Document Register (auto-generated)¶
Generated by
tools/isms.py buildfrom each document's front-matter. Do not edit by hand — change the document's front-matter and rebuild. Last built: 2026-08-23
Clause 4 — Context¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-04-1 | Information Security Context, Requirements and Scope | policy | ✅ approved | 1.0 | 4.1, 4.2, 4.3, 4.4 | Olaf Jacobson | 2027-08-13 |
| ISMS-DOC-04-2 | System Description (SOC 2) | reference | ✏️ draft | 0.1 | 4.3 | Olaf Jacobson | — |
Clause 5 — Leadership¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-05-2 | Information Security Roles, Responsibilities and Authorities | policy | ✏️ draft | 0.2 | 5.1, 5.3, A.5.2 | Olaf Jacobson | — |
| ISMS-DOC-05-3 | Executive Support Letter | record | ✏️ draft | 0.2 | 5.1 | Olaf Jacobson | — |
| ISMS-DOC-05-4 | Information Security Policy | policy | ✏️ draft | 0.3 | 5.2, A.5.1 | Olaf Jacobson | — |
Clause 6 — Planning (risk & SoA)¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-06-1 | Information Security Objectives & Plan | plan | ✏️ draft | 0.2 | 6.2, 5.1, 7.1 | Olaf Jacobson | — |
| ISMS-DOC-06-2 | Risk Assessment and Treatment Process | process | ✅ approved | 0.1 | 6.1.2, 6.1.3, 8.2, 8.3 | Olaf Jacobson | 2027-08-13 |
| ISMS-DOC-06-3 | Risk Assessment Report | register | ✏️ draft | 0.4 | 6.1.2, 8.2 | Olaf Jacobson | — |
| ISMS-DOC-06-4 | Risk Treatment Plan | plan | ✏️ draft | 0.2 | 6.1.3, 8.3 | Olaf Jacobson | — |
| ISMS-FORM-06-1 | Risk Assessment Tool (CertiKit) | form | 🗄️ superseded | 0.2 | 6.1.2 | Olaf Jacobson | — |
| ISMS-FORM-06-2 | Statement of Applicability (SoA) | register | ✏️ draft | 0.1 | 6.1.3 | Olaf Jacobson | — |
Clause 7 — Support¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-07-1 | Information Security Competence, Awareness and Training Procedure | procedure | ✏️ draft | 0.1 | 7.2, 7.3, A.6.3 | Olaf Jacobson | — |
| ISMS-DOC-07-3 | Procedure for the Control of Documented Information | procedure | ✏️ draft | 0.2 | 7.5 | Olaf Jacobson | — |
| ISMS-DOC-07-5 | Security Training & Awareness Log | record | ✏️ draft | 0.1 | 7.2, 7.3, A.6.3 | Olaf Jacobson | — |
| ISMS-DOC-07-7 | Evidence Collection and Management Procedure | procedure | ✏️ draft | 0.1 | 7.5, 9.1, A.5.33 | Olaf Jacobson | — |
| ISMS-DOC-07-8 | External Access to the ISMS (auditors, customers, prospects) | procedure | ✏️ draft | 0.1 | 7.5, A.5.10, A.5.12, A.5.14, A.5.15, A.5.33 | Olaf Jacobson | — |
| ISMS-FORM-07-2 | Evidence Register | register | ✏️ draft | 0.1 | 7.5, 9.1, A.5.33 | Olaf Jacobson | — |
| ISMS-FORM-07-3 | Evidence Capture Manifest | form | ✏️ draft | 0.1 | 7.5, A.5.33 | Olaf Jacobson | — |
| ISMS-FORM-07-4 | Evidence Capture Log | record | ✏️ draft | 0.1 | 7.5, 9.1, A.5.33 | Olaf Jacobson | — |
Clause 8 — Operation¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-08-1 | Isms8 Process Interaction Overview | process | 📝 template | 0.1 | 8.1 | Melvin Jacobson | — |
| ISMS-DOC-A08-32-1 | Change Management Process | process | ✏️ draft | 0.2 | A.8.32, A.8.19, A.5.22 | Thomas Picauly | — |
Clause 9 — Performance evaluation¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-09-1 | Process for Monitoring, Measurement, Analysis and Evaluation | process | ✏️ draft | 0.1 | 9.1 | Olaf Jacobson | — |
| ISMS-DOC-09-2 | Procedure for Internal Audits | procedure | ✏️ draft | 0.1 | 9.2, A.5.35 | Olaf Jacobson | — |
| ISMS-DOC-09-4 | Management Review Procedure | procedure | ✏️ draft | 0.2 | 9.3, A.5.1 | Olaf Jacobson | — |
| ISMS-DOC-09-6 | Continuous Control Monitoring and GRC Architecture | process | ✏️ draft | 0.1 | 9.1, A.5.36, A.8.16 | Olaf Jacobson | — |
| ISMS-FORM-05-1 | Weekly ISMS sync — 2026-07-02 | record | ✏️ draft | 0.1 | 5.1 | Olaf Jacobson | — |
| ISMS-FORM-05-1-2026-07-24 | Weekly ISMS sync — 2026-07-24 | record | ✏️ draft | 0.1 | 5.1 | Olaf Jacobson | — |
| ISMS-FORM-09-6 | Automated Control Check Catalog | register | ✏️ draft | 0.1 | 9.1, A.5.36, A.8.16 | Olaf Jacobson | — |
| ISMS-FORM-09-7 | SOC 2 Type 1 Readiness (GetAgency checklist) | register | ✏️ draft | 0.1 | 9.1, A.5.36 | Olaf Jacobson | — |
| ISMS-FORM-09-8 | SOC 2 Type 1 — three-week close-out plan | plan | ✏️ draft | 0.4 | 9.1, 10.2 | Olaf Jacobson | — |
| ISMS-INDEX-meeting-log | ISMS Meeting Minutes — Log (index) | reference | ✏️ draft | 0.1 | — | Olaf Jacobson | — |
Clause 10 — Improvement¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-10-1 | Procedure for the Management of Nonconformity | procedure | ✅ approved | 0.1 | 10.1, 10.2 | Olaf Jacobson | 2027-08-13 |
Annex A.5 — Organizational¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-A05-1-1 | Social Media Policy | policy | 🗄️ superseded | 0.2 | A.5.1 | Olaf Jacobson | — |
| ISMS-DOC-A05-1-2 | HR Security Policy | policy | ✏️ draft | 0.2 | A.5.1, A.6.1, A.6.2, A.6.4, A.5.4 | Olaf Jacobson | — |
| ISMS-DOC-A05-10-1 | Acceptable Use Policy | policy | ✏️ draft | 0.2 | A.5.10, A.5.14, A.5.1 | Olaf Jacobson | — |
| ISMS-DOC-A05-10-3 | Electronic Messaging Policy | policy | 🗄️ superseded | 0.2 | A.5.10, A.5.14 | Olaf Jacobson | — |
| ISMS-DOC-A05-10-6 | Online Collaboration Policy | policy | 🗄️ superseded | 0.2 | A.5.10, A.5.14 | Olaf Jacobson | — |
| ISMS-DOC-A05-15-1 | Access Control Policy | policy | ✏️ draft | 0.4 | A.5.15, A.5.16, A.5.17, A.5.18, A.8.3, A.8.4, A.8.5 | Thomas Picauly | — |
| ISMS-DOC-A05-18-1 | User Access Management Process | process | ✏️ draft | 0.1 | A.5.16, A.5.17, A.5.18, A.8.2, A.8.5 | Thomas Picauly | — |
| ISMS-DOC-A05-19-1 | Supplier Relationships Security Policy | policy | ✏️ draft | 0.2 | A.5.19, A.5.20, A.5.21, A.5.22 | Olaf Jacobson | — |
| ISMS-DOC-A05-23-1 | Cloud Services Policy | policy | ✏️ draft | 0.2 | A.5.23 | Thomas Picauly | — |
| ISMS-DOC-A05-24-1 | Incident Playbook — Ransomware | procedure | ✏️ draft | 0.1 | A.5.24, A.5.26, A.8.7, A.8.13 | Olaf Jacobson | — |
| ISMS-DOC-A05-24-2 | Incident Playbook — Denial of Service | procedure | ✏️ draft | 0.1 | A.5.24, A.5.26, A.8.6, A.8.20 | Thomas Picauly | — |
| ISMS-DOC-A05-24-3 | Incident Playbook — Data Breach | procedure | ✏️ draft | 0.1 | A.5.24, A.5.26, A.5.34, A.8.15 | Olaf Jacobson | — |
| ISMS-DOC-A05-26-1 | Information Security Incident Response Procedure | procedure | ✏️ draft | 0.1 | A.5.24, A.5.25, A.5.26, A.5.27, A.5.28, A.6.8 | Olaf Jacobson | — |
| ISMS-DOC-A05-30-1 | Business Continuity & Disaster Recovery Plan | plan | ✏️ draft | 0.1 | A.5.29, A.5.30, A.8.13, A.8.14, A.8.6 | Olaf Jacobson | — |
| ISMS-DOC-A05-31-1 | Legal, Regulatory & Contractual Requirements Procedure | procedure | ✏️ draft | 0.2 | A.5.31, A.5.32, A.5.34 | Olaf Jacobson | — |
| ISMS-DOC-A05-32-1 | IP & Copyright Compliance Policy | policy | ✏️ draft | 0.2 | A.5.32 | Olaf Jacobson | — |
| ISMS-DOC-A05-33-1 | Records Retention & Protection Policy | policy | ✏️ draft | 0.4 | A.5.33 | Olaf Jacobson | — |
| ISMS-DOC-A05-34-1 | Privacy and Personal Data Protection Policy | policy | ✏️ draft | 0.2 | A.5.34 | Olaf Jacobson | — |
| ISMS-DOC-A05-34-2 | Personal Data Breach Notification Procedure | procedure | ✏️ draft | 0.1 | A.5.34, A.5.26 | Olaf Jacobson | — |
| ISMS-DOC-A05-37-1 | Operating Procedure — Production Database Access | procedure | ✏️ draft | 0.1 | A.5.37, A.8.2, A.8.20, A.8.22, A.5.15 | Thomas Picauly | — |
| ISMS-DOC-A05-4-1 | Information Security Whistleblowing Policy | policy | 🗄️ superseded | 0.2 | A.5.4 | Olaf Jacobson | — |
| ISMS-DOC-A05-7-1 | Threat Intelligence Policy | policy | 🗄️ superseded | 0.2 | A.5.7 | Olaf Jacobson | — |
| ISMS-DOC-A05-9-1 | Asset Management Policy | policy | ✏️ draft | 0.2 | A.5.9, A.5.10, A.5.11 | Olaf Jacobson | — |
| ISMS-DOC-A05-9-2 | Information Asset Inventory | register | ✏️ draft | 0.1 | A.5.9, A.5.10, A.5.11, A.5.12 | Olaf Jacobson | — |
| ISMS-FORM-A05-19-1 | Vendor & Sub-processor Register | register | ✏️ draft | 0.3 | A.5.19, A.5.20, A.5.21, A.5.22, A.5.23, A.5.9 | Olaf Jacobson | — |
| ISMS-FORM-A05-34-1 | Record of Processing Activities (GDPR Article 30(2)) | register | ✏️ draft | 0.1 | A.5.34, A.5.31, A.5.19, A.8.24 | Olaf Jacobson | — |
Annex A.6 — People¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-A06-1-1 | Employee Screening Procedure | procedure | 🗄️ superseded | 0.2 | A.6.1 | Olaf Jacobson | — |
| ISMS-DOC-A06-2-1 | Guidelines for Inclusion in Employment Contracts | procedure | ✏️ draft | 0.2 | A.6.2 | Olaf Jacobson | — |
| ISMS-DOC-A06-4-1 | Employee Disciplinary Process | process | 🗄️ superseded | 0.2 | A.6.4 | Olaf Jacobson | — |
| ISMS-DOC-A06-6-1 | Schedule of Confidentiality Agreements | register | ✏️ draft | 0.2 | A.6.6 | Olaf Jacobson | — |
| ISMS-DOC-A06-6-2 | Non-Disclosure Agreement (template) | form | ✏️ draft | 0.2 | A.6.6 | Olaf Jacobson | — |
| ISMS-DOC-A06-6-3 | Founder Confidentiality & Security Undertaking | form | ✏️ draft | 0.1 | A.6.6, A.6.2, A.5.4 | Olaf Jacobson | — |
| ISMS-DOC-A06-7-1 | Remote Working Policy | policy | ✏️ draft | 0.2 | A.6.7 | Olaf Jacobson | — |
| ISMS-DOC-A06-8-1 | Information Security Event Reporting Procedure | procedure | ✏️ draft | 0.3 | A.6.8 | Olaf Jacobson | — |
| ISMS-FORM-A06-1-1 | Employee Screening Checklist | form | ✏️ draft | 0.2 | A.6.1 | Olaf Jacobson | — |
| ISMS-FORM-A06-3-1 | Policy Acknowledgement Form | form | ✏️ draft | 0.1 | A.6.3, A.5.4, A.6.2 | Olaf Jacobson | — |
| ISMS-FORM-A06-5-1 | Employee Termination & Change of Employment Checklist | form | ✏️ draft | 0.2 | A.6.5 | Olaf Jacobson | — |
Annex A.7 — Physical¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-A07-7-1 | Clear Desk & Clear Screen Policy | policy | ✏️ draft | 0.2 | A.7.7 | Olaf Jacobson | — |
Annex A.8 — Technological¶
| ID | Document | Type | Status | Ver | Controls | Owner | Next review |
|---|---|---|---|---|---|---|---|
| ISMS-DOC-A08-1-1 | Device Management Policy | policy | ✏️ draft | 0.2 | A.8.1 | Thomas Picauly | — |
| ISMS-DOC-A08-1-2 | BYOD Policy | policy | 🗄️ superseded | 0.2 | A.8.1 | Thomas Picauly | — |
| ISMS-DOC-A08-1-3 | Device Security Standard (BYOD baseline & attestation) | policy | ✏️ draft | 0.1 | A.8.1, A.8.7, A.6.7, A.7.9, A.5.10 | Olaf Jacobson | — |
| ISMS-DOC-A08-10-1 | Data Handling & Deletion Policy | policy | ✏️ draft | 0.2 | A.8.10, A.8.11, A.8.12 | Thomas Picauly | — |
| ISMS-DOC-A08-11-1 | Data Masking Policy | policy | 🗄️ superseded | 0.2 | A.8.11 | Thomas Picauly | — |
| ISMS-DOC-A08-12-1 | Data Leakage Prevention Policy | policy | 🗄️ superseded | 0.2 | A.8.12 | Thomas Picauly | — |
| ISMS-DOC-A08-13-1 | Backup Policy | policy | ✏️ draft | 0.2 | A.8.13 | Thomas Picauly | — |
| ISMS-DOC-A08-14-1 | Availability Management Policy | policy | ✏️ draft | 0.2 | A.8.14 | Melvin Jacobson | — |
| ISMS-DOC-A08-15-1 | Logging & Monitoring Policy | policy | ✏️ draft | 0.2 | A.8.15, A.8.16 | Thomas Picauly | — |
| ISMS-DOC-A08-16-1 | Monitoring Policy | policy | 🗄️ superseded | 0.2 | A.8.16 | Thomas Picauly | — |
| ISMS-DOC-A08-19-1 | Software Policy | policy | ✏️ draft | 0.2 | A.8.19 | Thomas Picauly | — |
| ISMS-DOC-A08-20-1 | Cloud & Infrastructure Security Policy | policy | ✏️ draft | 0.2 | A.8.20, A.8.21, A.8.22 | Thomas Picauly | — |
| ISMS-DOC-A08-23-1 | Web Filtering Policy | policy | 🗄️ superseded | 0.2 | A.8.23 | Thomas Picauly | — |
| ISMS-DOC-A08-24-1 | Cryptographic Policy | policy | ✏️ draft | 0.2 | A.8.24 | Thomas Picauly | — |
| ISMS-DOC-A08-25-1 | Secure Development Policy | policy | ✏️ draft | 0.2 | A.8.25, A.8.27, A.8.31, A.8.28 | Thomas Picauly | — |
| ISMS-DOC-A08-28-1 | Secure Coding Policy | policy | 🗄️ superseded | 0.2 | A.8.28 | Thomas Picauly | — |
| ISMS-DOC-A08-3-1 | Dynamic Access Control Policy | policy | 🗄️ superseded | 0.2 | A.8.3, A.8.4, A.8.5 | Thomas Picauly | — |
| ISMS-DOC-A08-7-1 | Endpoint Protection Policy | policy | ✏️ draft | 0.2 | A.8.7, A.8.23 | Olaf Jacobson | — |
| ISMS-DOC-A08-8-1 | Technical Vulnerability & Threat Management Policy | policy | ✏️ draft | 0.2 | A.8.8, A.5.7 | Thomas Picauly | — |
| ISMS-DOC-A08-8-2 | Penetration Testing Procedure | procedure | ✏️ draft | 0.1 | A.8.8, A.8.29, A.5.35 | Thomas Picauly | — |
| ISMS-DOC-A08-9-1 | Configuration Management Policy | policy | ✏️ draft | 0.2 | A.8.9 | Thomas Picauly | — |