Mandatory ISO 27001:2022 Documentation

Categories

Latest Post

Have Any Question?

Got a question? We’re here to help!

Facebook
Twitter
LinkedIn
Pinterest

If you’ve ever wondered which documents are mandatory in the 2022 revision of ISO/IEC 27001, here’s the list you need. Below are both the mandatory documents for ISO 27001:2022 implementation and the most commonly used non-mandatory documents.

Key Mandatory Documents and Records

Some of the Mandatory ISO 27001 Documents:

  • ISMS Scope Document

  • Information Security Policy

  • Risk Assessment Report

  • Statement of Applicability

  • Internal Audit Report

Detailed Mandatory Documentation:

What Must Be DocumentedISO 27001 ReferenceUsually Documented Through
Scope of the ISMSClause 4.3ISMS Scope Document
Information Security PolicyClause 5.2Information Security Policy
Risk Assessment and Risk Treatment ProcessClause 6.1.2Risk Assessment and Treatment Methodology
Statement of ApplicabilityClause 6.1.3 d)Statement of Applicability
Risk Treatment PlanClauses 6.1.3 e, 6.2, and 8.3Risk Treatment Plan
Information Security ObjectivesClause 6.2List of Security Objectives
Risk Assessment and Treatment ReportClauses 8.2 and 8.3Risk Assessment & Treatment Report
Inventory of AssetsControl A.5.9*Inventory of Assets, or List of Assets in the Risk Register
Acceptable Use of AssetsControl A.5.10*IT Security Policy
Incident Response ProcedureControl A.5.26*Incident Management Procedure
Statutory, Regulatory, and Contractual RequirementsControl A.5.31*List of Legal, Regulatory, and Contractual Requirements
Security Operating Procedures for IT ManagementControl A.5.37*Security Procedures for IT Department
Definition of Security Roles and ResponsibilitiesControls A.6.2 and A.6.6*Agreements, NDAs, and specifying responsibilities in each security policy and procedure
Definition of Security ConfigurationsControl A.8.9*Security Procedures for IT Department
Secure System Engineering PrinciplesControl A.8.27*Secure Development Policy
 

Note: Individual documentation requirements according to Annex A controls are mandatory only if there are risks or requirements from interested parties demanding those controls.

Mandatory ISO 27001 Records:

What Must Be RecordedISO 27001 ReferenceUsually Recorded Through
Trainings, Skills, Experience, and QualificationsClause 7.2Training Certificates and CVs
Monitoring and Measurement ResultsClause 9.1Measurement Report
Internal Audit ProgramClause 9.2Internal Audit Program
Results of Internal AuditsClause 9.2Internal Audit Report
Results of Management ReviewClause 9.3Management Review Minutes
Results of Corrective ActionsClause 10.2Corrective Action Form
Logs of User Activities, Exceptions, and Security EventsControl A.8.15*Automatic Logs in Information Systems

Non-Mandatory ISO 27001 Documents

There are numerous non-mandatory ISO 27001 documents for implementation, especially for security controls from Annex A. Here are some commonly used non-mandatory documents:

  • Procedure for Document and Record Control (Clause 7.5, Control A.5.33)

  • Procedure for Internal Audit (Clause 9.2)

  • Procedure for Corrective Action (Clause 10.2)

  • Information Classification Policy (Controls A.5.10, A.5.12, and A.5.13)

  • Information Transfer Policy (Control A.5.14)

  • Access Control Policy (Control A.5.15)

  • Password Policy (Controls A.5.16, A.5.17, and A.8.5)

  • Supplier Security Policy (Controls A.5.19, A.5.21, A.5.22, and A.5.23)

  • Disaster Recovery Plan (Controls A.5.29, A.5.30, and A.8.14)

  • Mobile Device, Teleworking, and Work from Home Policy (Controls A.6.7, A.7.8, A.7.9, and A.8.1)

  • Procedures for Working in Secure Areas (Controls A.7.4 and A.7.6)

  • Clear Desk and Clear Screen Policy (Control A.7.7)

  • Bring Your Own Device (BYOD) Policy (Controls A.7.8 and A.8.1)

  • Disposal and Destruction Policy (Controls A.7.10, A.7.14, and A.8.10)

  • Backup Policy (Control A.8.13)

  • Encryption Policy (Control A.8.24)

  • Change Management Policy (Control A.8.32)

Impact of ISO 27001:2022 Revision on Documentation

The new ISO 27001:2022 revision brings good news for documentation:

  • It requires fewer mandatory documents compared to the 2013 revision.

  • Although there are 11 new security controls, there is no need to create new documents. Include new sections about these controls in existing documents from the 2013 revision.

New Security Controls in ISO 27001:2022Existing ISO 27001 Documents Where These Controls Can Be Included
A.5.7 Threat IntelligenceIncident Management Procedure
A.5.23 Information Security for Use of Cloud ServicesSupplier Security Policy
A.5.30 ICT Readiness for Business ContinuityDisaster Recovery Plan
A.7.4 Physical Security MonitoringProcedures for Working in Secure Areas
A.8.9 Configuration ManagementSecurity Procedures for IT Department
A.8.10 Information DeletionDisposal and Destruction Policy
A.8.11 Data MaskingSecure Development Policy
A.8.12 Data Leakage PreventionSecurity Procedures for IT Department
A.8.16 Monitoring ActivitiesSecurity Procedures for IT Department
A.8.23 Web FilteringSecurity Procedures for IT Department
A.8.28 Secure CodingSecure Development Policy

Ensuring Compliance

To ensure you have all mandatory documents for ISO 27001:2022, you have two options:

  1. ISO 27001:2022 Documentation Toolkit: Contains all mandatory documents and records, along with commonly used non-mandatory documentation.

  2. ISO 27001 Software: Select software with all required documents and wizards to help you complete them quickly.

Choosing the right tool can speed up your compliance process and help you avoid embarrassment at the certification audit.