A.5.1 Policies for information security
Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
15
artefacts
1
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Version control log with change descriptions · SIEM / log platform
periodic reviewEvidence produced at each review
- Approved amendment minutes · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Enterprise Information Security Policy · Policy repository / GRC workspace
- Data Classification Policy · Policy repository / GRC workspace
- Access Control Policy · Policy repository / GRC workspace
- Board meeting minutes approving the security policy · Policy repository / GRC workspace
- Signature page of policy approval · Policy repository / GRC workspace
- Email chain confirming senior management sign‑off · Policy repository / GRC workspace
- Distribution register showing recipients and dates · Policy repository / GRC workspace
- Employee acknowledgment receipts · Policy repository / GRC workspace
- Internal portal access logs for policy page · Policy repository / GRC workspace
- Annual policy review calendar · Policy repository / GRC workspace
- Documented review procedure · Policy repository / GRC workspace
- Meeting agenda for scheduled policy review · Policy repository / GRC workspace
- Change request form for policy amendment · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Policies not formally approved by senior management
- No evidence of distribution or employee acknowledgment
- Review dates not documented or missed
- Version control missing, leading to outdated policies
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet