- Documentation
- Run your ISMS
- Policies
The policy templates
What the shipped templates are, why they arrive in a separate folder, and how to adopt one.
Audience: ISMS Admin.
Certaria ships 34 ISO 27001:2022 policy templates. They arrive in a folder called Pending Applicability inside your policy library, as raw templates awaiting two things from you: personalisation, filling in your organisation’s own names and details, and an applicability decision, which of these controls apply to you at all.
Each filename is prefixed with its primary Annex A reference, for example A.5.10 - 01-acceptable-use-policy.docx, so policies appear in the same order an ISO 27001 auditor would expect.
What you are looking at
Section titled “What you are looking at”The 34 templates fall into two groups.
Universal templates (13 documents). Cover ISO 27001:2022 controls that every UK SME ISO 27001 customer needs regardless of business model: the information security policy, acceptable use policy, access control policy, incident response policy, and similar baseline documents. Your Statement of Applicability will mark all 13 as Applicable by default.
Conditional templates (21 documents). Cover controls that may or may not apply to your organisation depending on what your business actually does. Examples: do you employ staff, develop software, handle personal data at scale, use cryptography beyond M365 defaults, operate from physical premises. ISO 27001:2022 Clause 6.1.3(d) requires you to consider each control deliberately and document your decision.
Each template contains placeholder markers in square brackets, such as [Organisation Name], [ISMS Admin Name], [Approver Name and Title] and [DD MONTH YYYY]. These are intentional, and you replace them yourself. A quick way to check you have caught them all is to search the finished document for an opening square bracket.
What to do next
Section titled “What to do next”Adopting a template is your work, and it is four steps. It moves you between two places, and knowing which is which saves a lot of confusion:
- SharePoint holds the files. The templates, the copy you personalise, and the finished policy all live in your policy library.
- The Certaria app holds the records. Your Statement of Applicability, the document register, and the approval all live there. Your people never go there and need no licence.
The arrow crossing between the two boxes below is the moment your file becomes a tracked record.
%%{init: {"theme":"base","themeVariables":{
"fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
"background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
"primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
"secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
"textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
"clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
"edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
"labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
subgraph SP["In SharePoint"]
direction TB
TPL["34 templates in<br/>Pending Applicability"]
STAY["It stays where it is"]
COPY["Copy it to the root<br/><b>never edit in place</b>"]
PERS["Replace every [placeholder]"]
end
subgraph MDA["In the Certaria app"]
direction TB
SOA["Statement of Applicability<br/><i>your decision, and why</i>"]
DECIDE{"Does this control<br/>apply to us?"}
DRAFT["A Draft record appears"]
APPROVE["Set it to Approved"]
end
TPL --> SOA
SOA --> DECIDE
DECIDE -->|"it applies"| COPY
DECIDE -->|"it does not"| STAY
COPY --> PERS
PERS -.->|"within the hour"| DRAFT
DRAFT --> APPROVE
classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
class SOA,STAY,COPY,PERS,APPROVE you
class TPL,DRAFT auto
Solid arrows are things you do. The dotted arrow is Certaria: the Draft record is the only step it performs for you. Everything else is a decision or an edit that has to be yours, and the diamond is the one an auditor will ask you to justify.
- Decide whether the control applies to you, and record that in your Statement of Applicability with your justification. ISO 27001:2022 Clause 6.1.3(d) requires the decision and the reasoning to be yours.
- Copy the template out of
Pending Applicabilityinto the root of your policy library. Copy it, never edit it where it sits. - Personalise the copy: replace every placeholder marker with your organisation’s values.
- Check the record and approve it. Certaria creates a Draft record for the file within the hour. Setting it to Approved stamps the approval date and publishes it to your people.
Publish a policy is the full procedure with the failure modes.
Templates for controls that do not apply to you stay in Pending Applicability as documented references. There is no need to delete them, and leaving them there costs you nothing.
Why this design
Section titled “Why this design”ISO 27001:2022 Clause 6.1.3(d) requires the Statement of Applicability to be the organisation’s own statement, not a vendor’s pre-filled artefact. By gating personalisation on your SoA decisions, Certaria ensures each policy you adopt was a deliberate choice rather than an auto-generated default. This produces a stronger audit trail than auto-personalising everything at install would.
This folder structure also means the AppSource installation does not pre-empt your applicability decisions. Every customer’s /ISMS Policies/ folder ends up containing only the policies their organisation actually needs.
The 13 Universal templates
Section titled “The 13 Universal templates”| Annex A | Template filename | ISO 27001:2022 control |
|---|---|---|
| A.5.1 | A.5.1 - 16-information-security-policy.docx | Information security policy |
| A.5.9 | A.5.9 - 08-asset-management-policy.docx | Asset management |
| A.5.10 | A.5.10 - 01-acceptable-use-policy.docx | Acceptable use |
| A.5.12 | A.5.12 - 06-data-classification-policy.docx | Data classification |
| A.5.15 | A.5.15 - 02-access-control-policy.docx | Access control |
| A.5.24 | A.5.24 - 03-incident-response-policy.docx | Incident response |
| A.5.29 | A.5.29 - 14-business-continuity-policy.docx | Business continuity |
| A.5.31 | A.5.31 - 15-compliance-and-legal-policy.docx | Compliance and legal |
| A.5.33 | A.5.33 - 18-data-retention-disposal-policy.docx | Records retention and disposal |
| A.6.3 | A.6.3 - 19-security-awareness-training-policy.docx | Awareness training |
| Clause 6.1.2 | Clause 6.1.2 - 17-risk-assessment-methodology.docx | Risk assessment methodology |
| Clause 7.5 | Clause 7.5 - 24-document-control-procedure.docx | Document control |
| Clause 9.2 | Clause 9.2 - 22-internal-audit-procedure.docx | Internal audit |
The 21 Conditional templates
Section titled “The 21 Conditional templates”| Annex A | Template | Common applicability question |
|---|---|---|
| A.5.7 | Threat intelligence procedure | Do you consume external threat intelligence feeds? |
| A.5.14 | Information transfer policy | Do you exchange sensitive data with third parties? |
| A.5.14 | Information transfer procedure | Companion to the A.5.14 policy above |
| A.5.19 | Supplier security policy | Do you have IT or data suppliers? |
| A.5.20 | Supplier security clauses | Do you require contractual security clauses with suppliers? |
| A.5.23 | Cloud security policy | Do you use cloud services beyond M365? |
| A.5.32 | IP handling procedure | Is intellectual property a material organisational asset? |
| A.5.34 | DPIA procedure | Do you process personal data at scale (UK GDPR)? |
| A.6.1 | Personnel screening procedure | Do you screen new hires (financial or regulated sectors)? |
| A.6.2 | HR security policy | Do you employ staff rather than contractors only? |
| A.6.2 | Onboarding and offboarding checklist | Do you hire and offboard staff? |
| A.6.4 | Disciplinary procedure | Do you have an internal HR disciplinary function? |
| A.6.6 | NDA confidentiality agreement | Do you engage parties requiring confidentiality undertakings? |
| A.6.7 | Remote working policy | Do any staff work remotely? |
| A.7.4 | Physical security policy | Do you have physical premises? |
| A.7.14 | Secure disposal procedure | Do you physically dispose of hardware? |
| A.8.1 | BYOD policy | Do staff use personal devices for work? |
| A.8.15 | Logging and monitoring policy | Do you operate non-M365 systems needing custom logging? |
| A.8.24 | Cryptography policy | Do you handle encryption beyond M365 defaults? |
| A.8.25 | Secure development policy | Does your organisation develop software? |
| Clause 7.5 | Policy exception framework | Always relevant once your ISMS has operational complexity |
(Conditional templates are sorted by Annex A reference for cross-checking against your Statement of Applicability.)
Questions
Section titled “Questions”Publish a policy covers adoption end to end, and the Statement of Applicability covers recording the decision. If something is not working as described, troubleshooting starts from the symptom.