ISO 27001 practical guide
ISO 27001 Mandatory Documents
ISO 27001 requires particular documented information and evidence that management-system processes operate, but it does not prescribe one universal document pack. The right set combines explicitly maintained information, practical documents chosen to run the ISMS, and retained records showing decisions and results.
- Search intent
- Determine which documents and records an ISMS needs without relying on a misleading universal list.
- Guide area
- Evidence
- Review status
- Practitioner reviewed
What this means in practice
Separate documents that direct work from records created by work. A policy, methodology or procedure explains the intended approach; an approval, review result, ticket or meeting decision shows that the approach operated.
Use existing business systems when they provide controlled, retrievable evidence. An ISMS does not become stronger merely because every record is copied into a separate folder.
Step-by-step implementation
- Step 1. Map Clauses 4–10 to the information your organization must maintain or retain.
- Step 2. Identify the policies, methods and working instructions needed to operate your chosen processes consistently.
- Step 3. Define the operating records each process creates, including owner, location, retention and access rules.
- Step 4. Link risk-treatment decisions and applicable Annex A controls to their implementation evidence.
- Step 5. Apply document approval, version, availability and change controls proportionate to use.
- Step 6. Sample the document set against real activity and remove obsolete, duplicate or ownerless material.
What to prepare
- ISMS scope and process map
- documented risk criteria and assessment results
- risk treatment decisions and Statement of Applicability
- information security policy and objectives
- competence, audit, management-review and corrective-action records
Documents, records and evidence
| Area or field | Example | Why it matters |
|---|---|---|
| Governance | Scope, policy, responsibilities and objectives | Approved/current documents plus decisions showing leadership use |
| Risk management | Method, risk results, treatment plan and SoA | Reassessments, approvals, completed actions and residual-risk decisions |
| Assurance | Audit programme, reports and management review | Samples, findings, decisions, follow-up and closure evidence |
| Improvement | Nonconformity and corrective-action records | Cause analysis, implemented action and effectiveness review |
A useful document register
A 60-person SaaS provider keeps controlled policies in its knowledge platform, risks and treatments in a governed register, change evidence in service-management tickets, training evidence in the learning platform and leadership decisions in management-review minutes. Its document register points to authoritative sources rather than creating duplicate copies.
What an auditor will look for
- Traceability from an applicable requirement or process to current documented information.
- Evidence that documents are approved, available, protected and changed deliberately.
- Records covering a representative period and the complete ISMS scope.
- Consistency between written methods and what owners demonstrate in practice.
An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.
Common mistakes
- Treating every template found online as mandatory.
- Confusing a policy statement with evidence that a process operated.
- Maintaining duplicate versions in email, shared drives and governance tools.
- Producing documents immediately before audit with no operating history.
Practical checklist
- □ Required documented information has an owner and authoritative location.
- □ Implementation documents are proportionate to process risk and complexity.
- □ Operating records have retention, protection and retrieval arrangements.
- □ Obsolete versions are removed from points of use.
- □ Samples connect documents to actual decisions and outcomes.
Frequently asked questions
How many documents does ISO 27001 require?
There is no reliable universal number. Count depends on scope, process design, chosen controls and how existing systems retain controlled information.
Do I need an ISMS manual?
Not necessarily. A concise map of ISMS processes can be useful, but the management system may be documented across controlled sources.
Can records stay in existing systems?
Yes, where they remain identifiable, protected, retrievable and subject to appropriate retention and access controls.
Continue through the practical guide library
Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.