Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Policy Health & Attestation Reporting Workbook

Reports document currency and acknowledgement coverage in the two forms management actually acts on: what is overdue and who has not signed.

Available soon

Format
Excel
Size
95 KB
Length
13 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Register Data
  • Acknowledgement Data
  • Overdue Acknowledgements
  • Metric Definitions
  • Quarterly Report
  • Trend
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Register Data sheet: in the Policy Register & Review Schedule, copy the register table's rows (sheet Register, columns A to Z, from row 4 down) and paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order.
2Acknowledgement Data sheet: in the Policy Attestation & Acknowledgement Tracker, copy the Summary sheet's 'Acknowledgement by policy' rows (columns B to N, one row per policy, not the 'All policies' total) and paste them as values into cell B4.
3Overdue Acknowledgements sheet: from the same tracker, copy the Overdue by Manager rows (columns B to J) and paste them as values into cell B4.
4Delete the EXAMPLE rows on the three data sheets before you paste, and check that dates are real dates (right-aligned), not text.
5Quarterly Report sheet: enter the report date, normally the last day of the quarter. The EXAMPLE uses 2026-09-30; replace it with your quarter end. Document figures are recalculated at this date from the pasted register; acknowledgement figures are as the tracker calculated them at its own As-at date, so set that to the same date before copying.
6Read the four headline measures. Each has its target and a status in words; the colour only repeats the word. Add a line of commentary to every measure that missed its target or moved.
7Name what is overdue and who has not signed: the report lists the documents past review, triggered or in force without approval, the coverage of each policy, and the overdue acknowledgements by manager. Add the action and date agreed for each document.
8Trend sheet: type the previous three quarters' results from the reports you kept (the current quarter fills in). Keep a copy of this workbook for each quarter as the record.
9Complete 'What to tell management' and take the report to [[e.g. Executive Committee, or the management body]] every quarter (PF-12).

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The EXAMPLE is a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30: the same register as the Policy Register & Review Schedule and the same acknowledgement figures as the Policy Attestation & Acknowledgement Tracker. PM-01 is 2 (AUP-001, 91 days past review; BKP-001, 46 days past review); PM-02 is 0; PM-03 is 907 of 960 person-and-policy pairs; PM-04 is 4, counted on the tracker's named sample of 12 people. The previous three quarters on the Trend sheet are EXAMPLE figures typed in, as you would from earlier reports.

PM-03 is counted as: Acknowledged person-and-policy pairs ÷ in-scope pairs, across Policy-tier documents that require acknowledgement. The whole-population totals come from the tracker's Reported columns. PM-04 can only name people listed individually in the tracker; if your tracker holds totals for some policies, say so in the commentary.

Columns used from the register: Document ref, Title, Tier, Owner, Lifecycle status, Approval date, Approved by, Approved at the tier's level, Next review date, Review trigger, Where published. The register's own Status and Days to review are carried across but not used: they were calculated at its as-at date, not your report date.

Tailoring — small organisation: the report can be one page — the four measures, the overdue documents and the names. Take it to whoever approves your policies, every quarter.

Tailoring — regulated entity (NIS2, DORA): take the report to the management body. Documents past review are named with their approval dates (Delegated Regulation (EU) 2024/1774 Art 2(2)(b), (c)); keep each quarter's copy as the record of how the policies' implementation is monitored.

Tailoring — IT run by a service provider: include the provider's documents that carry out your policies in the register you paste, and ask the provider for its staff's acknowledgement figures where they are in scope.

Register Data

Paste the Policy Register & Review Schedule table here as values (columns A–Z, from row 4). Columns AA–AG are calculated at the report date. The 10 EXAMPLE rows are that register's example — delete them first.

ExampleDocument refTitleTierTopic (PT-nn)TopicOwnerApprover requiredVersionLifecycle statusApproval dateApproved byApproved at the tier's levelReview interval (months)Next review dateStatusDays to reviewReview due soonReview orderReview triggerTrigger detailsTriggered reviewWhere publishedSuperseded version archivedRecord checkNotesNext review (calc)Past review at report date (calc)Days past review (calc)In force without approval (calc)Triggered review (calc)Why listed (calc)Listed no. (calc)
EXAMPLEISP-001Information Security PolicyPolicyPT-01Information security policy (the top policy)Chief Operating OfficerExecutive management (the management body, or its delegate for the top policy)3.0Approved12 Mar 2026Executive Committee (without the Chief Operating Officer)Yes1212 Mar 2027Approved1635Intranet policy libraryYesOK12 Mar 2027
EXAMPLEAUP-001Acceptable Use PolicyPolicyPT-02Acceptable use of information and technologyHead of ITExecutive management (the management body, or its delegate for the top policy)2.1Approved1 Jul 2025Executive CommitteeYes121 Jul 2026Review overdue-911Intranet policy libraryYesReview overdue more than 30 days: escalate (PF-06, PM-01)Escalated to executive management on 2026-07-31, 30 days overdue. The owner started the review in September; the changes are material, so the next version is 3.0. Version 2.1 stays in force until 3.0 is approved.1 Jul 2026Yes91Past review, escalate1
EXAMPLEACP-001Access Control PolicyPolicyPT-03Access control and identityHead of ITExecutive management (the management body, or its delegate for the top policy)2.0Approved20 Jan 2026Executive CommitteeYes1220 Jan 2027Approved1123An audit or assessment finding against the documentInternal audit, September 2026: the policy does not cover emergency (break-glass) administrator accounts: who may use them, and how each use is reviewed.Review nowIntranet policy libraryYesTriggered review: review now (PF-06)Review brought forward by the audit finding; the owner is drafting the change to add emergency administrator accounts.20 Jan 2027YesTriggered review2
EXAMPLEINC-001Incident Management PolicyPolicyPT-05Incident managementHead of Information SecurityExecutive management (the management body, or its delegate for the top policy)1.2Approved4 May 2026Executive CommitteeYes124 May 2027Approved2166Intranet policy libraryYesOK4 May 2027
EXAMPLESUP-001Supplier Security PolicyPolicyPT-08Supplier and third-party securityHead of ProcurementExecutive management (the management body, or its delegate for the top policy)1.0Awaiting approval12Awaiting approvalNot applicable (first version)OKWith the Executive Committee for its October meeting. Not published until approved.
EXAMPLEVMS-001Vulnerability & Exposure Management StandardStandardPT-07Vulnerability and patch managementHead of Information SecurityHead of Information Security (the document owner is consulted)1.0Approved10 Sep 2026Executive CommitteeYes1210 Sep 2027Approved3457Intranet policy libraryNot applicable (first version)OK10 Sep 2027
EXAMPLEBKP-001Backup StandardStandardPT-06Backup and recoveryIT Operations ManagerHead of Information Security (the document owner is consulted)1.3Approved15 Aug 2025Head of Information SecurityYes1215 Aug 2026Review overdue-462Intranet policy libraryYesReview overdue more than 30 days: escalate (PF-06, PM-01)Escalated to executive management on 2026-09-14, 30 days overdue. The owner has not yet started the review.15 Aug 2026Yes46Past review, escalate3
EXAMPLEEXC-STDSecurity Exception & Waiver StandardStandardPT-15Security exceptions and waiversHead of Information SecurityHead of Information Security (the document owner is consulted)1.0Approved10 Sep 2026Executive CommitteeYes1210 Sep 2027Approved3458Intranet policy libraryNot applicable (first version)OK10 Sep 2027
EXAMPLEJML-PRCJoiner, Mover, Leaver ProcedureProcedurePT-14People security (joiners, movers, leavers, training)HR DirectorHead of Information Security (the process owner is consulted)2.2Approved3 Feb 2025Head of Information SecurityYes243 Feb 2027Approved1264Intranet policy libraryYesOK3 Feb 2027
EXAMPLERMT-GDLRemote Working GuidelineGuidelinePT-09Remote working and mobile devicesHead of ITInformation security1.1Approved18 Nov 2025Head of Information SecurityYes2418 Nov 2027Approved4149Intranet policy libraryYesOK18 Nov 2027

Acknowledgement Data

Paste the Policy Attestation & Acknowledgement Tracker's Summary 'Acknowledgement by policy' rows here as values, into B4 (not the total row). EXAMPLE: that tracker's example as at 2026-09-30.

ExampleDocument refTitleVersionListed: in scopeListed: currentListed: outdated versionListed: not yet dueListed: overdueListed: overdue more than 30 daysReported: in scopeReported: currentReported: coverageStatus
EXAMPLEISP-001Information Security Policy3.01211001124023196.3%Met
EXAMPLEAUP-001Acceptable Use Policy2.1128004224021489.2%Below target
EXAMPLEACP-001Access Control Policy2.01210011124022995.4%Met
EXAMPLEINC-001Incident Management Policy1.21211010024023397.1%Met

Overdue Acknowledgements

Paste the Policy Attestation & Acknowledgement Tracker's Overdue by Manager rows here as values, into B4. EXAMPLE: that tracker's example as at 2026-09-30.

ExampleNo.ManagerNameRolePolicies overdueOverdue (count)Longest overdue (days)Overdue more than 30 days (count)Manager's people overdue
EXAMPLE1Anna KowalskiDaniel ReyesSoftware EngineerAUP-001 (annual, 77 days)17712
EXAMPLE2Anna KowalskiLiam O'ConnorDevOps EngineerISP-001 (material change, 168 days)11681
EXAMPLE3Grace AdeyemiOliver BrandtAccounts AssistantAUP-001 (annual, 5 days)1501
EXAMPLE4Head of SalesRavi MenonSales ExecutiveAUP-001 (annual, 120 days)112011
EXAMPLE5Mark EllisonChloe MartinCustomer Support AgentACP-001 (material change, 221 days)122112
EXAMPLE6Mark EllisonJamal AhmedCustomer Support AgentAUP-001 (joiner, 23 days)1230

Metric Definitions

Metric definitions

The four headline measures of the Policy Framework Standard, defined once so every quarter is calculated the same way (PF-12).

MeasureDefinitionHow this workbook calculates itTargetHow to read it
PM-01 Documents past review dateApproved documents whose next review date has passed.Register rows with Lifecycle status Approved whose next review date is before the report date. Also shown: how many are policies, and the longest, in calendar days past the review date.Zero policies; no document more than 30 days overdueMet only when no policy is past review and nothing is more than 30 days past it. A review more than 30 calendar days overdue is escalated to executive management (PF-06).
PM-02 Documents in force without approvalDocuments people are told to follow that have no recorded approval at the right level.Register rows, not retired, that are approved or published but have no approval date, no approver recorded, an approval below the tier's level, or approval by the document's own owner.ZeroAny figure above zero means people are following something nobody with authority approved (each tier is approved at the level set for it; a document is not in force until approved and published.).
PM-03 Acknowledgement coveragePeople in scope with a current acknowledgement of each policy that applies to them, as a share of all people in scope.Acknowledged person-and-policy pairs ÷ in-scope pairs, across Policy-tier documents that require acknowledgement. From the Acknowledgement Data: sum of Reported: current divided by sum of Reported: in scope.≥ 95%Read the per-policy coverage too: one policy far below target can hide inside a good total.
PM-04 Overdue acknowledgementsPeople past their joiner, change or annual deadline, named by manager.From the Acknowledgement Data: the sum of Listed: overdue more than 30 days (the headline) and of Listed: overdue (all). Names come from the Overdue Acknowledgements sheet.Zero older than 30 daysOld overdue acknowledgements are a management problem, not a reminder problem: each manager named is asked to act.

Quarterly Report

Policy health and attestation — quarterly report

Yellow cells are yours: the report date, the commentary and the actions. Everything else is calculated. Each figure has a status in words; the colour only repeats it.

Report settings

SettingValue
Report date (the quarter end)30 Sep 2026EXAMPLE report date: replace with your quarter end
QuarterQ3 2026
Quarter start1 Jul 2026

Headline measures

MeasureResultTargetStatusCommentary — what changed, and why
PM-01 Documents past review date2Zero policies; no document more than 30 days overdueAction needed
of which policies10
longest past its review date (days)9130 or fewer
PM-02 Documents in force without approval0ZeroMet
PM-03 Acknowledgement coverage94.5%≥ 95%Below target
PM-04 Overdue acknowledgements: older than 30 days4Zero older than 30 daysAction needed
all overdue acknowledgements6—

Document figures are at the report date; acknowledgement figures are as the tracker calculated them. PM-04 counts the people the tracker lists individually.

What is overdue — documents

DocumentTierOwnerNext review dateDays past reviewWhy listedAction agreed and date
AUP-001 Acceptable Use PolicyPolicyHead of IT1 Jul 202691Past review, escalate
ACP-001 Access Control PolicyPolicyHead of IT20 Jan 2027Triggered review
BKP-001 Backup StandardStandardIT Operations Manager15 Aug 202646Past review, escalate

Coming up: 0 approved document(s) due for review by 2026-12-31. Documents more than 30 days past review are escalated to executive management (PF-06).

Who has not signed — coverage by policy

PolicyIn scopeCurrentNot currentCoverageStatusOverdue (listed)Over 30 days (listed)
ISP-001 Information Security Policy240231996.3%Met11
AUP-001 Acceptable Use Policy2402142689.2%Below target42
ACP-001 Access Control Policy2402291195.4%Met11
INC-001 Incident Management Policy240233797.1%Met00
All policies9609075394.5%Below target64

Who has not signed — overdue acknowledgements by manager (first 15)

ManagerNamePolicies overdueLongest (days)Over 30 daysManager's people overdue
Anna KowalskiDaniel ReyesAUP-001 (annual, 77 days)7712
Anna KowalskiLiam O'ConnorISP-001 (material change, 168 days)1681
Grace AdeyemiOliver BrandtAUP-001 (annual, 5 days)51
Head of SalesRavi MenonAUP-001 (annual, 120 days)12011
Mark EllisonChloe MartinACP-001 (material change, 221 days)22112
Mark EllisonJamal AhmedAUP-001 (joiner, 23 days)23

What to tell management

PointWhat to say
The position in one sentence[[e.g. Two documents are past review, one of them the Acceptable Use Policy; acknowledgement coverage is 94.5%, just below the 95% target.]]
What is overdue and what is being done[[e.g. AUP-001 is 91 days past review; version 3.0 goes to executive management in November. BKP-001 is 46 days past review; the IT Operations Manager starts the review in October.]]
Who has not signed[[e.g. Four people are more than 30 days overdue; their managers have been asked to close them by 16 October.]]
Decisions or support needed[[e.g. Approve SUP-001 at the October meeting; confirm the review plan for AUP-001.]]
What has improved since the last report[[e.g. No document was in force without approval all year.]]
Prepared by (name, role) and date[[Name, role, YYYY-MM-DD]]

Trend

Trend — the last four quarters

The four headline measures at each of the last four quarter ends. Type the three earlier quarters from the reports you kept; the last row comes from the Quarterly Report. Direction compares each quarter with the one before.

Quarter endQuarterPM-01 past reviewPM-01 statusPM-02 without approvalPM-02 statusPM-03 coveragePM-03 statusPM-04 over 30 daysPM-04 statusPM-03 directionCommentary
31 Dec 2025Q4 20252Action needed0Met91.0%Below target3Action needed—
31 Mar 2026Q1 20261Action needed0Met93.2%Below target2Action neededImproving
30 Jun 2026Q2 20260Met0Met95.1%Met2Action neededImproving
30 Sep 2026Q3 20262Action needed0Met94.5%Below target4Action neededWorsening

EXAMPLE: the three earlier quarters are typed in, as you would from the reports kept for them. PM-01's status is typed too: it depends on which documents were overdue and by how long, which only that quarter's report shows.

Lists

TierLifecycleStatusMetStatus
PolicyDraftMet
StandardIn consultationAction needed
ProcedureAwaiting approval
GuidelineApproved

Retired

Definitions

Definitions

TermMeaning in this workbook
Report dateThe quarter end the report is for. Document figures are calculated at this date.
Past reviewAn approved document whose next review date is before the report date (PM-01).
Days past reviewCalendar days from the next review date to the report date.
EscalationA review more than 30 calendar days past its date is escalated to executive management (PF-06) and named in every quarterly report until approved.
In force without approvalAn approved or published document with no approval date, no approver recorded, an approval below its tier's level, or approval by its own owner (PF-03, PM-02).
Triggered reviewAn approved document with an event recorded that brings its review forward (PF-06).
Policies requiring acknowledgementPolicy-tier documents in force (PF-09).
Reported: in scope / currentPer policy, people in scope and people with a current acknowledgement, from the Policy Attestation & Acknowledgement Tracker: whole-population totals where the tracker holds them, otherwise its listed people.
CoverageCurrent acknowledgements as a share of people in scope.
Listed: overduePeople listed individually in the tracker who are past their joiner, change or annual deadline.
PM-01 Documents past review dateApproved documents whose next review date has passed. Target: zero policies; no document more than 30 days overdue.
PM-02 Documents in force without approvalDocuments people are told to follow that have no recorded approval at the right level. Target: zero.
PM-03 Acknowledgement coveragePeople in scope with a current acknowledgement of each policy that applies to them, as a share of all people in scope. Target: ≥ 95%.
PM-04 Overdue acknowledgementsPeople past their joiner, change or annual deadline, named by manager. Target: zero older than 30 days.
(calc)A column the workbook calculates. Do not type or paste over it.
PF-nn, PM-nnRule and measure numbers in the Policy Framework Standard.
EXAMPLE rowThe example organisation's figures as at 2026-09-30. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationThe workbook as a whole: four defined measures, calculated the same way each quarter, with the results evaluated and reported
ISO/IEC 27001:2022Annex A 5.36 — Compliance with policies, rules and standards for information securityWhat is overdue and who has not signed: where compliance with policies is not yet achieved
NIST CSF 2.0GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”Headline measures against targets, Trend, and what to tell management
NIS2 — Directive (EU) 2022/2555Article 21(2)(f) — “policies and procedures to assess the effectiveness of cybersecurity risk-management measures”The quarterly report as a procedure to assess whether the policies are working
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(c) — policies contain indicators to monitor their implementation and record exceptions from itHeadline measures as indicators to monitor the policies' implementation

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774