Starting point
Docusnap Sports GmbH is preparing its ISO 27001 certification. For the control Review access rights regularly a policy is still missing: who grants access rights, and at what cadence they are reviewed. The IT Security Officer writes it, the IT Manager approves it. The tenant has Strict Mode enabled: requesting and approving are separate roles.1. Create the controlled document
1
Open the dialog
Document opens the dialog Create New Document.
2
Set the title and turn on document control
Title: Access Control Policy. Switch on Controlled Document — that
makes Type mandatory.
3
Choose the type
Type: Policy. Language, format and export settings stay on their
defaults.
4
Create
Create Document. The document opens as a tab with the chapter
Introduction.
Whether a document is controlled is decided when it is created. It cannot be
changed afterward.
2. Write the content
On the Content tab we switch to edit mode with Edit. We rename the chapter Introduction to Scope by double-clicking it and create a second chapter Granting and Review: who grants access rights, quarterly review. Save. The document stays in status Draft.3. Set the responsible person and the approver
1
Edit the properties
Tab Properties, pencil icon. Anyone can edit this tab, regardless of the
right to the content.
2
Set the responsible person
The IT Security Officer. Without Responsible the content is locked for
everyone.
3
Set the approver
The IT Manager. In Strict Mode, Responsible and Approver must not be
the same person; the page reports this immediately.
4
Save
Without both roles, no approval can be requested on the Document Control
tab.
4. Request approval
1
Fill in the request
Tab Document Control. Version: Major Version — the first version
becomes 1.0. Change Reason: “Initial version for inclusion in the ISMS”.
2
Review the changes
Show Changes shows the entire content as new. There is no earlier version.
3
Submit the request
Request Approval sets the document to In Review. The content is locked
until a decision is made.
5. Decide
The IT Manager sees the request: Requested Version, Change Reason, requester, date. Approve sets the document to Approved and writes version 1.0.Reject requires a Reason and sets the document to Draft. The responsible
person can revise it and submit again.