Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
19 / 34

Chapter 17

17Documented Information: What Is Written Endures

1 min read19 of 34Read it in the book · page 105

“A document nobody reads is more dangerous than none at all, because it gives false confidence.”

The standard requires “documented information” in many places: the scope, the policy, the risk methodology, the Statement of Applicability, objectives, competence records and audit results. The practical question is: how do we document enough without drowning the team in paperwork?

The documented information pyramidThe documented information pyramid
The documented information pyramid
Text in this figure

Policies · Why? · one page per topic · Procedures · Who does what, when? · Instructions, templates · How, step by step? · Records and evidence · What actually happened? · Version control applies to all: documents, code, models and data · Figure 22

The Documentation Pyramid

  • Policies: At the top: few and short, stating “what” and “why”, and approved by leadership.
  • Procedures: Stating “how”: the steps for handling an incident, onboarding a new employee or offboarding a leaver.
  • Instructions and templates: Checklists and ready-made forms that make implementation easy.
  • Records: At the base: evidence that what was written was actually done, such as review minutes, access logs and incident reports.

Managing Documents

  • Identification: A title, date, owner and version number for every document.
  • Review and approval: Before publication and after every significant change.
  • Availability and protection: Available to those who need it, protected from unauthorised change and loss.
  • Retention and disposal: A defined period for each type of record, then secure deletion.

From the Field

Write the procedure as it is actually carried out, not as you wish it were. The auditor compares the document with reality, and the gap between them is the first finding in their report.

2026 Update

AI can speed up first drafts of policies and procedures, but an uncustomised generated document looks generic and an auditor spots it quickly. Use it for structure and wording, and write the reality yourself: system names, real roles and the decisions you have made.

Document as much as you need to repeat success and prove it; no more, no less.

Lessons Learned

  1. 1Documentation is a pyramid: policies, procedures, instructions and records.
  2. 2Every document has an owner, a version and a review date.
  3. 3Records are the evidence of implementation.
  4. 4A document describes reality, not aspiration.

Tip: use ← → to move between sections.