Creating and Updating Documents in the SOMS

Introduction

A Security Operations Management System (SOMS) lives and breathes through its documented information. Clause 7.5 of ISO 18788:2015 requires organizations to establish, control, and maintain documentation that supports the implementation, operation, and continual improvement of the system.

Creating and updating documents is not simply an administrative activity—it is the process by which strategic intent is translated into written guidance, operational procedures, and auditable records. Done correctly, documentation provides clarity, consistency, accountability, and assurance to clients, regulators, and auditors.

The Purpose of Documented Information

  1. Consistency - Ensures that all staff follow the same policies and procedures.
  2. Compliance - Demonstrates alignment with ISO 18788 requirements and legal/regulatory obligations.
  3. Traceability - Provides an auditable trail of decisions, actions, and changes.
  4. Awareness - Makes roles, responsibilities, and expectations clear to employees.
  5. Assurance - Gives external stakeholders confidence that the SOMS is controlled and effective.

Creating Documents for the SOMS

When creating a document, organizations must ensure it is:

  • Appropriate and relevant to the SOMS scope (Clause 4.3).
  • Accurate and clear, written in language accessible to the intended audience.
  • Formally authorized by the correct level of management (CEO for governance documents, divisional heads for procedures, supervisors for operational instructions).
  • Version-controlled, with a unique identifier (per your Document Control Procedure).
  • Integrated with other system documents (e.g., policies → procedures → SOPs → forms).

Types of Documents Common in ISO 18788

  • Governance Documents (Level 1): Policy, Statement of Conformance, Scope of SOMS, Manual.
  • Management System Documents (Level 2): Procedures for risk management, complaints & grievances, human rights, awareness.
  • Operational Documents (Level 3): SOPs for guard deployment, incident response, access control.
  • Evidence/Records (Level 4): Training attendance, incident reports, audit logs, communication registers.

Updating Documents

Documentation must remain current, relevant, and effective. Updating follows a structured process:

  1. Trigger for Update - Policy changes, new client requirements, audit findings, legal/regulatory updates, or lessons learned from incidents.
  2. Draft Revision - Responsible owner revises the document in line with the change.
  3. Review - Peer review and validation by subject matter experts or compliance officers.
  4. Approval - Formal sign-off by the authorized manager.
  5. Version Control Update - New version number, date of approval, author, and approver recorded.
  6. Communication - Updated document shared with relevant personnel (training, toolbox talks, awareness campaigns).
  7. Archiving Old Versions - Previous versions archived securely in line with the Archiving Act and internal retention policy, ensuring traceability.

Documentation Control Requirements

To comply with ISO 18788 (aligned with ISO 27001 Clause 7.5.3 and ISO 9001 Clause 7.5):

  • Identification - Documents must carry a title, ID number, version, author, and approval date.
  • Review and Approval - Controlled through a documented sign-off process.
  • Accessibility - Documents must be available where and when they are needed.
  • Protection - Prevent unauthorized use, changes, or loss.
  • Retention and Disposition - Maintain documents for legally required periods; dispose securely when obsolete.
  • Auditability - Ensure audit trails exist for document creation, revision, and approval.

Evidence for Audits (Creating & Updating Documents)

Auditors will typically request evidence such as:

  • Document Register showing version histories and approval records.
  • Samples of recently updated procedures with tracked changes.
  • Communication records proving dissemination of updates (emails, training sessions, sign-off sheets).
  • Archived versions of superseded documents to demonstrate traceability.
  • Compliance checks showing alignment of documents with ISO 18788 requirements.

Conclusion

Creating and updating documents under Clause 7.5 of ISO 18788 is not just administrative housekeeping—it is a core governance process that ensures the SOMS remains current, credible, and auditable.

By following structured controls—covering creation, review, approval, version control, communication, and archiving—organizations provide evidence of maturity, accountability, and continual improvement.

This disciplined approach to documentation reassures clients, auditors, and stakeholders that the organization's policies, procedures, and records are not only written but are living documents, guiding daily security operations.