Governance and evidence

Scope

Scope holds the central scope document with organisational units, systems, interfaces and justification. Create a version, submit it for review and approve it. Changing elements or interfaces returns the document to draft. History shows approved versions.

Scope with document status and linked elements

Policies

Policies manage owner, status, validity, visibility and versions. Create a draft, review it and approve it. For acknowledgement-required policies, record target groups and acknowledgements. Archive rather than delete to retain evidence.

Policy list with status and reviews

Risks and measures

Risks records cause, impact, likelihood, severity, treatment and review date. Link affected assets, vendors, controls and measures. Critical risks appear on the dashboard.

Measures records responsible person, due date, progress, effort and effectiveness review. Completed measures remain linked to their risks and evidence. Document result and status, not just a percentage.

Risk list with assessment and treatment

Measures with due dates and owners

Statement of Applicability

Applicability assesses every control in the selected framework as applicable or not applicable. Excluding a control requires justification. Implementation status, maturity, due date and linked evidence form the SoA. Create snapshots before an audit or management review refers to a state.

SoA with controls and implementation status

Management reviews and audits

A Management review consolidates metrics, risks, incidents, audit results and decisions. Record the agenda, decisions and resulting measures.

An Audit contains programme, scope, team, checklist, findings and report. Started and completed audits use controlled status transitions. Findings can remain under follow-up after completion while the report stays unchanged.

Management reviews with decisions and dates

Audits with findings and programme