Sentrix

ISO 27001 guide · Clause 7

7.5.3 — Control of documented information

Clause 7.5.3 requires that once a document exists it stays available, protected and managed: distribution, access, storage, versions, retention and disposal.

By Sentrix · Published 2026-07-16

A correct, approved document that nobody can find, or that three people are editing three different versions of, is not actually controlled.

Mandatory requirement · Documented information required: no

In plain language

7.5.3 requires that, once a document exists, it stays available to the people who need it, protected from unauthorized access or loss, and properly managed through distribution, storage, version control, and eventual disposal.

Why this requirement exists

A well-written, properly approved document that lives on someone’s personal laptop, in an outdated shared drive folder, or with no access restrictions on sensitive content is functionally broken even though 7.5.2 was satisfied at the moment of creation. This requirement covers the document’s entire life after that point.

Scenario: an auditor asks to see the current risk treatment plan and receives three different versions from three different people, none of them dated or clearly marked as the authoritative copy. The content might even be identical, but the lack of version control is itself the nonconformity—the organization cannot demonstrate it controls its own documented information.

What the standard expects

The standard expects documented information required by the ISMS and by this standard to be controlled so that it is available and suitable for use where and when needed, and adequately protected—for example from loss of confidentiality, improper use, or loss of integrity. As applicable, the organization must address distribution, access, retrieval and use; storage and preservation, including legibility; control of changes such as version control; and retention and disposition. Documented information of external origin that the organization determines is necessary for the ISMS must also be identified as appropriate and controlled.

In practice

  • Store ISMS documents in a single system of record—not scattered across personal drives, email attachments, and multiple shared folders.
  • Restrict access to sensitive documents (the risk register, incident details) on a need-to-know basis, and log who can see what.
  • Enforce simple version control—a single current version, clearly dated, with prior versions archived rather than deleted.
  • Set retention periods appropriate to each document type, and actually dispose of documents once retention expires, rather than keeping everything forever by default.
  • Track external documents you rely on (a vendor’s SOC 2 report, a regulatory guidance document) the same way you track internal ones.

Evidence the auditor will ask for

  • A single, identifiable current version for any document requested, with clear version history.
  • Access control records or permissions showing sensitive documents are appropriately restricted.
  • A retention schedule and evidence it is actually followed.

Common pitfalls

  • Multiple copies of the "same" document circulating with no clear authoritative version.
  • Sensitive documents (the risk register, incident reports) stored with the same broad access as routine files.
  • No retention or disposal practice at all—everything accumulates indefinitely, including outdated drafts that could confuse an audit.

Related requirements

Sources

Frequently asked questions

Does this require a dedicated document management system?
No. A well-organized shared drive with clear naming conventions and access permissions can satisfy this for a small organization. What matters is that access, versioning, and retention are actually controlled, not the specific tool used. The essential point is a single system of record rather than copies scattered across drives and inboxes.
How long should ISMS documents be retained?
The standard leaves this to the organization. Set a retention period appropriate to each document type in a retention schedule, actually follow it—the auditor will ask for evidence that it is—and keep your prior audit history. Dispose of documents once retention expires rather than keeping everything forever by default.
Are documents of external origin covered?
Yes. Documented information of external origin that the organization determines is necessary for the ISMS—a vendor’s SOC 2 report, a regulatory guidance document—must be identified as appropriate and controlled. Track those documents the same way you track internal ones: current version, access, storage, and retention.

Let's talk about your compliance program.

Last updated: 2026-09-17