) (PF-03), and add it to the register (PF-11). | 18 |
| 4 | PT-11 | Logging and monitoring | Missing | Growing | Write a standard on this topic from the Security Policy Document Template, have it approved by Head of Information Security (the document owner is consulted) (PF-03), and add it to the register (PF-11). | 11 |
| 5 | PT-02 | Acceptable use of information and technology | Needs work | Core | Review it and record the review (PF-06). Collect acknowledgements from everyone it applies to (PF-09). | 2 |
| 6 | PT-06 | Backup and recovery | Needs work | Core | Review it and record the review (PF-06). | 6 |
| 7 | PT-16 | Business continuity and ICT resilience | Duplicated | Regulated | Merge the overlapping documents into one, retire the other (PF-08) and correct the register (PF-11). | 16 |
| 8 | PT-08 | Supplier and third-party security | Needs work | Growing | Issue it as a policy approved by executive management (the management body, or its delegate for the top policy) (PF-01, PF-03). Once approved, set its next review date (PF-06) and collect acknowledgements from everyone it applies to (PF-09). | 8 |
| 9 | PT-09 | Remote working and mobile devices | Needs work | Growing | Issue it as a standard approved by Head of Information Security (the document owner is consulted) (PF-01, PF-03). | 9 |
| 10 | PT-14 | People security (joiners, movers, leavers, training) | Needs work | Growing | Extend the document, or add one, so the whole topic is covered. Issue it as a policy approved by executive management (the management body, or its delegate for the top policy) (PF-01, PF-03). Once approved, collect acknowledgements from everyone it applies to (PF-09). | 14 |
11
12
13
14
15
16
17
18
How the order is set
1. Missing documents come first, because a topic with no document has no rule at all: Core topics, then Regulated topics (a legal obligation for regulated entities), then Growing topics.
2. Then documents that need work or are duplicated, in the same order: Core, Regulated, Growing.
3. Within each group, topics keep their order in the list (PT-01 first). The Priority group and Sort key columns on Results by Topic show the working; the grey Map row column here is the row of the topic in that table.
Lists
| AnswerMode | ProfileList | PriorityOrder | YesNo | ExistsAnswer | AckAnswer | AckTiers | Result | TierName | TierApprover |
|---|---|---|---|---|---|---|---|---|---|
| Example organisation | Core | Core | Yes | Yes | Yes | Policy | Covered | Policy | executive management (the management body, or its delegate for the top policy) |
| My answers | Growing | Regulated | No | Partly | No | Needs work | Standard | Head of Information Security (the document owner is consulted) | |
| Regulated | Growing | No | Not applicable | Duplicated | Procedure | Head of Information Security (the process owner is consulted) | |||
| Missing | Guideline | information security |
Not answered
Not required
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Topic (PT-nn) | A subject a security document set must cover, such as access control or backup; the 18 topics and the profile from which each is needed are in the Security Policy Hierarchy & Document Map. |
| Profile | Core, Growing or Regulated: decides which topics an organisation needs. Each profile includes the topics of the one before it. |
| Tier | One of Policy, Standard, Procedure, Guideline. The tier sets who approves a document and how often it is reviewed. |
| Covered | A document exists for the whole topic, approved at the right tier, in date, acknowledged where required and not duplicated. |
| Needs work | A document exists but covers only part of the topic, or fails at least one check. |
| Duplicated | Two or more documents cover the same ground, so people could be following different rules. |
| Missing | No written document covers the topic. |
| Acknowledgement | A person's recorded confirmation that they have read a policy that applies to them (PF-09). The pack's target is 95% of people in scope (PM-03). |
| Register | The Policy Register & Review Schedule: the only authoritative list of documents (PF-11). |
| Management body | The board of directors or equivalent governing body; under NIS2 and DORA it approves the security risk-management measures. |
| ASSUMED | An example answer for a topic the example register excerpt does not show, chosen to illustrate a result. |
| EXAMPLE | Values for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity). Replace them with your own. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 7.5 — Documented information | Whole workbook: whether the documented information the organisation needs exists and is controlled |
| ISO/IEC 27001:2022 | Annex A 5.1 — Policies for information security | Questions 2 and 3: policies approved and reviewed |
| ISO/IEC 27001:2022 | Annex A 5.36 — Compliance with policies, rules and standards for information security | Summary & Actions: gaps in the rules the organisation can be checked against |
| NIST CSF 2.0 | GV.PO-01 — “Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced” | Your Profile and Results: the policy set measured against the organisation's context |
| NIS2 — Directive (EU) 2022/2555 | Article 21(2)(a) — “policies on risk analysis and information system security” | Assessment: the policies the profile requires |
| NIS2 — Directive (EU) 2022/2555 | Article 21(2)(f) — “policies and procedures to assess the effectiveness of cybersecurity risk-management measures” | Whole workbook: assessing the policy set; topic PT-18 |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(b) — ICT security policies indicate the date of their formal approval by the management body | Question 2: approval by the management body (regulated entities) |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(f) — policies list the documentation to be maintained | Results by Topic: the documentation to be maintained |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774