- Scope statement and ISMS policyFoundational
- Approved, dated, and owned by a named person.
- Risk assessment and treatment recordsFoundational
- Method, criteria, assessed risks, owners, treatment decisions.
- Statement of ApplicabilityFoundational
- All 42 Annex A controls, each with an inclusion decision and justification.
- Asset and information inventoryRecurring
- Classified, owned, and current — the dependency for a dozen other controls.
- User access review recordsRecurring
- Who reviewed which accounts, when, and what changed as a result.
- Supplier register and agreementsRecurring
- Including cloud services, with the security terms actually in the contract.
- Incident records and post-incident reviewEvent-driven
- Auditors would rather see a handled incident than an empty log.
- Continuity and ICT readiness test resultsEvent-driven
- A test with a date, a result and a corrective action.
- Awareness and competence recordsTime-bound
- Completion by person and date. The item most likely to have expired.
- Internal audit programme and reportsTime-bound
- Independent of the area audited, and covering the whole management system over the cycle.
- Management review minutesTime-bound
- Inputs, decisions, actions. Missing minutes is a common Stage 2 nonconformity.