Skip to content

The policy templates

What the shipped templates are, why they arrive in a separate folder, and how to adopt one.

Audience: ISMS Admin.

Certaria ships 34 ISO 27001:2022 policy templates. They arrive in a folder called Pending Applicability inside your policy library, as raw templates awaiting two things from you: personalisation, filling in your organisation’s own names and details, and an applicability decision, which of these controls apply to you at all.

Each filename is prefixed with its primary Annex A reference, for example A.5.10 - 01-acceptable-use-policy.docx, so policies appear in the same order an ISO 27001 auditor would expect.

The 34 templates fall into two groups.

Universal templates (13 documents). Cover ISO 27001:2022 controls that every UK SME ISO 27001 customer needs regardless of business model: the information security policy, acceptable use policy, access control policy, incident response policy, and similar baseline documents. Your Statement of Applicability will mark all 13 as Applicable by default.

Conditional templates (21 documents). Cover controls that may or may not apply to your organisation depending on what your business actually does. Examples: do you employ staff, develop software, handle personal data at scale, use cryptography beyond M365 defaults, operate from physical premises. ISO 27001:2022 Clause 6.1.3(d) requires you to consider each control deliberately and document your decision.

Each template contains placeholder markers in square brackets, such as [Organisation Name], [ISMS Admin Name], [Approver Name and Title] and [DD MONTH YYYY]. These are intentional, and you replace them yourself. A quick way to check you have caught them all is to search the finished document for an opening square bracket.

Adopting a template is your work, and it is four steps. It moves you between two places, and knowing which is which saves a lot of confusion:

  • SharePoint holds the files. The templates, the copy you personalise, and the finished policy all live in your policy library.
  • The Certaria app holds the records. Your Statement of Applicability, the document register, and the approval all live there. Your people never go there and need no licence.

The arrow crossing between the two boxes below is the moment your file becomes a tracked record.

%%{init: {"theme":"base","themeVariables":{
  "fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
  "background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
  "primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
  "secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
  "textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
  "clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
  "edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
  "labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
  subgraph SP["In SharePoint"]
    direction TB
    TPL["34 templates in<br/>Pending Applicability"]
    STAY["It stays where it is"]
    COPY["Copy it to the root<br/><b>never edit in place</b>"]
    PERS["Replace every [placeholder]"]
  end

  subgraph MDA["In the Certaria app"]
    direction TB
    SOA["Statement of Applicability<br/><i>your decision, and why</i>"]
    DECIDE{"Does this control<br/>apply to us?"}
    DRAFT["A Draft record appears"]
    APPROVE["Set it to Approved"]
  end

  TPL --> SOA
  SOA --> DECIDE
  DECIDE -->|"it applies"| COPY
  DECIDE -->|"it does not"| STAY
  COPY --> PERS
  PERS -.->|"within the hour"| DRAFT
  DRAFT --> APPROVE

  classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
  classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
  class SOA,STAY,COPY,PERS,APPROVE you
  class TPL,DRAFT auto

Solid arrows are things you do. The dotted arrow is Certaria: the Draft record is the only step it performs for you. Everything else is a decision or an edit that has to be yours, and the diamond is the one an auditor will ask you to justify.

  1. Decide whether the control applies to you, and record that in your Statement of Applicability with your justification. ISO 27001:2022 Clause 6.1.3(d) requires the decision and the reasoning to be yours.
  2. Copy the template out of Pending Applicability into the root of your policy library. Copy it, never edit it where it sits.
  3. Personalise the copy: replace every placeholder marker with your organisation’s values.
  4. Check the record and approve it. Certaria creates a Draft record for the file within the hour. Setting it to Approved stamps the approval date and publishes it to your people.

Publish a policy is the full procedure with the failure modes.

Templates for controls that do not apply to you stay in Pending Applicability as documented references. There is no need to delete them, and leaving them there costs you nothing.

ISO 27001:2022 Clause 6.1.3(d) requires the Statement of Applicability to be the organisation’s own statement, not a vendor’s pre-filled artefact. By gating personalisation on your SoA decisions, Certaria ensures each policy you adopt was a deliberate choice rather than an auto-generated default. This produces a stronger audit trail than auto-personalising everything at install would.

This folder structure also means the AppSource installation does not pre-empt your applicability decisions. Every customer’s /ISMS Policies/ folder ends up containing only the policies their organisation actually needs.

Annex ATemplate filenameISO 27001:2022 control
A.5.1A.5.1 - 16-information-security-policy.docxInformation security policy
A.5.9A.5.9 - 08-asset-management-policy.docxAsset management
A.5.10A.5.10 - 01-acceptable-use-policy.docxAcceptable use
A.5.12A.5.12 - 06-data-classification-policy.docxData classification
A.5.15A.5.15 - 02-access-control-policy.docxAccess control
A.5.24A.5.24 - 03-incident-response-policy.docxIncident response
A.5.29A.5.29 - 14-business-continuity-policy.docxBusiness continuity
A.5.31A.5.31 - 15-compliance-and-legal-policy.docxCompliance and legal
A.5.33A.5.33 - 18-data-retention-disposal-policy.docxRecords retention and disposal
A.6.3A.6.3 - 19-security-awareness-training-policy.docxAwareness training
Clause 6.1.2Clause 6.1.2 - 17-risk-assessment-methodology.docxRisk assessment methodology
Clause 7.5Clause 7.5 - 24-document-control-procedure.docxDocument control
Clause 9.2Clause 9.2 - 22-internal-audit-procedure.docxInternal audit
Annex ATemplateCommon applicability question
A.5.7Threat intelligence procedureDo you consume external threat intelligence feeds?
A.5.14Information transfer policyDo you exchange sensitive data with third parties?
A.5.14Information transfer procedureCompanion to the A.5.14 policy above
A.5.19Supplier security policyDo you have IT or data suppliers?
A.5.20Supplier security clausesDo you require contractual security clauses with suppliers?
A.5.23Cloud security policyDo you use cloud services beyond M365?
A.5.32IP handling procedureIs intellectual property a material organisational asset?
A.5.34DPIA procedureDo you process personal data at scale (UK GDPR)?
A.6.1Personnel screening procedureDo you screen new hires (financial or regulated sectors)?
A.6.2HR security policyDo you employ staff rather than contractors only?
A.6.2Onboarding and offboarding checklistDo you hire and offboard staff?
A.6.4Disciplinary procedureDo you have an internal HR disciplinary function?
A.6.6NDA confidentiality agreementDo you engage parties requiring confidentiality undertakings?
A.6.7Remote working policyDo any staff work remotely?
A.7.4Physical security policyDo you have physical premises?
A.7.14Secure disposal procedureDo you physically dispose of hardware?
A.8.1BYOD policyDo staff use personal devices for work?
A.8.15Logging and monitoring policyDo you operate non-M365 systems needing custom logging?
A.8.24Cryptography policyDo you handle encryption beyond M365 defaults?
A.8.25Secure development policyDoes your organisation develop software?
Clause 7.5Policy exception frameworkAlways relevant once your ISMS has operational complexity

(Conditional templates are sorted by Annex A reference for cross-checking against your Statement of Applicability.)

Publish a policy covers adoption end to end, and the Statement of Applicability covers recording the decision. If something is not working as described, troubleshooting starts from the symptom.