ISMS Document Management Policy
Written By Micah
ISO 27001:2022, Clause 7.5 Documented information, requires that an organization's information security (and privacy) management system shall include documented information required by the ISO 27001 standard as well as documented information determined by the organization as being necessary for the effectiveness of its ISMS (+PIMS).
Commonly associated evidence:
ISMS (+PIMS) Document Management Policy
Who needs a policy like this?
Organizations that adhere to ISO 27001 and ISO 27701
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
If you need help using the template, please let us know.