Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Policy Register & Review Schedule

Maintains the authoritative inventory of security documents with owner, approval status, version and next review date.

Available soon

Format
Excel
Size
104 KB
Length
10 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Register
  • Summary
  • Review Schedule
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30; replace it with today's date, or type =TODAY() to keep it current. Every status, countdown and flag is measured against this date. Freeze it at a fixed date when you keep a quarter-end copy.
2Delete the EXAMPLE rows on the Register sheet before you enter your own documents. Do not type over the white calculated columns.
3Add one row per security document, of every tier, and nothing else (PF-11). Give it a unique Document ref (for example ACP-001) that never changes and appears on the document itself. Choose its Tier (PF-01) and its Topic (PT-01 to PT-18, as in the Security Policy Hierarchy & Document Map), and name one Owner: a role or a person who is accountable for its content and its review (PF-02).
4Approver required fills in from the tier (PF-03). Policy: approved by executive management (the management body, or its delegate for the top policy); reviewed at least every 12 months. Standard: approved by head of Information Security (the document owner is consulted); reviewed at least every 12 months. Procedure: approved by head of Information Security (the process owner is consulted); reviewed at least every 24 months. Guideline: approved by information security; reviewed at least every 24 months. The review intervals are the latest a review may happen; a trigger brings it forward.
5Record the version in force and its Lifecycle status (Draft, In consultation, Awaiting approval, Approved, Retired). Never type Review overdue: the register shows it when an approved document passes its next review date. The register shows the status of the version in force while a revision is prepared; Draft, In consultation and Awaiting approval apply only to a document with no version in force. Keep the row on the version in force and note the revision's stage in Notes; when the revision is approved, change Version, Approval date and Approved by.
6For an approved document, enter the Approval date, who approved it (the body or person, as the approval record shows it) and whether that was at the level the tier requires. The owner never approves their own document; when the tier's approver is the owner, the next level up approves. A document that people are told to follow without a recorded approval at the right level, or approved by its own owner, is counted in PM-02.
7Next review date is the approval date plus the tier's interval (PF-06). Days to review counts calendar days from the As-at date; it is negative once the date has passed. Review due soon appears when the review is within the notice period set on the Summary sheet (90 calendar days, the Policy Framework Standard's review notice): tell the owner to start. A review more than 30 calendar days overdue is escalated to executive management (Record check says so).
8When something happens that should bring a review forward, choose it in Review trigger and say what happened in Trigger details (PF-06). The five triggers are: a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses. Triggered review shows Review now until the review is done; then clear the trigger and record the new approval. A review that changes nothing is still recorded: enter the new approval date and say so in Notes.
9Record where the document is published (one place everyone who must follow it can reach) and whether the superseded version has been withdrawn and archived (PF-08). A Retired document is withdrawn: clear Where published.
10Clear every Record check that does not say OK. Each quarter, take the Summary's PM-01 and PM-02 to the quarterly report (PF-12), or paste this table into the Policy Health & Attestation Reporting Workbook.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The EXAMPLE is a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30. Its 10 rows are the same documents the Policy Attestation & Acknowledgement Tracker and the Policy Health & Attestation Reporting Workbook use. Two are past their review date (PM-01) and one is awaiting approval and not published, so PM-02 is zero.

Review due soon uses the review notice period on the Summary sheet: 90 calendar days, as the Policy Framework Standard sets it. It is long enough for drafting, consultation (PF-07) and approval before the review date. If your approved Standard sets a different notice, change it there.

Tailoring — small organisation: you may have a dozen documents and one person who writes most of them. Keep the register anyway: it is the evidence that each document has an owner, an approval and a review date. A single Executive Committee or the managing director can approve every policy; record who actually signed.

Tailoring — regulated entity (NIS2, DORA): policies are approved by the management body and the approval date is recorded on each ICT security policy (Delegated Regulation (EU) 2024/1774 Art 2(2)(b)). DORA Art 6(5) asks for the ICT risk management framework to be reviewed at least once a year and after major ICT-related incidents: set the Standard and Procedure review intervals on the Lists sheet to 12 months for documents that form part of that framework, and use the "major incident" trigger. Keep each quarter-end copy (As-at date frozen) as a record for supervisors.

Tailoring — IT run by a service provider: the provider's own procedures that carry out your policies belong in this register too, with a named owner in your organisation who obtains the current version and confirms its review. Record the provider's document reference in Notes.

Tiers, approvers and review intervals are read from the Lists sheet (Tier, TierApprover, TierReviewMonths). If your approved Policy Framework Standard sets different values, change them there and nowhere else.

Register

One row per security document, of every tier. Yellow columns are inputs; white columns calculate. Status colours always carry a text label.

ExampleDocument refTitleTierTopic (PT-nn)TopicOwnerApprover requiredVersionLifecycle statusApproval dateApproved byApproved at the tier's levelReview interval (months)Next review dateStatusDays to reviewReview due soonReview orderReview triggerTrigger detailsTriggered reviewWhere publishedSuperseded version archivedRecord checkNotes
EXAMPLEISP-001Information Security PolicyPolicyPT-01Information security policy (the top policy)Chief Operating OfficerExecutive management (the management body, or its delegate for the top policy)3.0Approved12 Mar 2026Executive Committee (without the Chief Operating Officer)Yes1212 Mar 2027Approved1635Intranet policy libraryYesOK
EXAMPLEAUP-001Acceptable Use PolicyPolicyPT-02Acceptable use of information and technologyHead of ITExecutive management (the management body, or its delegate for the top policy)2.1Approved1 Jul 2025Executive CommitteeYes121 Jul 2026Review overdue-911Intranet policy libraryYesReview overdue more than 30 days: escalate (PF-06, PM-01)Escalated to executive management on 2026-07-31, 30 days overdue. The owner started the review in September; the changes are material, so the next version is 3.0. Version 2.1 stays in force until 3.0 is approved.
EXAMPLEACP-001Access Control PolicyPolicyPT-03Access control and identityHead of ITExecutive management (the management body, or its delegate for the top policy)2.0Approved20 Jan 2026Executive CommitteeYes1220 Jan 2027Approved1123An audit or assessment finding against the documentInternal audit, September 2026: the policy does not cover emergency (break-glass) administrator accounts: who may use them, and how each use is reviewed.Review nowIntranet policy libraryYesTriggered review: review now (PF-06)Review brought forward by the audit finding; the owner is drafting the change to add emergency administrator accounts.
EXAMPLEINC-001Incident Management PolicyPolicyPT-05Incident managementHead of Information SecurityExecutive management (the management body, or its delegate for the top policy)1.2Approved4 May 2026Executive CommitteeYes124 May 2027Approved2166Intranet policy libraryYesOK
EXAMPLESUP-001Supplier Security PolicyPolicyPT-08Supplier and third-party securityHead of ProcurementExecutive management (the management body, or its delegate for the top policy)1.0Awaiting approval12Awaiting approvalNot applicable (first version)OKWith the Executive Committee for its October meeting. Not published until approved.
EXAMPLEVMS-001Vulnerability & Exposure Management StandardStandardPT-07Vulnerability and patch managementHead of Information SecurityHead of Information Security (the document owner is consulted)1.0Approved10 Sep 2026Executive CommitteeYes1210 Sep 2027Approved3457Intranet policy libraryNot applicable (first version)OK
EXAMPLEBKP-001Backup StandardStandardPT-06Backup and recoveryIT Operations ManagerHead of Information Security (the document owner is consulted)1.3Approved15 Aug 2025Head of Information SecurityYes1215 Aug 2026Review overdue-462Intranet policy libraryYesReview overdue more than 30 days: escalate (PF-06, PM-01)Escalated to executive management on 2026-09-14, 30 days overdue. The owner has not yet started the review.
EXAMPLEEXC-STDSecurity Exception & Waiver StandardStandardPT-15Security exceptions and waiversHead of Information SecurityHead of Information Security (the document owner is consulted)1.0Approved10 Sep 2026Executive CommitteeYes1210 Sep 2027Approved3458Intranet policy libraryNot applicable (first version)OK
EXAMPLEJML-PRCJoiner, Mover, Leaver ProcedureProcedurePT-14People security (joiners, movers, leavers, training)HR DirectorHead of Information Security (the process owner is consulted)2.2Approved3 Feb 2025Head of Information SecurityYes243 Feb 2027Approved1264Intranet policy libraryYesOK
EXAMPLERMT-GDLRemote Working GuidelineGuidelinePT-09Remote working and mobile devicesHead of ITInformation security1.1Approved18 Nov 2025Head of Information SecurityYes2418 Nov 2027Approved4149Intranet policy libraryYesOK

Summary

Register summary

Every figure is calculated from the Register as at the date shown. PM-01 and PM-02 are two of the four headline measures reported every quarter (PF-12); the other two come from the Policy Attestation & Acknowledgement Tracker.

As-at date30 Sep 2026EXAMPLE as-at date: replace with today's date, or type =TODAY()
Review notice: calendar days before the next review date90From the Policy Framework Standard. [[Change only if your Standard sets a different notice]]

Headline measures

MeasureResultTargetStatusWhat it means
PM-01 Documents past review date2Zero policies; no document more than 30 days overdueAction neededApproved documents whose next review date has passed. Each tier has a maximum review interval (PF-06).
of which policies10A policy past its review date is the most visible gap to an auditor or a supervisor.
longest past its review date (days)9130 or fewerCalendar days from the next review date to the As-at date, for the document furthest past it.
PM-02 Documents in force without approval0ZeroMetDocuments people are told to follow that have no recorded approval at the right level. Counted here: approved or published documents with no approval date, no approver recorded, an approval below the tier's level, or approval by the document's own owner (PF-03).

Documents by status and tier

StatusPolicyStandardProcedureGuidelineTotal
Draft00000
In consultation00000
Awaiting approval10001
Approved32117
Review overdue11002
Retired00000
All documents531110

Needs attention

MeasureResultTargetStatusWhat it means
Approved documents due for review soon0—Within 90 days of the As-at date. Start the review now so consultation and approval finish in time (PF-07).
Past the review date by more than 30 days20Action neededEscalate each one to [[e.g. Executive Committee, or the management body]] and name it in the quarterly report until the review is approved.
Triggered reviews not yet done10Action neededReview now, whatever the next review date says (PF-06).
Published before approval00MetWithdraw it, or get it approved at the tier's level (PF-03).
Approved but not published00MetNobody can follow a document they cannot find (PF-08).
Retired but still published00MetWithdraw and archive it (PF-08).
Superseded version not archived00MetOnly the current version may be available to follow (PF-08).
Rows with a record check to resolve30Action neededAny row whose Record check does not say OK. It shows the row's first problem only.

Quarterly register review

ItemEntry
Reviewed by[[Name, role]]
Review date[[YYYY-MM-DD]]
Documents past review, and the date each review will finish[[e.g. AUP-001: version 3.0 to executive management at its November meeting]]
Documents awaiting approval, and when they go to their approver[[e.g. SUP-001: Executive Committee, October meeting]]
Actions agreed, with owner and date[[Action — owner — date]]

Review Schedule

Review schedule — the next 12 months

Approved documents by the month their next review falls due, counted from the As-at date on the Summary sheet, and every document in force in review-date order. Calculated from the Register; do not type here.

Reviews due by month

MonthFromToPolicyStandardProcedureGuidelineTotalDocuments due
Already overdue29 Sep 202611002AUP-001, BKP-001
31 Oct 202630 Sep 202631 Oct 202600000—
30 Nov 20261 Nov 202630 Nov 202600000—
31 Dec 20261 Dec 202631 Dec 202600000—
31 Jan 20271 Jan 202731 Jan 202710001ACP-001
28 Feb 20271 Feb 202728 Feb 202700101JML-PRC
31 Mar 20271 Mar 202731 Mar 202710001ISP-001
30 Apr 20271 Apr 202730 Apr 202700000—
31 May 20271 May 202731 May 202710001INC-001
30 Jun 20271 Jun 202730 Jun 202700000—
31 Jul 20271 Jul 202731 Jul 202700000—
31 Aug 20271 Aug 202731 Aug 202700000—
30 Sep 20271 Sep 202730 Sep 202702002VMS-001, EXC-STD

The first month runs from the As-at date to that month's end. Documents due lists up to 6 refs per month, earliest first; the list below has them all.

Documents in force, in review-date order

No.Document refNext reviewDays to reviewTierStatusDue soonTriggerTitle — owner
1AUP-0011 Jul 2026-91PolicyReview overdueAcceptable Use Policy — Head of IT
2BKP-00115 Aug 2026-46StandardReview overdueBackup Standard — IT Operations Manager
3ACP-00120 Jan 2027112PolicyApprovedReview nowAccess Control Policy — Head of IT
4JML-PRC3 Feb 2027126ProcedureApprovedJoiner, Mover, Leaver Procedure — HR Director
5ISP-00112 Mar 2027163PolicyApprovedInformation Security Policy — Chief Operating Officer
6INC-0014 May 2027216PolicyApprovedIncident Management Policy — Head of Information Security
7VMS-00110 Sep 2027345StandardApprovedVulnerability & Exposure Management Standard — Head of Information Security
8EXC-STD10 Sep 2027345StandardApprovedSecurity Exception & Waiver Standard — Head of Information Security
9RMT-GDL18 Nov 2027414GuidelineApprovedRemote Working Guideline — Head of IT

Shows the first 25 documents in force. Days to review is negative for a document past its review date.

Lists

TierTierApproverTierReviewMonthsTopicIdTopicNameLifecycleStatusTriggerArchivedYesNo
PolicyExecutive management (the management body, or its delegate for the top policy)12PT-01Information security policy (the top policy)DraftA major incident, or an incident the document should have preventedYesYes
StandardHead of Information Security (the document owner is consulted)12PT-02Acceptable use of information and technologyIn consultationA material change to the organisation's activities, systems or suppliersNoNo
ProcedureHead of Information Security (the process owner is consulted)24PT-03Access control and identityAwaiting approvalA change in law, regulation or a contract the document supportsNot applicable (first version)
GuidelineInformation security24PT-04Asset management and information classificationApprovedAn audit or assessment finding against the document
PT-05Incident managementRetiredA significant change in the threats the document addresses
PT-06Backup and recovery
PT-07Vulnerability and patch management
PT-08Supplier and third-party security
PT-09Remote working and mobile devices
PT-10Cryptography and key management
PT-11Logging and monitoring
PT-12Secure development and change management
PT-13Physical and environmental security
PT-14People security (joiners, movers, leavers, training)
PT-15Security exceptions and waivers
PT-16Business continuity and ICT resilience
PT-17Information security risk management
PT-18Effectiveness assessment of security measures

Definitions

Definitions

TermMeaning in this workbook
Security documentAny policy, standard, procedure or guideline that tells people how information and systems are protected. All of them belong in this register (PF-11).
PolicyWhat the organisation commits to and why. Short, stable, written for everyone. Mandatory. Approved by executive management (the management body, or its delegate for the top policy); reviewed at least every 12 months.
StandardThe specific, measurable requirements that make a policy real: settings, deadlines, minimums. Mandatory. Approved by head of Information Security (the document owner is consulted); reviewed at least every 12 months.
ProcedureHow a task is done, step by step, by named roles. Mandatory. Approved by head of Information Security (the process owner is consulted); reviewed at least every 24 months.
GuidelineRecommended practice. Helpful, not mandatory; nobody is non-compliant for not following it. Not mandatory. Approved by information security; reviewed at least every 24 months.
Document refYour unique reference for the document, shown on the document itself. It stays the same through every version.
Topic (PT-nn)The policy topic the document covers, from the Security Policy Hierarchy & Document Map: PT-01 to PT-18.
OwnerThe one role or person accountable for the document's content and its review (PF-02). [[e.g. Head of IT for the access control policy]]
Approver requiredThe level that must approve a document of this tier before it is in force (PF-03), from the Lists sheet.
Approved at the tier's levelYes when the approval record shows the document was approved by the approver its tier requires, or above. No counts in PM-02. Nobody approves a document they own: an owner's own approval is flagged and counted in PM-02 too (PF-03).
Lifecycle statusThe status you enter: Draft, In consultation, Awaiting approval, Approved, Retired. Review overdue is never entered; it is calculated.
Status: DraftBeing written; not in force.
Status: In consultationCirculated for comment to the people it affects (PF-07).
Status: Awaiting approvalFinal text with the approver for its tier (PF-03).
Status: ApprovedIn force: approved, published, and within its review date.
Status: Review overdueIn force, but past its next review date (PF-06).
Status: RetiredWithdrawn and archived; no longer in force (PF-08).
Next review dateThe approval date plus the tier's maximum review interval, in months (PF-06). A trigger brings the review forward.
Days to reviewCalendar days from the As-at date to the next review date; negative once it has passed.
Review due soonAn approved document whose next review is within the review notice period set on the Summary sheet (90 calendar days in the Policy Framework Standard). The owner is told to start the review.
EscalationA review more than 30 calendar days overdue is escalated to executive management and named in every quarterly report until it is approved (PF-06, PF-12).
Review orderThe document's place when every document in force is sorted by next review date, earliest first. Used by the Review Schedule.
Review triggerAn event that forces a review before the scheduled date (PF-06): a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses.
Where publishedThe one place where everyone who must follow the document can reach the current approved version (PF-08).
Superseded version archivedWhether the previous version was withdrawn from where people find it and kept in the archive (PF-08). Not applicable to a first version.
Record checkA calculated prompt showing the row's first missing or inconsistent item. OK means nothing is outstanding.
As-at dateThe date every status and countdown is measured against. Set on the Summary sheet.
PM-01 Documents past review dateApproved documents whose next review date has passed. Target: zero policies; no document more than 30 days overdue.
PM-02 Documents in force without approvalDocuments people are told to follow that have no recorded approval at the right level. Target: zero.
PF-nnRule numbers in the Policy Framework Standard. PM-nn are its headline measures; PT-nn its policy topics.
EXAMPLE rowA worked example: the example organisation's documents as at 2026-09-30. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 7.5.3 — Control of documented informationThe register as a whole: each document identified, versioned, approved, published where it is needed and its superseded versions withdrawn
ISO/IEC 27001:2022Annex A 5.1 — Policies for information securityPolicies approved by management, published and reviewed at planned intervals and on significant change: Approval, Next review date, Review trigger
NIST CSF 2.0GV.PO-02 — “Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission”Next review date, Review trigger and the Review Schedule: policy reviewed and updated as requirements, threats and the organisation change
DORA — Regulation (EU) 2022/2554Article 6(5) — the ICT risk management framework is documented and reviewed at least once a year, and after major ICT-related incidentsReview intervals and the major-incident trigger; regulated-entity tailoring note
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(b) — ICT security policies indicate the date of their formal approval by the management bodyApproval date and Approved by for each policy
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(j) — policies are reviewed in accordance with DORA Article 6(5)Next review date and Status: policies reviewed in line with DORA Art 6(5)

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774