Policy Register & Review Schedule
Maintains the authoritative inventory of security documents with owner, approval status, version and next review date.
Available soon
- Format
- Excel
- Size
- 104 KB
- Length
- 10 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Register
- Summary
- Review Schedule
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30; replace it with today's date, or type =TODAY() to keep it current. Every status, countdown and flag is measured against this date. Freeze it at a fixed date when you keep a quarter-end copy. |
| 2 | Delete the EXAMPLE rows on the Register sheet before you enter your own documents. Do not type over the white calculated columns. |
| 3 | Add one row per security document, of every tier, and nothing else (PF-11). Give it a unique Document ref (for example ACP-001) that never changes and appears on the document itself. Choose its Tier (PF-01) and its Topic (PT-01 to PT-18, as in the Security Policy Hierarchy & Document Map), and name one Owner: a role or a person who is accountable for its content and its review (PF-02). |
| 4 | Approver required fills in from the tier (PF-03). Policy: approved by executive management (the management body, or its delegate for the top policy); reviewed at least every 12 months. Standard: approved by head of Information Security (the document owner is consulted); reviewed at least every 12 months. Procedure: approved by head of Information Security (the process owner is consulted); reviewed at least every 24 months. Guideline: approved by information security; reviewed at least every 24 months. The review intervals are the latest a review may happen; a trigger brings it forward. |
| 5 | Record the version in force and its Lifecycle status (Draft, In consultation, Awaiting approval, Approved, Retired). Never type Review overdue: the register shows it when an approved document passes its next review date. The register shows the status of the version in force while a revision is prepared; Draft, In consultation and Awaiting approval apply only to a document with no version in force. Keep the row on the version in force and note the revision's stage in Notes; when the revision is approved, change Version, Approval date and Approved by. |
| 6 | For an approved document, enter the Approval date, who approved it (the body or person, as the approval record shows it) and whether that was at the level the tier requires. The owner never approves their own document; when the tier's approver is the owner, the next level up approves. A document that people are told to follow without a recorded approval at the right level, or approved by its own owner, is counted in PM-02. |
| 7 | Next review date is the approval date plus the tier's interval (PF-06). Days to review counts calendar days from the As-at date; it is negative once the date has passed. Review due soon appears when the review is within the notice period set on the Summary sheet (90 calendar days, the Policy Framework Standard's review notice): tell the owner to start. A review more than 30 calendar days overdue is escalated to executive management (Record check says so). |
| 8 | When something happens that should bring a review forward, choose it in Review trigger and say what happened in Trigger details (PF-06). The five triggers are: a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses. Triggered review shows Review now until the review is done; then clear the trigger and record the new approval. A review that changes nothing is still recorded: enter the new approval date and say so in Notes. |
| 9 | Record where the document is published (one place everyone who must follow it can reach) and whether the superseded version has been withdrawn and archived (PF-08). A Retired document is withdrawn: clear Where published. |
| 10 | Clear every Record check that does not say OK. Each quarter, take the Summary's PM-01 and PM-02 to the quarterly report (PF-12), or paste this table into the Policy Health & Attestation Reporting Workbook. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The EXAMPLE is a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30. Its 10 rows are the same documents the Policy Attestation & Acknowledgement Tracker and the Policy Health & Attestation Reporting Workbook use. Two are past their review date (PM-01) and one is awaiting approval and not published, so PM-02 is zero.
Review due soon uses the review notice period on the Summary sheet: 90 calendar days, as the Policy Framework Standard sets it. It is long enough for drafting, consultation (PF-07) and approval before the review date. If your approved Standard sets a different notice, change it there.
Tailoring — small organisation: you may have a dozen documents and one person who writes most of them. Keep the register anyway: it is the evidence that each document has an owner, an approval and a review date. A single Executive Committee or the managing director can approve every policy; record who actually signed.
Tailoring — regulated entity (NIS2, DORA): policies are approved by the management body and the approval date is recorded on each ICT security policy (Delegated Regulation (EU) 2024/1774 Art 2(2)(b)). DORA Art 6(5) asks for the ICT risk management framework to be reviewed at least once a year and after major ICT-related incidents: set the Standard and Procedure review intervals on the Lists sheet to 12 months for documents that form part of that framework, and use the "major incident" trigger. Keep each quarter-end copy (As-at date frozen) as a record for supervisors.
Tailoring — IT run by a service provider: the provider's own procedures that carry out your policies belong in this register too, with a named owner in your organisation who obtains the current version and confirms its review. Record the provider's document reference in Notes.
Tiers, approvers and review intervals are read from the Lists sheet (Tier, TierApprover, TierReviewMonths). If your approved Policy Framework Standard sets different values, change them there and nowhere else.
Register
One row per security document, of every tier. Yellow columns are inputs; white columns calculate. Status colours always carry a text label.
| Example | Document ref | Title | Tier | Topic (PT-nn) | Topic | Owner | Approver required | Version | Lifecycle status | Approval date | Approved by | Approved at the tier's level | Review interval (months) | Next review date | Status | Days to review | Review due soon | Review order | Review trigger | Trigger details | Triggered review | Where published | Superseded version archived | Record check | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | ISP-001 | Information Security Policy | Policy | PT-01 | Information security policy (the top policy) | Chief Operating Officer | Executive management (the management body, or its delegate for the top policy) | 3.0 | Approved | 12 Mar 2026 | Executive Committee (without the Chief Operating Officer) | Yes | 12 | 12 Mar 2027 | Approved | 163 | 5 | Intranet policy library | Yes | OK | |||||
| EXAMPLE | AUP-001 | Acceptable Use Policy | Policy | PT-02 | Acceptable use of information and technology | Head of IT | Executive management (the management body, or its delegate for the top policy) | 2.1 | Approved | 1 Jul 2025 | Executive Committee | Yes | 12 | 1 Jul 2026 | Review overdue | -91 | 1 | Intranet policy library | Yes | Review overdue more than 30 days: escalate (PF-06, PM-01) | Escalated to executive management on 2026-07-31, 30 days overdue. The owner started the review in September; the changes are material, so the next version is 3.0. Version 2.1 stays in force until 3.0 is approved. | ||||
| EXAMPLE | ACP-001 | Access Control Policy | Policy | PT-03 | Access control and identity | Head of IT | Executive management (the management body, or its delegate for the top policy) | 2.0 | Approved | 20 Jan 2026 | Executive Committee | Yes | 12 | 20 Jan 2027 | Approved | 112 | 3 | An audit or assessment finding against the document | Internal audit, September 2026: the policy does not cover emergency (break-glass) administrator accounts: who may use them, and how each use is reviewed. | Review now | Intranet policy library | Yes | Triggered review: review now (PF-06) | Review brought forward by the audit finding; the owner is drafting the change to add emergency administrator accounts. | |
| EXAMPLE | INC-001 | Incident Management Policy | Policy | PT-05 | Incident management | Head of Information Security | Executive management (the management body, or its delegate for the top policy) | 1.2 | Approved | 4 May 2026 | Executive Committee | Yes | 12 | 4 May 2027 | Approved | 216 | 6 | Intranet policy library | Yes | OK | |||||
| EXAMPLE | SUP-001 | Supplier Security Policy | Policy | PT-08 | Supplier and third-party security | Head of Procurement | Executive management (the management body, or its delegate for the top policy) | 1.0 | Awaiting approval | 12 | Awaiting approval | Not applicable (first version) | OK | With the Executive Committee for its October meeting. Not published until approved. | |||||||||||
| EXAMPLE | VMS-001 | Vulnerability & Exposure Management Standard | Standard | PT-07 | Vulnerability and patch management | Head of Information Security | Head of Information Security (the document owner is consulted) | 1.0 | Approved | 10 Sep 2026 | Executive Committee | Yes | 12 | 10 Sep 2027 | Approved | 345 | 7 | Intranet policy library | Not applicable (first version) | OK | |||||
| EXAMPLE | BKP-001 | Backup Standard | Standard | PT-06 | Backup and recovery | IT Operations Manager | Head of Information Security (the document owner is consulted) | 1.3 | Approved | 15 Aug 2025 | Head of Information Security | Yes | 12 | 15 Aug 2026 | Review overdue | -46 | 2 | Intranet policy library | Yes | Review overdue more than 30 days: escalate (PF-06, PM-01) | Escalated to executive management on 2026-09-14, 30 days overdue. The owner has not yet started the review. | ||||
| EXAMPLE | EXC-STD | Security Exception & Waiver Standard | Standard | PT-15 | Security exceptions and waivers | Head of Information Security | Head of Information Security (the document owner is consulted) | 1.0 | Approved | 10 Sep 2026 | Executive Committee | Yes | 12 | 10 Sep 2027 | Approved | 345 | 8 | Intranet policy library | Not applicable (first version) | OK | |||||
| EXAMPLE | JML-PRC | Joiner, Mover, Leaver Procedure | Procedure | PT-14 | People security (joiners, movers, leavers, training) | HR Director | Head of Information Security (the process owner is consulted) | 2.2 | Approved | 3 Feb 2025 | Head of Information Security | Yes | 24 | 3 Feb 2027 | Approved | 126 | 4 | Intranet policy library | Yes | OK | |||||
| EXAMPLE | RMT-GDL | Remote Working Guideline | Guideline | PT-09 | Remote working and mobile devices | Head of IT | Information security | 1.1 | Approved | 18 Nov 2025 | Head of Information Security | Yes | 24 | 18 Nov 2027 | Approved | 414 | 9 | Intranet policy library | Yes | OK |
Summary
Register summary
Every figure is calculated from the Register as at the date shown. PM-01 and PM-02 are two of the four headline measures reported every quarter (PF-12); the other two come from the Policy Attestation & Acknowledgement Tracker.
| As-at date | 30 Sep 2026 | EXAMPLE as-at date: replace with today's date, or type =TODAY() |
| Review notice: calendar days before the next review date | 90 | From the Policy Framework Standard. [[Change only if your Standard sets a different notice]] |
Headline measures
| Measure | Result | Target | Status | What it means | |||
|---|---|---|---|---|---|---|---|
| PM-01 Documents past review date | 2 | Zero policies; no document more than 30 days overdue | Action needed | Approved documents whose next review date has passed. Each tier has a maximum review interval (PF-06). | |||
| of which policies | 1 | 0 | A policy past its review date is the most visible gap to an auditor or a supervisor. | ||||
| longest past its review date (days) | 91 | 30 or fewer | Calendar days from the next review date to the As-at date, for the document furthest past it. | ||||
| PM-02 Documents in force without approval | 0 | Zero | Met | Documents people are told to follow that have no recorded approval at the right level. Counted here: approved or published documents with no approval date, no approver recorded, an approval below the tier's level, or approval by the document's own owner (PF-03). | |||
Documents by status and tier
| Status | Policy | Standard | Procedure | Guideline | Total |
|---|---|---|---|---|---|
| Draft | 0 | 0 | 0 | 0 | 0 |
| In consultation | 0 | 0 | 0 | 0 | 0 |
| Awaiting approval | 1 | 0 | 0 | 0 | 1 |
| Approved | 3 | 2 | 1 | 1 | 7 |
| Review overdue | 1 | 1 | 0 | 0 | 2 |
| Retired | 0 | 0 | 0 | 0 | 0 |
| All documents | 5 | 3 | 1 | 1 | 10 |
Needs attention
| Measure | Result | Target | Status | What it means | |||
|---|---|---|---|---|---|---|---|
| Approved documents due for review soon | 0 | — | Within 90 days of the As-at date. Start the review now so consultation and approval finish in time (PF-07). | ||||
| Past the review date by more than 30 days | 2 | 0 | Action needed | Escalate each one to [[e.g. Executive Committee, or the management body]] and name it in the quarterly report until the review is approved. | |||
| Triggered reviews not yet done | 1 | 0 | Action needed | Review now, whatever the next review date says (PF-06). | |||
| Published before approval | 0 | 0 | Met | Withdraw it, or get it approved at the tier's level (PF-03). | |||
| Approved but not published | 0 | 0 | Met | Nobody can follow a document they cannot find (PF-08). | |||
| Retired but still published | 0 | 0 | Met | Withdraw and archive it (PF-08). | |||
| Superseded version not archived | 0 | 0 | Met | Only the current version may be available to follow (PF-08). | |||
| Rows with a record check to resolve | 3 | 0 | Action needed | Any row whose Record check does not say OK. It shows the row's first problem only. | |||
Quarterly register review
| Item | Entry | ||||||
|---|---|---|---|---|---|---|---|
| Reviewed by | [[Name, role]] | ||||||
| Review date | [[YYYY-MM-DD]] | ||||||
| Documents past review, and the date each review will finish | [[e.g. AUP-001: version 3.0 to executive management at its November meeting]] | ||||||
| Documents awaiting approval, and when they go to their approver | [[e.g. SUP-001: Executive Committee, October meeting]] | ||||||
| Actions agreed, with owner and date | [[Action — owner — date]] | ||||||
Review Schedule
Review schedule — the next 12 months
Approved documents by the month their next review falls due, counted from the As-at date on the Summary sheet, and every document in force in review-date order. Calculated from the Register; do not type here.
Reviews due by month
| Month | From | To | Policy | Standard | Procedure | Guideline | Total | Documents due |
|---|---|---|---|---|---|---|---|---|
| Already overdue | 29 Sep 2026 | 1 | 1 | 0 | 0 | 2 | AUP-001, BKP-001 | |
| 31 Oct 2026 | 30 Sep 2026 | 31 Oct 2026 | 0 | 0 | 0 | 0 | 0 | — |
| 30 Nov 2026 | 1 Nov 2026 | 30 Nov 2026 | 0 | 0 | 0 | 0 | 0 | — |
| 31 Dec 2026 | 1 Dec 2026 | 31 Dec 2026 | 0 | 0 | 0 | 0 | 0 | — |
| 31 Jan 2027 | 1 Jan 2027 | 31 Jan 2027 | 1 | 0 | 0 | 0 | 1 | ACP-001 |
| 28 Feb 2027 | 1 Feb 2027 | 28 Feb 2027 | 0 | 0 | 1 | 0 | 1 | JML-PRC |
| 31 Mar 2027 | 1 Mar 2027 | 31 Mar 2027 | 1 | 0 | 0 | 0 | 1 | ISP-001 |
| 30 Apr 2027 | 1 Apr 2027 | 30 Apr 2027 | 0 | 0 | 0 | 0 | 0 | — |
| 31 May 2027 | 1 May 2027 | 31 May 2027 | 1 | 0 | 0 | 0 | 1 | INC-001 |
| 30 Jun 2027 | 1 Jun 2027 | 30 Jun 2027 | 0 | 0 | 0 | 0 | 0 | — |
| 31 Jul 2027 | 1 Jul 2027 | 31 Jul 2027 | 0 | 0 | 0 | 0 | 0 | — |
| 31 Aug 2027 | 1 Aug 2027 | 31 Aug 2027 | 0 | 0 | 0 | 0 | 0 | — |
| 30 Sep 2027 | 1 Sep 2027 | 30 Sep 2027 | 0 | 2 | 0 | 0 | 2 | VMS-001, EXC-STD |
The first month runs from the As-at date to that month's end. Documents due lists up to 6 refs per month, earliest first; the list below has them all.
Documents in force, in review-date order
| No. | Document ref | Next review | Days to review | Tier | Status | Due soon | Trigger | Title — owner |
|---|---|---|---|---|---|---|---|---|
| 1 | AUP-001 | 1 Jul 2026 | -91 | Policy | Review overdue | Acceptable Use Policy — Head of IT | ||
| 2 | BKP-001 | 15 Aug 2026 | -46 | Standard | Review overdue | Backup Standard — IT Operations Manager | ||
| 3 | ACP-001 | 20 Jan 2027 | 112 | Policy | Approved | Review now | Access Control Policy — Head of IT | |
| 4 | JML-PRC | 3 Feb 2027 | 126 | Procedure | Approved | Joiner, Mover, Leaver Procedure — HR Director | ||
| 5 | ISP-001 | 12 Mar 2027 | 163 | Policy | Approved | Information Security Policy — Chief Operating Officer | ||
| 6 | INC-001 | 4 May 2027 | 216 | Policy | Approved | Incident Management Policy — Head of Information Security | ||
| 7 | VMS-001 | 10 Sep 2027 | 345 | Standard | Approved | Vulnerability & Exposure Management Standard — Head of Information Security | ||
| 8 | EXC-STD | 10 Sep 2027 | 345 | Standard | Approved | Security Exception & Waiver Standard — Head of Information Security | ||
| 9 | RMT-GDL | 18 Nov 2027 | 414 | Guideline | Approved | Remote Working Guideline — Head of IT |
Shows the first 25 documents in force. Days to review is negative for a document past its review date.
Lists
| Tier | TierApprover | TierReviewMonths | TopicId | TopicName | LifecycleStatus | Trigger | Archived | YesNo |
|---|---|---|---|---|---|---|---|---|
| Policy | Executive management (the management body, or its delegate for the top policy) | 12 | PT-01 | Information security policy (the top policy) | Draft | A major incident, or an incident the document should have prevented | Yes | Yes |
| Standard | Head of Information Security (the document owner is consulted) | 12 | PT-02 | Acceptable use of information and technology | In consultation | A material change to the organisation's activities, systems or suppliers | No | No |
| Procedure | Head of Information Security (the process owner is consulted) | 24 | PT-03 | Access control and identity | Awaiting approval | A change in law, regulation or a contract the document supports | Not applicable (first version) | |
| Guideline | Information security | 24 | PT-04 | Asset management and information classification | Approved | An audit or assessment finding against the document | ||
| PT-05 | Incident management | Retired | A significant change in the threats the document addresses | |||||
| PT-06 | Backup and recovery | |||||||
| PT-07 | Vulnerability and patch management | |||||||
| PT-08 | Supplier and third-party security | |||||||
| PT-09 | Remote working and mobile devices | |||||||
| PT-10 | Cryptography and key management | |||||||
| PT-11 | Logging and monitoring | |||||||
| PT-12 | Secure development and change management | |||||||
| PT-13 | Physical and environmental security | |||||||
| PT-14 | People security (joiners, movers, leavers, training) | |||||||
| PT-15 | Security exceptions and waivers | |||||||
| PT-16 | Business continuity and ICT resilience | |||||||
| PT-17 | Information security risk management | |||||||
| PT-18 | Effectiveness assessment of security measures |
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Security document | Any policy, standard, procedure or guideline that tells people how information and systems are protected. All of them belong in this register (PF-11). |
| Policy | What the organisation commits to and why. Short, stable, written for everyone. Mandatory. Approved by executive management (the management body, or its delegate for the top policy); reviewed at least every 12 months. |
| Standard | The specific, measurable requirements that make a policy real: settings, deadlines, minimums. Mandatory. Approved by head of Information Security (the document owner is consulted); reviewed at least every 12 months. |
| Procedure | How a task is done, step by step, by named roles. Mandatory. Approved by head of Information Security (the process owner is consulted); reviewed at least every 24 months. |
| Guideline | Recommended practice. Helpful, not mandatory; nobody is non-compliant for not following it. Not mandatory. Approved by information security; reviewed at least every 24 months. |
| Document ref | Your unique reference for the document, shown on the document itself. It stays the same through every version. |
| Topic (PT-nn) | The policy topic the document covers, from the Security Policy Hierarchy & Document Map: PT-01 to PT-18. |
| Owner | The one role or person accountable for the document's content and its review (PF-02). [[e.g. Head of IT for the access control policy]] |
| Approver required | The level that must approve a document of this tier before it is in force (PF-03), from the Lists sheet. |
| Approved at the tier's level | Yes when the approval record shows the document was approved by the approver its tier requires, or above. No counts in PM-02. Nobody approves a document they own: an owner's own approval is flagged and counted in PM-02 too (PF-03). |
| Lifecycle status | The status you enter: Draft, In consultation, Awaiting approval, Approved, Retired. Review overdue is never entered; it is calculated. |
| Status: Draft | Being written; not in force. |
| Status: In consultation | Circulated for comment to the people it affects (PF-07). |
| Status: Awaiting approval | Final text with the approver for its tier (PF-03). |
| Status: Approved | In force: approved, published, and within its review date. |
| Status: Review overdue | In force, but past its next review date (PF-06). |
| Status: Retired | Withdrawn and archived; no longer in force (PF-08). |
| Next review date | The approval date plus the tier's maximum review interval, in months (PF-06). A trigger brings the review forward. |
| Days to review | Calendar days from the As-at date to the next review date; negative once it has passed. |
| Review due soon | An approved document whose next review is within the review notice period set on the Summary sheet (90 calendar days in the Policy Framework Standard). The owner is told to start the review. |
| Escalation | A review more than 30 calendar days overdue is escalated to executive management and named in every quarterly report until it is approved (PF-06, PF-12). |
| Review order | The document's place when every document in force is sorted by next review date, earliest first. Used by the Review Schedule. |
| Review trigger | An event that forces a review before the scheduled date (PF-06): a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses. |
| Where published | The one place where everyone who must follow the document can reach the current approved version (PF-08). |
| Superseded version archived | Whether the previous version was withdrawn from where people find it and kept in the archive (PF-08). Not applicable to a first version. |
| Record check | A calculated prompt showing the row's first missing or inconsistent item. OK means nothing is outstanding. |
| As-at date | The date every status and countdown is measured against. Set on the Summary sheet. |
| PM-01 Documents past review date | Approved documents whose next review date has passed. Target: zero policies; no document more than 30 days overdue. |
| PM-02 Documents in force without approval | Documents people are told to follow that have no recorded approval at the right level. Target: zero. |
| PF-nn | Rule numbers in the Policy Framework Standard. PM-nn are its headline measures; PT-nn its policy topics. |
| EXAMPLE row | A worked example: the example organisation's documents as at 2026-09-30. Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 7.5.3 — Control of documented information | The register as a whole: each document identified, versioned, approved, published where it is needed and its superseded versions withdrawn |
| ISO/IEC 27001:2022 | Annex A 5.1 — Policies for information security | Policies approved by management, published and reviewed at planned intervals and on significant change: Approval, Next review date, Review trigger |
| NIST CSF 2.0 | GV.PO-02 — “Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission” | Next review date, Review trigger and the Review Schedule: policy reviewed and updated as requirements, threats and the organisation change |
| DORA — Regulation (EU) 2022/2554 | Article 6(5) — the ICT risk management framework is documented and reviewed at least once a year, and after major ICT-related incidents | Review intervals and the major-incident trigger; regulated-entity tailoring note |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(b) — ICT security policies indicate the date of their formal approval by the management body | Approval date and Approved by for each policy |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(j) — policies are reviewed in accordance with DORA Article 6(5) | Next review date and Status: policies reviewed in line with DORA Art 6(5) |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774