Back to templates
    Template

    Policy map

    A fourteen-column register of the policy set: tier, owner, approver, audience, the requirement that put each document there, and its next review date.

    Governance5 Sept 20263 min read

    ISO/IEC 27001:2022ISO/IEC 27002:2022
    On this page
    Download the template

    policy-map.xlsx · 9 kBLicensed CC BY 4.0

    What this is

    A register of the policy set: one row per document, four sheets. It is the artefact produced by section 3.3 of Policy architecture people can find, and supports two decisions. Which document states the rule that applies here, and does this document still need to exist? Control 5.1 asks that policies be defined, approved, published, communicated, acknowledged and reviewed 1. A folder cannot show any of that; a map with dates and roles can.

    How to use it

    1. Work the Tiers sheet first. Four default tiers ship with the file. Adjust the wording rather than deleting rows: the tier labels are what the Map sheet points at. See the playbook, section 3.1.
    2. Delete the six example rows on Map and Exceptions first.
    3. Create one Map row per existing document, including the ones nobody claims. Fill Owner (role) and Approver (role) first; a document with neither is the first thing to fix.
    4. Fill Requirement served from the risk register or the obligations list, not from a control catalogue. Name the risk decision or the legal obligation. See the playbook, section 3.2.
    5. Treat an empty requirement cell as a retirement candidate. Decide retire, merge or keep, and record it. See the playbook, section 3.8.
    6. Set Next review by tier, then move a date forward when a change trigger fires. Reviews take management review and audit results into account 1.
    7. Record every exception on the Exceptions sheet, with an owner, an approver and an expiry. Compliance with policies, rules and standards is reviewed regularly, and results recorded 2.
    8. Keep version, approval date and status in the map, not the file name. Clause 7.5.3 is Control of documented information 3.

    What good looks like

    Six of the fourteen Map columns, from the workbook's own rows.

    IDTierOwner (role)Requirement servedNext reviewStatus
    POL-0011. PolicyHead of information securityISO/IEC 27001:2022 clause 5.2; risk decision RSK-0042027-04-141. Current
    STD-0142. StandardPlatform engineering leadDirective (EU) 2022/2555 Art. 21(2)(i); risk decision RSK-0112027-06-021. Current
    GDL-0034. GuidelineWorkplace services leadRisk decision RSK-0222027-11-202. In review

    Fields

    FieldRequiredMeaningCommon mistake
    TieryesWhich of the four tiers the document sits inCalling everything a policy
    Owner, ApproveryesThe role keeping it current, and the role whose decision bindsNaming a person, or no approver
    AudienceyesWho the document is written for"Everyone", where the rule reaches one team
    Requirement servedyesThe clause, article or risk decision behind itA control number, which explains nothing
    Controls drivennoWhat the document is meant to make happenRestating the title
    Version, Approved, Next reviewyesWhich version is current, when approved, when next readKeeping the version in the file name
    Statusyes1. Current, 2. In review or 3. RetiredLeaving retired documents readable

    Download

    • File: policy-map.xlsx (xlsx, 9 KB) — sheets Read first, Tiers, Map, Exceptions.
    • Markdown variant: the same tables in plain markdown, beside the workbook as _policy-map.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data and no organisation names; the example rows are invented.

    References

    1. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. Controls 5.1 and 5.36 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 4
    2. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 5

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 27002:2022 control 5.1, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
    3. 3ISO/IEC 27001:2022 clause 7.5.3, iso.org/obp · verified 2026-09-03
    4. 4ISO/IEC 27002:2022 controls 5.1 and 5.36, licensed copy · verified 2026-09-05
    5. 5ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03