Governance and evidence
Scope
Scope holds the central scope document with organisational units, systems, interfaces and justification. Create a version, submit it for review and approve it. Changing elements or interfaces returns the document to draft. History shows approved versions.

Policies
Policies manage owner, status, validity, visibility and versions. Create a draft, review it and approve it. For acknowledgement-required policies, record target groups and acknowledgements. Archive rather than delete to retain evidence.

Risks and measures
Risks records cause, impact, likelihood, severity, treatment and review date. Link affected assets, vendors, controls and measures. Critical risks appear on the dashboard.
Measures records responsible person, due date, progress, effort and effectiveness review. Completed measures remain linked to their risks and evidence. Document result and status, not just a percentage.


Statement of Applicability
Applicability assesses every control in the selected framework as applicable or not applicable. Excluding a control requires justification. Implementation status, maturity, due date and linked evidence form the SoA. Create snapshots before an audit or management review refers to a state.

Management reviews and audits
A Management review consolidates metrics, risks, incidents, audit results and decisions. Record the agenda, decisions and resulting measures.
An Audit contains programme, scope, team, checklist, findings and report. Started and completed audits use controlled status transitions. Findings can remain under follow-up after completion while the report stays unchanged.

