Skip to content

Documented Information Control (Clause 7.5)

To meet the requirements of ISO 27001 Clause 7.5, all ISMS policies, procedures, and evidence artifacts follow strict configuration control:

  1. Source of Truth: All markdown documentation resides in the master Git repository.
  2. Tamper-Proof Audit Trail: Changes to any policy or register require a formal Git Pull Request (PR) with approval recorded by the Lead Implementer.
  3. Review Cadence: All active documents undergo mandatory review every 12 months or upon significant organizational change.
  4. Access Control: Public/general staff access to the published site is read-only. Authoring and approval rights are restricted to authorized administrators.