Documented Information Requirements
In ISO/IEC 27001, documented information means information that an organization must control and maintain, along with the medium that holds it. Clause 7.5 sets the core requirements, and a Lead Auditor must assess whether the ISMS documentation is adequate, controlled and used in practice. Clause 7… In ISO/IEC 27001, documented information means information that an organization must control and maintain, along with the medium that holds it. Clause 7.5 sets the core requirements, and a Lead Auditor must assess whether the ISMS documentation is adequate, controlled and used in practice. Clause 7.5.1 requires two types of documented information: what the standard explicitly requires, and what the organization itself decides is necessary for an effective ISMS. The extent varies with organizational size, the complexity of processes and interactions, and the competence of personnel. The standard uses two verbs. 'Maintain' refers to documents such as policies and procedures. 'Retain' refers to records that serve as evidence. Mandatory documented information includes the ISMS scope (4.3), the information security policy (5.2), the risk assessment and risk treatment processes (6.1.2, 6.1.3), the Statement of Applicability (6.1.3 d), the risk treatment plan, and information security objectives (6.2). Mandatory records include evidence of competence (7.2), operational planning and control information (8.1), risk assessment results (8.2), risk treatment results (8.3), monitoring and measurement results (9.1), the internal audit programme and its results (9.2), management review results (9.3), and nonconformities with their corrective actions (10.2). Clause 7.5.2 requires appropriate identification, such as titles, dates, authors or reference numbers. It also requires a suitable format and medium, and review and approval for suitability and adequacy. Clause 7.5.3 requires control so that documented information is available, suitable for use, and adequately protected against loss of confidentiality, improper use or loss of integrity. Controls address distribution, access, retrieval, storage, preservation of legibility, version control, retention and disposition. Documented information of external origin, such as legal requirements or supplier contracts, must also be identified and controlled. During audits, a Lead Auditor checks that documents are current, approved and accessible. The auditor also confirms that records provide objective evidence that the ISMS conforms to requirements and operates effectively.
Documented Information Requirements in ISO/IEC 27001 (Clause 7.5): A Lead Auditor Guide
Introduction
Documented information is the evidence backbone of an Information Security Management System (ISMS). In ISO/IEC 27001:2022 (and the 2013 edition before it), the requirements are set out mainly in Clause 7.5 Documented information, with specific obligations spread across Clauses 4 to 10. As an ISO 27001 Lead Auditor you must know what the standard requires to be documented, how that information must be controlled, and how to judge whether an organization's documentation is adequate. This guide explains why the topic matters, what it is, how it works in practice, and how to answer exam questions on it.
1. Why Documented Information Is Important
Evidence of conformity: Auditors cannot rely on verbal assurances. Documented information gives objective evidence that the ISMS has been planned, implemented, monitored and improved.
Consistency and repeatability: Documented policies, processes and procedures help people perform security activities the same way every time, which reduces errors and dependence on individuals.
Knowledge retention: Documentation preserves organizational knowledge when staff leave or roles change.
Accountability and traceability: Records show who did what, when and with what result, such as risk assessments, audits, management reviews and corrective actions.
Legal, regulatory and contractual compliance: Many laws and contracts require proof of security controls. Documented information supplies that proof.
Basis for improvement: Monitoring results, audit findings and nonconformity records feed continual improvement (Clause 10).
Information security in its own right: Documented information is itself an information asset. If it is leaked, altered or lost, the ISMS and the organization can be harmed. This is why Clause 7.5.3 requires it to be protected.
2. What Documented Information Is
ISO/IEC 27000 defines documented information as information required to be controlled and maintained by an organization and the medium on which it is contained. It can be in any format and on any medium, from any source. It can refer to:
- the management system, including related processes
- information created for the organization to operate (documentation)
- evidence of results achieved (records)
Maintain vs. Retain: key terminology
The Annex SL / Harmonized Structure replaced the old terms 'documents' and 'records' with one term, documented information:
- 'Maintain documented information' = what used to be called a document, such as a policy, scope or procedure. It is kept current and updated when needed.
- 'Retain documented information' = what used to be called a record, such as audit results or evidence of competence. It is kept as evidence and should not be altered.
This distinction is a very common exam topic.
Clause 7.5.1 General
The organization's ISMS shall include:
a) documented information required by ISO/IEC 27001; and
b) documented information determined by the organization as being necessary for the effectiveness of the ISMS.
A note explains that the extent of documented information can differ from one organization to another due to:
- the size of the organization and its type of activities, processes, products and services
- the complexity of processes and their interactions
- the competence of persons
This means there is no single 'correct' amount of documentation. A small company with highly competent staff may need far less than a multinational. Auditors must judge adequacy in context.
Mandatory Documented Information in ISO/IEC 27001:2022
The main explicit requirements are:
- 4.3 Scope of the ISMS (maintain)
- 5.2 Information security policy (maintain)
- 6.1.2 Information security risk assessment process (retain)
- 6.1.3 Information security risk treatment process (retain)
- 6.1.3 d) Statement of Applicability (SoA), with justification for inclusions and exclusions of Annex A controls
- 6.1.3 e) / f) Information security risk treatment plan, and risk owners' approval and acceptance of residual risks
- 6.2 Information security objectives (retain)
- 7.2 d) Evidence of competence (retain)
- 7.5.1 b) Documented information the organization determines as necessary
- 8.1 Documented information to the extent necessary to have confidence that processes have been carried out as planned
- 8.2 Results of information security risk assessments (retain)
- 8.3 Results of information security risk treatment (retain)
- 9.1 Evidence of monitoring and measurement results (available)
- 9.2.2 Evidence of the implementation of the audit programme(s) and the audit results
- 9.3.3 Evidence of the results of management reviews
- 10.2 Evidence of the nature of nonconformities, actions taken and results of corrective actions
Annex A controls may also imply documentation when they are applicable, for example 5.1 Policies for information security, 5.9 Inventory of information and other associated assets, 5.31 Legal, statutory, regulatory and contractual requirements, and 5.37 Documented operating procedures. These become requirements only if the control is selected in the SoA, or if the organization's own risk treatment makes them necessary.
What is NOT explicitly mandatory
The standard does not require a 'quality-manual style' ISMS manual, or documented procedures for internal audit, management review, document control or corrective action. Organizations may still choose to create them under 7.5.1 b). Auditors must not raise a nonconformity simply because a document they personally expect is missing, unless its absence affects effectiveness or breaks a stated requirement.
3. How It Works
Clause 7.5.2 Creating and updating
When creating and updating documented information, the organization shall ensure appropriate:
a) identification and description, such as title, date, author or reference number
b) format and media, such as language, software version, graphics, paper or electronic
c) review and approval for suitability and adequacy
Clause 7.5.3 Control of documented information
Documented information shall be controlled to ensure:
a) it is available and suitable for use, where and when it is needed
b) it is adequately protected, for example from loss of confidentiality, improper use or loss of integrity
For control, the organization shall address, as applicable:
c) distribution, access, retrieval and use
d) storage and preservation, including preservation of legibility
e) control of changes, such as version control
f) retention and disposition
Documented information of external origin that the organization determines to be necessary for planning and operating the ISMS, such as laws, standards, vendor manuals or client security requirements, shall be identified as appropriate and controlled.
A note clarifies that access can mean permission to view only, or permission and authority to view and change.
Practical implementation examples
- A document management system with version numbers, approval workflows and change history
- Classification labels, such as Internal or Confidential, applied to ISMS documents
- Role-based access control so only authorised owners can edit the policy
- Backups and integrity protection for records such as logs and audit reports
- A retention schedule linked to legal requirements, with secure disposal
- Withdrawal or clear marking of obsolete versions so they are not used by mistake
- A register of external documents, such as applicable regulations and contracts, with review dates
How an auditor audits documented information
1. Stage 1 (documentation review): Confirm that mandatory documented information exists, for example scope, policy, risk methodology, SoA, risk treatment plan and objectives. Check that it is consistent and adequate for the context.
2. Stage 2 (implementation): Sample documents and records. Verify approval, version, availability at the point of use, protection and alignment with practice. Interview staff to confirm they know and use the current version.
3. Trace audit trails: For example, risk assessment results, then SoA, then the treatment plan, then implemented controls, then monitoring records.
4. Check records integrity: Records must not be altered retrospectively. Look for dates, signatures or system logs.
5. Evaluate the effect: A missing record may indicate that an activity was not performed at all, for example no management review.
Typical nonconformities
- SoA missing justification for excluded controls (6.1.3 d)
- Obsolete policy version in use on the intranet (7.5.3 c, e)
- No evidence of competence for the security administrator (7.2 d)
- Internal audit performed but results not retained (9.2.2)
- Confidential risk register stored in an open shared folder (7.5.3 b)
- Policy never reviewed or approved by top management (5.2, 7.5.2 c)
- No retention rule, with records deleted prematurely (7.5.3 f)
4. Exam Tips: Answering Questions on Documented Information Requirements
Tip 1: Know the maintain vs. retain distinction. Maintain refers to living documents, such as the scope, policy and SoA. Retain refers to evidence or records, such as audit results, competence evidence and corrective actions. Questions often test whether you can classify an item correctly.
Tip 2: Memorise the mandatory list with clause numbers. Lead auditor exams, such as PECB or CQI/IRCA, frequently ask which item is NOT mandatory. Common distractors include an ISMS manual, a documented internal audit procedure, a business continuity plan (required only if selected through Annex A), or an asset inventory (an Annex A control, not a main-clause requirement).
Tip 3: Remember the 7.5.2 trio and the 7.5.3 list. For creating and updating, remember identification and description, format and media, and review and approval. For control, remember available and suitable, protected, distribution/access/retrieval/use, storage and preservation, control of changes, retention and disposition, and external origin.
Tip 4: Apply the principle of proportionality. When a scenario describes a small organization with little documentation, do not assume a nonconformity. Ask whether the required documented information exists and whether the ISMS is effective. The note to 7.5.1 is your justification.
Tip 5: Link the finding to the correct clause. In scenario or essay questions, state the requirement, the objective evidence and the gap. For example: 'Clause 7.5.3 requires documented information to be adequately protected from loss of confidentiality. Evidence: the risk register containing vulnerability details was accessible to all staff on a shared drive. Therefore the requirement is not fulfilled.'
Tip 6: Grade the nonconformity sensibly. A single outdated form in one department is typically minor. A missing SoA, no risk assessment results, or no evidence that internal audits or management reviews ever took place usually indicates a systemic or major nonconformity, because a core ISMS process is absent.
Tip 7: Treat documented information as an information asset. Exams like to connect 7.5.3 with confidentiality, integrity and availability. Protection of ISMS documents applies the CIA triad to the ISMS itself.
Tip 8: Do not forget external documents. Laws, regulations, customer contracts and supplier documents that the ISMS depends on must be identified and controlled. This is a frequently missed point.
Tip 9: Watch for edition differences. In the 2022 edition, Annex A has 93 controls in four themes, and Clause 6.3 Planning of changes was added without an explicit documentation requirement. Clause 8.1 also has a documentation requirement 'to the extent necessary'. Read questions carefully to identify which edition they reference.
Tip 10: Use auditor reasoning for 'what would you do next' questions. The best answer is usually to seek objective evidence. Ask to see the record, sample further, interview the process owner, or verify the version in use. Writing the procedure for the auditee or accepting verbal claims is wrong, because auditors must remain independent and evidence-based.
Tip 11: Check consistency between documents. Scenario questions may hide inconsistencies, such as a scope that excludes a site the SoA covers, or objectives that do not align with the policy. Spotting these shows lead auditor competence.
Sample question
An organization has no documented procedure for internal audits, but it has an audit programme, audit plans and audit reports for the past year. Is this a nonconformity?
Answer: No. ISO/IEC 27001 Clause 9.2 requires documented information as evidence of the implementation of the audit programme and the audit results, not a documented procedure. The retained evidence satisfies the requirement, provided the audits were effective and covered the requirements of 9.2.
Summary
Documented information requirements ensure the ISMS is defined, evidenced, protected and controlled. Remember the two sources (required by the standard and determined necessary by the organization), the maintain vs. retain distinction, the mandatory list, the 7.5.2 creation criteria, and the 7.5.3 control criteria. In the exam, always anchor your answer to the exact clause, use objective evidence, apply proportionality, and grade findings by their impact on ISMS effectiveness.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!