By John Watt on Sunday, 29 November 2020
Category: ISO27001 Information Security Management Systems

List of mandatory documents required by ISO 27001:2013

It has been a fair while since ISO27001:2013 for Information Security Management Systems was published yet it's adoption is only really now starting to gain some traction, just in time for the work on the next revision to really get underway. Like all ISO standards there are set requirements about what you must do, ISO list these as "shall" , part of these must does is of course documentation and records. It's fair to say that there are a few more requirements in ISO27001 than some of the other standards but they all do make sense and will lead to a really sound Information Security Management System. 

We've made a list of them below along with the ones that we also recommend and the clauses that they are linked to. Unlike other standards, the ISO27001:2013 Information Security Management standard has an Annex which acts like a check list linked back to risks, some of the documentation requirements are only applicable if that particular risk is applicable to your organisation. We'll talk more about Annex A in future blog posts.

  Mandatory Documents for ISO27001:2013

Mandatory Documents from Annex A if there are risks found which would require their implementation

Non-Mandatory Documents (but commonly used)

Mandatory Records

  Grab the Checksheet

To make it simple we've created this check sheet that you can use to track everything that you need,

Just tell us where you want it emailed to and we'll do the rest.

Leave Comments