Control of Documented Information
Introduction
Clause 7.5.3 of ISO 18788:2015 sets out requirements for the control of documented information within a Security Operations Management System (SOMS). Unlike Clause 7.5.2 (creating and updating), this clause focuses on how documents and records are controlled throughout their lifecycle to ensure accuracy, integrity, confidentiality, and availability.
For a security company, documentation control is not only about internal efficiency—it is critical to demonstrate compliance, human rights accountability, and operational assurance during audits and client reviews.
Objectives of Controlling Documented Information
- Availability - Documents must be accessible when and where needed.
- Integrity - Information must be accurate, complete, and protected from loss or tampering.
- Confidentiality - Sensitive information (e.g., client data, human rights complaints) must be secure and only accessible to authorized persons.
- Traceability - All changes, versions, and approvals must be auditable.
- Compliance - Control systems must align with ISO 18788, the Archiving Act, and applicable data protection laws (e.g., POPIA, GDPR).
Requirements of Clause 7.5.3
ISO 18788 requires organizations to implement control processes that ensure documented information is:
- Identified and described (title, author, version, date, reference code).
- Reviewed and approved before issue.
- Accessible and retrievable when needed.
- Protected against loss of confidentiality, improper use, or damage.
- Retained for defined periods as per retention schedules.
- Disposed securely when no longer required.
- Prevented from unintended use when obsolete (e.g., watermark “superseded†or moved to archive).
Control Methods and Tools
1. Document Registers
- Maintain a central register for policies, procedures, SOPs, and records.
- Each entry must include version number, approval date, responsible owner, retention period.
2. Version Control
- Assign unique identifiers to each document (Doc ID, version, revision date).
- Superseded versions must be archived and marked as obsolete.
- Ensure only the latest version is in operational use.
3. Access Controls
- Define who can view, edit, approve, or archive documents.
- Use role-based permissions (e.g., supervisors may access SOPs but not governance manuals).
- Sensitive documents (e.g., whistleblower records, client contracts) require additional protections.
4. Distribution and Communication
- Track how documents are distributed (emails, intranet, ISOLTX system).
- Require acknowledgement from recipients for critical documents (e.g., new SOPs).
5. Retention and Archiving
- Apply retention schedules in line with the Archiving Act.
- Evidence records (incident reports, grievance files, audit reports) may require 5-10 years retention.
- Secure disposal (shredding, digital erasure) once retention expires.
6. Protection and Backup
- Use secure servers or GRC systems (e.g., ISOLTX DMS) with regular backups.
- Apply encryption for confidential records.
- Ensure disaster recovery plans (BCMS) cover documented information.
Examples of Documented Information in a SOMS
- Policies and Manuals: Security Policy, SOMS Manual, Statement of Conformance.
- Procedures and SOPs: Risk assessment procedures, incident response SOPs, grievance handling.
- Records: Training logs, equipment checklists, communication logs, audit reports.
- Registers: Risk registers, asset registers, complaints registers, evidence registers.
Each of these must be controlled through the lifecycle—from creation, approval, and active use, to archiving and secure disposal.
Audit Evidence for Clause 7.5.3
Auditors will request to see:
- Document Control Procedure and Registers.
- Samples of controlled documents showing version numbers and approvals.
- Records of updates (change logs, sign-offs).
- Archived/superseded documents properly marked and stored.
- Access controls and distribution logs.
- Retention schedules aligned with laws and ISO requirements.
Strong evidence follows the Audit Evidence Reliability Model (AERM):
- Highly Reliable: Automated audit logs from GRC systems, time-stamped version control, third-party certification.
- Moderate Reliability: Document registers, approval sign-offs.
- Low Reliability: Verbal confirmation that staff have “seen the update.â€
Conclusion
Clause 7.5.3 ensures that documented information in the SOMS is not just written but properly controlled throughout its lifecycle. With proper identification, versioning, distribution, retention, and protection, documentation becomes a living assurance tool rather than a static archive.
By linking document control to resources, awareness, and evidence reliability, organizations strengthen audit readiness, client confidence, and continual improvement under ISO 18788.