Documented Information Control (Clause 7.5)
To meet the requirements of ISO 27001 Clause 7.5, all ISMS policies, procedures, and evidence artifacts follow strict configuration control:
- Source of Truth: All markdown documentation resides in the master Git repository.
- Tamper-Proof Audit Trail: Changes to any policy or register require a formal Git Pull Request (PR) with approval recorded by the Lead Implementer.
- Review Cadence: All active documents undergo mandatory review every 12 months or upon significant organizational change.
- Access Control: Public/general staff access to the published site is read-only. Authoring and approval rights are restricted to authorized administrators.