- Documentation
- Run your ISMS
- Document governance
Policies
Tier one: management intent and the rules everyone must follow, and the two questions an auditor asks about every one of them.
Audience: ISMS Admin.
Where: SharePoint holds the files. The Certaria app holds the records.
A policy binds. It does not explain how the work is done
Section titled “A policy binds. It does not explain how the work is done”A policy states management intent and the rules everyone must follow. Its audience is the whole organisation without exception, from the newest starter to the board, and there is no group of people a policy quietly does not reach.
That is what separates this tier from the other three. A policy says what must be true. It does not set out the steps by which somebody makes it true, which is a procedure’s job. A useful test is whether the document would still stand if you replaced your tooling tomorrow. If it names a system, a screen, or a sequence of steps, you are looking at a procedure wearing a policy’s title, and it will be tested against the wrong question at audit.
Twenty-one of the thirty-four templates Certaria ships are policies
Section titled “Twenty-one of the thirty-four templates Certaria ships are policies”They live in the Certaria app as templates, awaiting two things from you: an applicability decision about whether the control applies to you at all, and personalisation once you adopt it. A template is never in force and never publishes.
Each filename carries its primary Annex A reference as a prefix, so your library sorts in the order an ISO 27001 auditor works through rather than alphabetically by title.
Adopt a template is the catalogue and the steps. This page does not repeat them.
An auditor asks two questions about a policy, and only two
Section titled “An auditor asks two questions about a policy, and only two”Was it approved by leadership, and has it been reviewed this year. Almost everything else you do on this tier exists to be able to answer those two.
Approval is a management act, so the record has to name a person and a date. ISO 27001:2022 Clause 5.2 places the information security policy on top management, and A.5.1 expects policies to be approved by management, communicated, and reviewed at planned intervals. A document sitting in a library evidences none of that on its own. When you set a document to Approved, Certaria stamps the Approved Date and records the account that did it as the Approver. That is what turns “we have an access control policy” into “our access control policy was approved by a named person on a named date”, which is the form the question is actually asked in.
A yearly review that changes nothing is still a review, and is still evidence. The commonest mistake on this tier is treating the review as busywork when the policy has not moved. What an auditor wants is proof that you looked and the date you looked, not a redraft. Recording the review does not change the document and does not ask your organisation to confirm it again.
The app holds the list. Your people never open it
Section titled “The app holds the list. Your people never open it”The Policies entry under Document Governance in the Certaria app opens the document list filtered to this tier, so what you see there is every policy and nothing that is not one. Acknowledgements sits directly beneath it, and is where you see who still owes a confirmation.
Your people never open the app at all. They read policies from the Published Documents list on your SharePoint site and confirm them on the Certaria card in Microsoft Teams, and they need no Power Platform licence to do either.
Nothing in the lifecycle differs by tier
Section titled “Nothing in the lifecycle differs by tier”A policy is adopted, published, revised and reviewed exactly as any other document Certaria holds. There is no policy-only route through the lifecycle and no step that applies to this tier alone, so the four pages below are the whole of it.
- Adopt a template: decide whether the control applies to you, then copy a template and personalise it.
- Publish a document: check the record Certaria created, approve it, and confirm it reached your people.
- Revise a document: change a policy that is already in force, without withdrawing it while you work.
- The annual review cycle: the prompt, and what counts as the record that a review happened.
Related
Section titled “Related”- Document governance compares all four tiers on one screen, and covers what your people see.
- The Statement of Applicability is where the applicability decision behind each policy is recorded, and where a policy is named as the document covering a control.
- Who can see and do what covers who is able to approve a policy in the first place.