Policy map
A fourteen-column register of the policy set: tier, owner, approver, audience, the requirement that put each document there, and its next review date.
Governance5 Sept 20263 min read
On this page
policy-map.xlsx · 9 kBLicensed CC BY 4.0
What this is
A register of the policy set: one row per document, four sheets. It is the artefact produced by section 3.3 of Policy architecture people can find, and supports two decisions. Which document states the rule that applies here, and does this document still need to exist? Control 5.1 asks that policies be defined, approved, published, communicated, acknowledged and reviewed 1. A folder cannot show any of that; a map with dates and roles can.
How to use it
- Work the Tiers sheet first. Four default tiers ship with the file. Adjust the wording rather than deleting rows: the tier labels are what the Map sheet points at. See the playbook, section 3.1.
- Delete the six example rows on Map and Exceptions first.
- Create one Map row per existing document, including the ones nobody claims. Fill Owner (role) and Approver (role) first; a document with neither is the first thing to fix.
- Fill Requirement served from the risk register or the obligations list, not from a control catalogue. Name the risk decision or the legal obligation. See the playbook, section 3.2.
- Treat an empty requirement cell as a retirement candidate. Decide retire, merge or keep, and record it. See the playbook, section 3.8.
- Set Next review by tier, then move a date forward when a change trigger fires. Reviews take management review and audit results into account 1.
- Record every exception on the Exceptions sheet, with an owner, an approver and an expiry. Compliance with policies, rules and standards is reviewed regularly, and results recorded 2.
- Keep version, approval date and status in the map, not the file name. Clause 7.5.3 is Control of documented information 3.
What good looks like
Six of the fourteen Map columns, from the workbook's own rows.
| ID | Tier | Owner (role) | Requirement served | Next review | Status |
|---|---|---|---|---|---|
| POL-001 | 1. Policy | Head of information security | ISO/IEC 27001:2022 clause 5.2; risk decision RSK-004 | 2027-04-14 | 1. Current |
| STD-014 | 2. Standard | Platform engineering lead | Directive (EU) 2022/2555 Art. 21(2)(i); risk decision RSK-011 | 2027-06-02 | 1. Current |
| GDL-003 | 4. Guideline | Workplace services lead | Risk decision RSK-022 | 2027-11-20 | 2. In review |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Tier | yes | Which of the four tiers the document sits in | Calling everything a policy |
| Owner, Approver | yes | The role keeping it current, and the role whose decision binds | Naming a person, or no approver |
| Audience | yes | Who the document is written for | "Everyone", where the rule reaches one team |
| Requirement served | yes | The clause, article or risk decision behind it | A control number, which explains nothing |
| Controls driven | no | What the document is meant to make happen | Restating the title |
| Version, Approved, Next review | yes | Which version is current, when approved, when next read | Keeping the version in the file name |
| Status | yes | 1. Current, 2. In review or 3. Retired | Leaving retired documents readable |
Download
- File:
policy-map.xlsx(xlsx, 9 KB) — sheets Read first, Tiers, Map, Exceptions. - Markdown variant: the same tables in plain markdown, beside the workbook as
_policy-map.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data and no organisation names; the example rows are invented.
Related
- Playbook: Policy architecture people can find
- Playbook: Building an ISMS people actually use, the same set from the management-system side.
- Playbook: Risk acceptance and residual risk, the record behind an exception.
References
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. Controls 5.1 and 5.36 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 4
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 5
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO/IEC 27002:2022 control 5.1, licensed copy · verified 2026-09-05
- 2ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
- 3ISO/IEC 27001:2022 clause 7.5.3, iso.org/obp · verified 2026-09-03
- 4ISO/IEC 27002:2022 controls 5.1 and 5.36, licensed copy · verified 2026-09-05
- 5ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03