Starting point
The Access Control Policy from Approving a Document has been in force for a year. At the annual review the IT Security Officer shortened the review cadence from quarterly to monthly. A first draft was rejected for a missing transition rule and revised. The auditor wants to trace how the valid version 2.0 came about.1. Find the valid version
Tab History, Versions: 1.0 with status Superseded, 2.0 with status Valid. Tab Overview shows the same state under Valid Version; the history additionally shows the previous versions.Superseded concerns the version, not the document. Approver and approval date
of 1.0 stay intact.
2. Compare the versions
1
Open version 2.0
A click on the row opens the sidebar with Created On, Approved On,
Change Reason and the properties as of the time of approval.
2
Choose the comparison
The selection at the top of the sidebar puts 2.0 against version 1.0.
3
Read the properties
The table shows Review interval in both versions: twelve months against
one month.
4
Read the chapters
The new chapter Transition Rule is marked. The content can be shown side
by side or one below the other.
3. Show the rejected attempt
The version list contains only approved versions. The approval history contains every request:
A click on the rejected row opens the sidebar with the requester’s Comment
and the IT Manager’s Rejection Reason: “Transition rule for ongoing review
cycles is missing.”
For an auditor, the rejected request is part of the evidence: it shows that the
approval process was reviewed, not only confirmed.
4. Output the version as a PDF
Download stands next to version 2.0 as soon as the export is finished. The PDF contains the version as it stood at the time of approval.The export runs in the background. If Download is missing, it has not
finished yet.