Mandatory vs discretionary ISMS documentation
Whereas ISO/IEC 27001 indicates that only fourteen (14) types of ISMS documentation are strictly required (mandatory), they are barely a start, even for a barebones ISMS. In practice, both mandatory and discretionary documents are valuable . ISO/IEC 27001 c lause 4.4 states: “The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.” Documentation (termed 'documented information' in the standard - see clause 7.5) is generally the best way for management to inform workers about their information security responsibilities e.g. through written policies, procedures/work instructions and job/role descriptions, accompanied by awareness and training materials such as guidelines and briefings. In addition, many security-related processes generate 'records' such as completed forms, ...