Name Control area / control title / control description Applied? Justification for inclusion* Justification for exclusion Doc
Do you have a written information security policy?
Do you have written topic-specific policies (such as an access control or backup policy) to support your information security policy where necessary?
Are your information security and topic-specific policies approved by management?
Are those policies published, communicated to and acknowledged by relevant personnel and interested parties?
Are those policies reviewed at planned intervals and after significant changes occur?
Have you defined information security roles and responsibilities?
Have you allocated information security roles and responsibilities according to organisation needs?