- Documentation
- Run your ISMS
- Document governance
Plans
Tier four: frameworks for responding to a named event, and the only tier an auditor expects you to have rehearsed.
Audience: ISMS Admin.
Where: SharePoint holds the files. The Certaria app holds the records.
A plan is read on the worst day, not on an ordinary one
Section titled “A plan is read on the worst day, not on an ordinary one”A plan is a framework for responding to a named event, read under pressure by your incident and recovery teams. Most organisations end up with three: incident response, business continuity, and disaster recovery. You reach for it once the ordinary arrangements have stopped working.
The document is not the evidence on this tier
Section titled “The document is not the evidence on this tier”Controls A.5.24 to A.5.30 cover incident readiness, continuity and recovery, and they expect these plans to have been rehearsed.
An auditor here does not ask to read the plan. They ask for the test schedule and the results. A continuity plan nobody has exercised answers neither question, because the point of an exercise is to find what the document got wrong while that is still cheap.
A plan filed among your policies is a plan nobody scheduled a test for, and the test is the thing you are asked about.
No plans ship, and the list opens empty
Section titled “No plans ship, and the list opens empty”The Plans entry under Document Governance opens an empty list on every install and stays empty until you write something, which is normal rather than a fault.
It is also deliberate. A plan is worthless unless it names your people, your systems and who somebody calls at two in the morning. A generic one would look like preparation without being any.
Creating a plan takes one step the tiers with templates do not
Section titled “Creating a plan takes one step the tiers with templates do not”A plan is created and published exactly as a policy is. Publish a document has the steps.
One thing needs correcting afterwards, on this tier and on Guides and standards, and on neither of the other two. Those are the two tiers no templates ship for. Certaria takes a new file’s category from the shipped template it matches. No plan templates ship, so nothing ever matches and Certaria falls back to Policy. Change the Category on the document record to Plan.
Nothing fails if you do not, and nothing is reported: Policy is one of the four categories the publishing automation accepts, so the plan publishes and asks for confirmation correctly. The only symptom is where it lands: it sits in the Policies list, the Plans list stays empty, and the failure named above has arrived by default.
The document record carries approval and review, not rehearsal
Section titled “The document record carries approval and review, not rehearsal”The record holds the plan’s title, version, owner, ISO 27001 clause, approval and review date. There is no field on it for an exercise, a test date or a result. The review date drives the annual document review, which asks whether the plan still stands, not whether anybody has run it.
The schedule and the results live elsewhere, in two places you already have:
- Schedule the exercise as recurring work. A task template creates it on its cycle, and the reminders chase it once it has an owner and a due date. See Tasks and deadlines.
- A real event exercises the plan for you. An incident taken through its Review stage opens a corrective action, which records what the plan met and what you changed. See Incidents and concerns.
An auditor asks when you last rehearsed it, and what happened
Section titled “An auditor asks when you last rehearsed it, and what happened”Four tiers, four different questions. A policy is tested on its approval and review. A procedure on its execution. A guide on whether it is usable and whether anybody has seen it. A plan on whether it has been rehearsed.
Your people are asked to confirm a plan exactly as they confirm a policy
Section titled “Your people are asked to confirm a plan exactly as they confirm a policy”Publishing a plan reaches everybody: the same list, the same confirmation, the same reminders.
Confirming you have read the incident response plan is not the same as having practised it, and only one of those is what A.5.24 to A.5.30 ask about. The acknowledgement register is evidence that your people know the plan exists, not that it works.
Your people read it from the Published Documents list on your SharePoint site and confirm it on the Certaria card in Microsoft Teams. They never open the Certaria app, and they need no Power Platform licence.
This tier has no part of the lifecycle to itself
Section titled “This tier has no part of the lifecycle to itself”Beyond the category correction, the lifecycle is identical for a plan and a policy.
- Adopt a template: nothing to offer here, because no plan templates ship.
- Publish a document: the record, the approval, and confirming it reached your people.
- Revise a document: change a plan already in force. An exercise that found a gap is the commonest reason to.
- The annual review cycle: the prompt, and what counts as the record of a review.
Related
Section titled “Related”- Document governance compares all four tiers on one screen.
- Policies is the list a plan lands in if its category is left alone.
- Procedures and Guides and standards are the other two tiers.
- Incidents and concerns records a real event, and Tasks and deadlines schedules a recurring exercise.