Knowledge base
ISO 27001: Required Documented Information – Simple Guide
A guide to the key documents required for ISO 27001 compliance.
Neha Dvivedi · ١٦ أغسطس ٢٠٢٦
ISO 27001 requires organisations to maintain certain documents and records to show that their Information Security Management System (ISMS) is properly planned, implemented and maintained.
1. Documents You Must Maintain
Your organisation should have documented information covering:
• ISMS Scope – Defines what parts of the organisation, systems, locations and activities are covered by the ISMS.
• Information Security Policy – Explains the organisation’s overall approach to information security.
• Risk Assessment Process – Describes how information security risks are identified and assessed.
• Risk Treatment Process – Explains how identified risks will be managed or reduced.
• Statement of Applicability (SoA) – Shows which security controls apply to the organisation and why.
• Information Security Objectives – Defines what the organisation wants to achieve in information security.
• Other Necessary ISMS Information – Any additional documented information needed to make the ISMS work effectively.
2. Records You Must Keep
You also need to retain evidence that your ISMS activities are actually being carried out. This includes:
• Records showing that employees are competent and properly trained.
• Results of the information security risk assessment.
• Results of risk treatment activities.
• Evidence of monitoring and measurement.
• The internal audit programme and audit results.
• Management review records and results.
• Records of nonconformities and the actions taken to address them.
• Corrective action records and their results.
• Evidence that operational processes were planned and carried out as intended.
3. Documents Commonly Maintained for ISO 27001 Controls
Some documents are not specifically named as mandatory documents in the standard, but organisations commonly maintain them because they help demonstrate that applicable controls are being implemented.
These may include:
• Asset inventory – A list of hardware, software, information and other important assets.
• Access control policy and access review records – Shows who has access to systems and whether that access is regularly reviewed.
• Supplier register and security requirements – Identifies suppliers and the information security requirements they need to follow.
• Incident register and incident response procedure – Records security incidents and explains how incidents are handled.
• Business continuity and backup arrangements – Includes backup procedures and evidence that data can actually be restored.
• Change management records – Shows how important changes to systems and processes are controlled.
• Acceptable use policy – Explains how employees are expected to use company systems and information.
• Secure development policy – Important for organisations that develop software or applications.
4. Statement of Applicability (SoA)
The Statement of Applicability (SoA) is one of the most important documents in an ISO 27001 implementation.
It lists the Annex A controls and explains:
• Which controls are applicable to the organisation.
• Which controls are not applicable.
• Why each decision has been made.
• How applicable controls are implemented.
• Which policies, procedures or records support those controls.
For controls that are excluded, the organisation should provide a clear and organisation-specific reason.
Simply writing “Not Applicable” is generally not enough. For example, saying “We do not have physical infrastructure because all our systems are cloud-hosted” provides a specific reason for excluding certain physical infrastructure-related controls.
5. Practical Documentation Tips
Keep documents useful
Write policies and procedures in a way that employees can actually understand and follow.
A policy that nobody reads is unlikely to result in a control that anybody follows.
Don't create one document for every control
ISO 27001 has many controls, but you do not need a separate document for each one.
Instead, group related controls into practical policies and procedures. This makes the ISMS easier to manage.
Keep documents updated
Every document should have:
• Date
• Version number
• Approval details
• Review/update information
Auditors look at whether documents are current. Old documents referring to systems or processes that no longer exist can become audit findings.
Keep your risk assessment updated
Risk assessment should not be treated as a one-time activity completed only before certification.
It should be reviewed and updated when there are significant changes, new risks, incidents or other relevant developments.
6. Common Documentation Problems Auditors Find
Some common issues include:
1. Generic Statement of Applicability
The justifications are so general that they could apply to almost any organisation.
2. Outdated policies
Policies were approved several years ago but still refer to systems, technologies or processes that no longer exist.
3. Incomplete access reviews
Records show that an access review was completed, but they don't clearly show what access was reviewed or what changes were made.
4. Backups that have never been tested
The organisation has a backup procedure but cannot provide evidence that data has actually been restored successfully.
5. Suppliers without security requirements
Contracts with suppliers who handle company or customer data do not clearly include information security requirements.
Key Takeaway
ISO 27001 documentation is not about creating more paperwork. It is about having the right information and evidence to show that your information security processes are planned, implemented, monitored and continuously improved.
The goal should be to create documentation that is practical, current, easy to understand and supported by real evidence.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
١٣ سبتمبر ٢٠٢٦
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
١٣ سبتمبر ٢٠٢٦
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
١٣ سبتمبر ٢٠٢٦
