Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

7.5 Documented Information

7.5.1 General Requirements

anDREa includes and maintains all documented information required by the ISO/IEC 27001 standard, alongside supplementary records deemed necessary for the continuous operational effectiveness of the ISMS.

  • Internal Master Repository: All official framework documents, risk registers, and master control files are securely stored and maintained within a dedicated, restricted-access configuration in Github. Access permissions and editing rights are strictly restricted based on role profiles and the principle of least privilege.
  • Public Transparency: Currently active, management-approved policies, procedural guidelines, and the formal Statement of Applicability (SoA) are published openly.

7.5.2 Creating and Updating Documented Information

To maintain structural consistency, clear metadata traceability, and compliance across our document library, all newly authored or updated ISMS records must adhere to standard design and content criteria:

1. Identification and Metadata Architecture

The primary interface or front matter of each document must explicitly feature:

  • Document Title: A clear, unambiguous title matching our indexing standard.
  • Review Date: The date of the last comprehensive validation or structural assessment.
  • Security Classification: The explicit confidentiality label assigned to the asset.
  • Version Management Record: A structured log detailing version increments, authors, exact adjustments made, and formal approval timestamps.
  • Governance Tracking: Every approval date must be linked directly to an internal tracking ticket or governance log detailing explicit Management Team authorization.

2. Version Control Lifecycle Rules

Prior to executing modifications to an active document:

  • A duplicate archive snapshot of the existing version is generated within the central documentation system following the standardized taxonomy format: YYYY_MM_DD_[Title]_[Previous_Version] or using the version control of Github and DevOps.
  • The historical timestamp represents the final date the text remained valid.
  • Archived legacy records are retained securely within a designated historical folder to preserve structural lineage.

3. Core Structural Components

At a minimum, policy documents must contain the following structural zones:

  • Purpose and Background: The driving context and objective of the control.
  • Scope: The explicit operational, architectural, or organizational boundaries of the text.
  • Objectives: The desired security or operational milestones intended by the policy.
  • Availability: Access criteria and readership mandates for the file.
  • Description of Norm Elements: Detailed operational text satisfying the targeted standard's compliance criteria.
  • Administrative Logs: Associated registries or reference links, where applicable.

7.5.3 Control of Documented Information

To satisfy ISO/IEC 27001 Clause 7.5.3, anDREa enforces strict protection, distribution, and preservation controls across our asset library to prevent data loss, corruption, or unauthorized modification.

  • Availability and Access: Approved documentation is kept immediately available and readable for operational needs. While current baselines are hosted publicly for reading, active modification rights are managed exclusively by the Management Team through role-based IAM configurations.
  • Data Protection and Redundancy: Master assets are protected from localized loss of integrity or confidentiality using Google Workspace enterprise-grade access logging and continuous background data replication.
  • Retention and Disposition: Outdated records are archived systematically as outlined in Section 7.5.2, preventing accidental erasure or operational deployment of legacy guidelines.
  • External Documentation Governance: Third-party assets necessary for ISMS planning—including supplier SOC 2 type II audit reports, regulatory guidelines, and standard specifications—are explicitly identified, registered in the Supplier List, and subjected to the same version control and storage restrictions as internal security assets.
  • Change Notification: The Management Team evaluates policy updates during implementation and proactively communicates material or operationally impactful procedural changes to all affected personnel.
  • Versioning: All documents use a date for versioning. Where applicable the field Last Updated will be used.