- Documentation
- Run your ISMS
- Document governance
Adopt a template
What the shipped templates are, why they arrive in a separate folder, and how to adopt one.
Audience: ISMS Admin.
Certaria ships 38 ISO 27001:2022 document templates. They live inside the Certaria app rather than on your SharePoint site, awaiting one thing from you: an applicability decision, which of these controls apply to you at all. Once you adopt one, Certaria fills your organisation’s own details into the copy for you.
Nothing reaches your site until you adopt it.
Each filename is prefixed with its primary Annex A reference, for example A.5.10 - 01-acceptable-use-policy.docx, so documents appear in the same order an ISO 27001 auditor would expect.
What you are looking at
Section titled “What you are looking at”The 38 templates fall into two groups.
Universal templates (16 documents). Cover ISO 27001:2022 controls that every UK SME ISO 27001 customer needs regardless of business model: the information security policy, acceptable use policy, access control policy, incident response policy, and similar baseline documents. Certaria does not pre-decide applicability for you: every one of the 93 controls arrives with a Clause 6.1.3(d) inclusion driver of Business Baseline, and the decision stays yours to confirm or change.
Conditional templates (22 documents). Cover controls that may or may not apply to your organisation depending on what your business actually does. Examples: do you employ staff, develop software, handle personal data at scale, use cryptography beyond M365 defaults, operate from physical premises. ISO 27001:2022 Clause 6.1.3(d) requires you to consider each control deliberately and document your decision.
Each template contains placeholder markers in square brackets, and most of them are filled in for you. Adopting a template completes your organisation’s name throughout, along with the ISMS administrator, the author and the date. Publishing an approved document completes the approver’s name and title, the effective date, the review date and the date it was last reviewed.
What remains is the handful that describe how your organisation actually works, naming a role or a decision inside the body text such as who authorises an exception. Those are yours, because nothing else can know them. A quick way to find what is left is to search the adopted document for an opening square bracket.
What to do next
Section titled “What to do next”Adopting a template is your work, and it is four steps. It moves you between two places, and knowing which is which saves a lot of confusion:
- The Certaria app holds the templates and the records: your Statement of Applicability, the document register, and the approval. Your people never go there and need no licence.
- SharePoint holds the working files. Adopting places a copy in Policy Masters, and that copy is yours to edit.
The arrow crossing between the two boxes below is the moment your file becomes a tracked record.
%%{init: {"theme":"base","themeVariables":{
"fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
"background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
"primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
"secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
"textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
"clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
"edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
"labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
subgraph SP["In SharePoint"]
direction TB
COPY["Adopt places a copy<br/>in Policy Masters"]
PERS["Certaria fills in<br/>your organisation's details"]
end
subgraph MDA["In the Certaria app"]
direction TB
TPL["38 templates<br/>in the app"]
STAY["It stays unadopted"]
SOA["Statement of Applicability<br/><i>your decision, and why</i>"]
DECIDE{"Does this control<br/>apply to us?"}
DRAFT["A Draft record appears"]
APPROVE["Set it to Approved"]
end
TPL --> SOA
SOA --> DECIDE
DECIDE -->|"it applies:<br/>Adopt Policy Template"| COPY
DECIDE -->|"it does not"| STAY
COPY --> PERS
COPY -.->|"in the same action"| DRAFT
PERS --> APPROVE
DRAFT --> APPROVE
classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
class SOA,STAY,COPY,APPROVE you
class TPL,DRAFT,PERS auto
Solid arrows are things you do. The dotted arrow is Certaria: adopting creates the Draft record for you, in the same action that places the file. Everything else is a decision or an edit that has to be yours, and the diamond is the one an auditor will ask you to justify.
- Decide whether the control applies to you, and record that in your Statement of Applicability with your justification. ISO 27001:2022 Clause 6.1.3(d) requires the decision and the reasoning to be yours.
- Adopt the template. In the Certaria hub switch to the Administration area, then open Policy Templates, open the record and choose Adopt Policy Template. Certaria places a copy in the root of Policy Masters and creates its Draft record in the same action, then gives you a link straight to the file.
- Read the copy through. Your organisation’s details are already in it. Complete any remaining bracketed placeholder that names a role or a decision only you can make, and check the wording suits how you actually work.
- Approve the record. Setting it to Approved stamps the approval date and publishes it to your people.
Adopting the same template twice is safe. If the file is already in Policy Masters, Certaria leaves it exactly as it is and says so. If the file has gone but its record has not, Certaria restores the file and re-links the record you already have rather than creating a second one.
Publish a document is the full procedure with the failure modes.
Templates for controls that do not apply to you simply stay unadopted in the app. There is nothing on your site to tidy up and nothing to delete, and they remain available if that decision changes.
Why this design
Section titled “Why this design”ISO 27001:2022 Clause 6.1.3(d) requires the Statement of Applicability to be the organisation’s own statement, not a vendor’s pre-filled artefact. By gating personalisation on your SoA decisions, Certaria ensures each document you adopt was a deliberate choice rather than an auto-generated default. This produces a stronger audit trail than auto-personalising everything at install would.
Keeping the templates in the app also means the AppSource installation does not pre-empt your applicability decisions. Your Policy Masters library ends up holding only the documents your organisation actually needs, because nothing arrives there until you adopt it.
The 16 Universal templates
Section titled “The 16 Universal templates”| Annex A | Template filename | ISO 27001:2022 control |
|---|---|---|
| A.5.1 | A.5.1 - 16-information-security-policy.docx | Information security policy |
| A.5.9 | A.5.9 - 08-asset-management-policy.docx | Asset management |
| A.5.10 | A.5.10 - 01-acceptable-use-policy.docx | Acceptable use |
| A.5.12 | A.5.12 - 06-data-classification-policy.docx | Data classification |
| A.5.15 | A.5.15 - 02-access-control-policy.docx | Access control |
| A.5.17 | A.5.17 - 38-password-and-access-guide.docx | Authentication information |
| A.5.24 | A.5.24 - 03-incident-response-policy.docx | Incident response |
| A.5.24 | A.5.24 - 35-incident-response-plan.docx | Incident response planning |
| A.5.29 | A.5.29 - 14-business-continuity-policy.docx | Business continuity |
| A.5.29 | A.5.29 - 36-business-continuity-plan.docx | ICT readiness for continuity |
| A.5.31 | A.5.31 - 15-compliance-and-legal-policy.docx | Compliance and legal |
| A.5.33 | A.5.33 - 18-data-retention-disposal-policy.docx | Records retention and disposal |
| A.6.3 | A.6.3 - 19-security-awareness-training-policy.docx | Awareness training |
| Clause 6.1.2 | Clause 6.1.2 - 17-risk-assessment-methodology.docx | Risk assessment methodology |
| Clause 7.5 | Clause 7.5 - 24-document-control-procedure.docx | Document control |
| Clause 9.2 | Clause 9.2 - 22-internal-audit-procedure.docx | Internal audit |
The 22 Conditional templates
Section titled “The 22 Conditional templates”| Annex A | Template | Common applicability question |
|---|---|---|
| A.5.7 | Threat intelligence procedure | Do you consume external threat intelligence feeds? |
| A.5.14 | Information transfer policy | Do you exchange sensitive data with third parties? |
| A.5.14 | Information transfer procedure | Companion to the A.5.14 policy above |
| A.5.19 | Supplier security policy | Do you have IT or data suppliers? |
| A.5.20 | Supplier security clauses | Do you require contractual security clauses with suppliers? |
| A.5.23 | Cloud security policy | Do you use cloud services beyond M365? |
| A.5.32 | IP handling procedure | Is intellectual property a material organisational asset? |
| A.5.34 | DPIA procedure | Do you process personal data at scale (UK GDPR)? |
| A.6.1 | Personnel screening procedure | Do you screen new hires (financial or regulated sectors)? |
| A.6.2 | HR security policy | Do you employ staff rather than contractors only? |
| A.6.2 | Onboarding and offboarding checklist | Do you hire and offboard staff? |
| A.6.4 | Disciplinary procedure | Do you have an internal HR disciplinary function? |
| A.6.6 | NDA confidentiality agreement | Do you engage parties requiring confidentiality undertakings? |
| A.6.7 | Remote working policy | Do any staff work remotely? |
| A.6.7 | Remote working security guide | Companion guidance for staff, where remote working applies |
| A.7.4 | Physical security policy | Do you have physical premises? |
| A.7.14 | Secure disposal procedure | Do you physically dispose of hardware? |
| A.8.1 | BYOD policy | Do staff use personal devices for work? |
| A.8.15 | Logging and monitoring policy | Do you operate non-M365 systems needing custom logging? |
| A.8.24 | Cryptography policy | Do you handle encryption beyond M365 defaults? |
| A.8.25 | Secure development policy | Does your organisation develop software? |
| Clause 7.5 | Policy exception framework | Always relevant once your ISMS has operational complexity |
(Conditional templates are sorted by Annex A reference for cross-checking against your Statement of Applicability.)
Questions
Section titled “Questions”Publish a document covers adoption end to end, and the Statement of Applicability covers recording the decision. If something is not working as described, troubleshooting starts from the symptom.