- Documentation
- Run your ISMS
The registers you maintain
Four places in Certaria that arrive empty and stay empty until you fill them in, what belongs in each, and what an auditor expects to find.
Purpose: four places in Certaria that arrive empty and stay empty until you fill them in. This explains what belongs in each, why Certaria does not populate them for you, and what an auditor expects to find.
Audience: ISMS Admin.
Why these are not automatic
Section titled “Why these are not automatic”Certaria fills in everything it can see. It reads your Microsoft 365 tenant, your policy library, your device compliance and your sign-in activity, and it keeps those current without being asked.
These four are different, for two reasons.
Some of it Certaria cannot see. Your GitHub organisation, your Azure subscriptions, the finance system your accountant logs into: these are outside your Microsoft tenant, and an ISMS tool that quietly ignored them would give you a register that looks complete and is not.
Some of it is a judgement, not a fact. “We reviewed everyone’s access in April and removed three accounts” is an assertion by a named person on a named date. Software cannot make that claim on your behalf, and an auditor would not accept it if it could.
User Accounts
Section titled “User Accounts”What it is. Your access control register for ISO 27001 A.5.18: every account that can reach anything, who owns it, and what kind of account it is.
What belongs in it
| Account type | Examples |
|---|---|
| Standard | Everyday work accounts |
| Admin | Global Administrator, SharePoint Administrator, any privileged role |
| Service | Automation accounts, application registrations |
| Shared Mailbox | Accounts behind a shared address |
| External | Contractors, auditors, third party support |
Record accounts from every system, not only Microsoft. GitHub, Azure, your finance and HR systems, anything with a login.
What an auditor asks. “Show me every account with access to systems in scope, tell me who owns each one, and show me when you last reviewed the list.”
Two columns stay manual. MFA Enabled is not read automatically: doing so needs an additional permission on your tenant, and Certaria does not ask for one just to fill a column. Your Conditional Access baseline is the stronger evidence for multi factor coverage in any case. Last Reviewed is a human assertion and always will be.
Shared Mailboxes
Section titled “Shared Mailboxes”What it is. A record of the mailboxes nobody owns personally, and therefore the ones that get missed.
What belongs in it. Shared mailboxes, distribution lists, aliases, mail enabled and security groups. For each, the address, who owns it, what it is for, and whether it forwards anywhere.
Forwarding is optional. Most shared mailboxes forward nowhere and are simply monitored by a team. Leave it blank in that case.
Why it matters. A mailbox with no personal owner receives customer data, supplier correspondence and password resets, and appears on nobody’s leaver checklist. It is one of the most reliable places to find an access gap, which is exactly why an auditor asks about it.
Access Reviews
Section titled “Access Reviews”What it is. The evidence that you periodically check who has access to what, and act on it. Certaria uses it for A.8.2 User Access Management.
What belongs in it. One record per review, with the date, who did it, how many accounts they looked at, what they found, what they changed, and when the next one is due.
Quarterly is the usual cadence for an organisation of ten to a hundred people. Pick one and keep to it: a regular review with modest findings is far better evidence than an occasional thorough one.
Record the reviews that found nothing. A register showing four reviews a year with three quiet ones is credible. A register with a single entry looks like a register created the week before the audit, because it usually is.
Additional Email Addresses
Section titled “Additional Email Addresses”What it is. Extra addresses for a person, each with a purpose. It is deliberately not where their main work address lives.
Where the work address is. On the person’s Identity record, taken from Microsoft 365 at import and kept current there. You will see it on the Identity section of their Person record.
When to add one here. When someone should receive a particular kind of message somewhere else. A personal address for certification reminders that must still arrive after they change role, or a separate address for training notices.
How Certaria chooses. Where an address exists here for the relevant purpose, it is used. Otherwise the work address is used. So leaving this empty is perfectly normal and everyone still gets their notifications.
Getting started
Section titled “Getting started”You do not need to complete these before you can use Certaria, and trying to fill them in perfectly on day one is the wrong instinct.
- Start with User Accounts, and start with Admin accounts only. Those are the ones an auditor asks about first and the ones that matter most.
- Add Shared Mailboxes as you come across them. Your mail administrator can list them in a few minutes.
- Record your first Access Review the first time you actually do one. Do not backdate reviews that did not happen.
- Leave Additional Email Addresses empty unless you have a reason.
The registers are worth more when they are honest than when they are full.