- Documentation
- Run your ISMS
- Document governance
Guides and standards
Tier three: practical instruction and technical advice, why none ships, and the mistake that turns advice into an obligation.
Audience: ISMS Admin.
Where: SharePoint holds the files. The Certaria app holds the records.
A guide advises. It does not oblige
Section titled “A guide advises. It does not oblige”A guide gives practical instruction and technical advice. Its readers are the people doing the work: end users who need to know how something is done safely, and administrators who need the technical detail behind it.
The document that belongs here is the one answering “how do I actually do this”. How to work securely away from the office. How to set up a phone for work use. It is written to be useful at the moment somebody needs it. A policy states the rule, a procedure sets out the workflow that meets it, and a guide helps a person get it right.
Nothing ships on this tier, and the list starts empty
Section titled “Nothing ships on this tier, and the list starts empty”No guides ship with Certaria. The Guides entry under Document Governance opens an empty list on every install, and it stays empty until you create something. That is normal on a new install rather than a fault.
It is also deliberate. A guide is specific to how your organisation actually works: which devices your people carry, which tools they use, where the work happens. A generic one would be advice about nobody.
Advice filed among your rules fails twice over
Section titled “Advice filed among your rules fails twice over”Mixing informal guidance into a list of binding rules costs you twice. Your people treat a suggestion as a requirement. And an auditor sampling “your policies” is handed something nobody ever approved as one, which puts a question mark over the whole list rather than over that document alone.
That is why this tier has a list of its own rather than sitting among the policies.
Creating a guide takes one step the tiers with templates do not
Section titled “Creating a guide takes one step the tiers with templates do not”A guide is created and published exactly as a policy is. The file goes into the policy library, Certaria creates the record as Draft, and you approve it. Publish a document has those steps, and this page does not repeat them.
One thing needs correcting afterwards, on this tier and on Plans, and on neither of the other two. Those are the two tiers no templates ship for. When Certaria registers a new file it takes the category from the shipped template that file matches. No guide templates ship, so no template ever matches, and Certaria falls back to Policy. Change the Category on the document record to Guide.
Nothing fails if you do not, and nothing is reported. The document publishes correctly and asks for confirmation correctly, because Policy is one of the four categories the publishing automation accepts. The only symptom is where it lands: the document sits in the Policies list, and the Guides list stays empty however many guides you write.
That is the mistake described above, arriving by default. Left as it is registered, a guide is filed among your binding rules and read as one.
An auditor asks whether a guide is used, not whether it was approved
Section titled “An auditor asks whether a guide is used, not whether it was approved”The questions on this tier are about usability, training and adoption. Approval is not the test.
That is the third distinct answer in three tiers. A policy is tested on its approval and its review. A procedure is tested on its execution. A guide is tested on whether it is genuinely usable, and on whether anybody has been shown it. A guide nobody has been shown is a guide nobody uses, and that is what is being sampled for.
Your people are asked to confirm a guide exactly as they confirm a policy
Section titled “Your people are asked to confirm a guide exactly as they confirm a policy”Publishing a guide reaches everybody, exactly as publishing a policy does: the same list, the same confirmation, the same reminders.
There is a tension worth naming. You are asking somebody to confirm they have read and understood a document that is advice rather than obligation, so word it so it reads as help. A guide worded like a rule collects confirmations that look, at audit, like acknowledgement of a requirement you never approved as one.
Your people read it from the Published Documents list on your SharePoint site and confirm it on the Certaria card in Microsoft Teams. They never open the Certaria app, and they need no Power Platform licence.
This tier has no part of the lifecycle to itself
Section titled “This tier has no part of the lifecycle to itself”Beyond the category correction above, publication, revision and review are identical for a guide and a policy.
- Adopt a template: the shipped catalogue and the applicability decision behind each one. It has the least to say for this tier, because there are no guide templates to adopt.
- Publish a document: the record, the approval, and confirming it reached your people.
- Revise a document: change a guide that is already in force, without withdrawing it while you work.
- The annual review cycle: the prompt, and what counts as the record that a review happened.
Related
Section titled “Related”- Document governance compares all four tiers on one screen.
- Policies is the tier this one is most easily confused with, and the list a guide lands in if its category is left alone.
- Procedures is the tier directly above.
- What Certaria asks of you is the page to send your people, and describes the confirmation they are asked for.