Checklist of Mandatory Documentation Required by ISO/IEC 27001 (2013 Revision)
Checklist of Mandatory Documentation Required by ISO/IEC 27001 (2013 Revision)
Checklist of Mandatory Documentation Required by ISO/IEC 27001 (2013 Revision)
Documentation Required by
ISO/IEC 27001 (2013 Revision)
*Controls from Annex A can be excluded if an organization concludes there are no risks or other
requirements which would demand the implementation of a control.
This is by no means a definitive list of documents and records that can be used during the ISO 27001
implementation – the standard allows any other documents to be added to improve the level of
information security.
Read more here: Problems with defining the scope in ISO 27001.
Read more here: Information security policy – how detailed should it be?
Read more here: ISO 27001 risk assessment & treatment – 6 basic steps.
Statement of Applicability
The Statement of Applicability (or SoA) is written based on the results of the risk treatment – this is a
central document within the ISMS because it describes not only which controls from Annex A are
applicable, but also how they will be implemented, and their current status. You could also consider the
Statement of Applicability as a document that describes the security profile of your company.
Read more here: The importance of Statement of Applicability for ISO 27001.
Read more here: Risk Treatment Plan and risk treatment process – What’s the difference?
For more information, look at this short handbook: ISO 27001 Risk Management in Plain English.
Security roles and responsibilities for third parties are defined in contracts.
Read more here: What is the job of Chief Information Security Officer (CISO) in ISO 27001?
Inventory of assets
If you didn't have such an inventory prior to the ISO 27001 project, the best way to create such a
document is directly from the result of the risk assessment – during the risk assessment all the assets and
their owners must be identified anyway, so you just copy the results from there.
Read more here: How to handle Asset register (Asset inventory) according to ISO 27001.
Read more about IT management here: ITIL & ISO 20000 Blog.
Read more here: 6-step process for handling supplier security according to ISO 27001.
To learn more, click here: Business continuity plan: How to structure it according to ISO 22301.
Read more here: How to perform training & awareness for ISO 27001 and ISO 22301.
Once this measurement method is in place, you have to perform the measurement accordingly. It is
important to report these results regularly to the persons who are in charge of evaluating them.
Read more here: ISO 27001 control objectives – Why are they important?
Read more here: How to make an Internal Audit checklist for ISO 27001 / ISO 22301.
Read more here: Why is management review important for ISO 27001 and ISO 22301?
Read more here: Practical use of corrective actions for ISO 27001 and ISO 22301.
You can use this free ISO online tool for handling your documentation, i.e., using it as a document
management system (DMS).
Read more here: Dilemmas with ISO 27001 & BS 25999-2 internal auditors.
More information about internal audit you can find in this free online training: ISO 27001:2013 Internal
Auditor Course.
For more information, please take a look at this useful handbook: Managing ISO Documentation: A Plain
English Guide.