01
Start from a defensible baseline
A library of structured templates covers ISO 27001 Annex A, ISO 22301, GDPR, BSI Grundschutz and ISO 42001. Templates open in a rich-text editor and show the linked controls that need review when content changes.
Policy management
KaitoSec keeps version, scope, approval, acknowledgement and next review together. Staff see the applicable state; security and audit see the evidence chain.
Where friction starts today
A policy gets drafted for the certification, approved in a meeting, and emailed round as a PDF. Six months later there are three versions in circulation, nobody is sure which one is in force, and the acknowledgement evidence is a half-remembered Slack thread. The document still exists. Whether anyone follows it, or has even read the current version, is anyone's guess.
A policy is supposed to be a control, not a file. It should connect to the ISO 27001 requirement it implements, carry its own review date, and prove who has acknowledged which version. When that link is missing, an auditor asking for the evidence behind a control sends the whole team digging through drives. When it is there, the policy and its proof are the same object, and a stale one surfaces before the audit instead of during it.
One data model
Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.
This module
Policy Management
Shared data model
One asset, one risk, one control, one piece of evidence
Entry to evidence
An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.
One change
A risk is re-assessed
Written with it
Where it surfaces
01
A library of structured templates covers ISO 27001 Annex A, ISO 22301, GDPR, BSI Grundschutz and ISO 42001. Templates open in a rich-text editor and show the linked controls that need review when content changes.
02
Every revision is saved with timestamp, author and change summary. KaitoSec keeps the full history so auditors can see exactly what was in force at any point, without email chains, shared drives or PDF graveyards.
03
Distribute policies to target groups and trace who acknowledged each version and where acknowledgement is missing. The audit trail retains the record beside the applicable document.
01
Define stages for draft, professional review, legal approval and publication. Responsibility, status and decision remain with the policy as evidence.
02
Each policy is linked to the ISO 27001 controls, NIS2 measures, Grundschutz safeguards, ISO 22301 clauses or ISO 42001 requirements it implements. When an auditor asks for the evidence behind a control, the policy is one click away.
03
Set review cycles per policy and let KaitoSec notify owners before expiry. Overdue reviews surface on the compliance dashboard, so outdated policies never make it through to the next audit unnoticed.
The library includes templates for information security, access control, acceptable use, incident response, business continuity, data classification, supplier security and AI governance. Every template is a starting point and must be adapted to scope, organisation and legal context.
Yes. Every template is fully editable in the rich-text editor. You can add company-specific sections, update branding and adjust scope statements. Customised policies retain their framework linkages and version history.
KaitoSec provides an audit-ready policy register listing every active policy, current version, approval date, review cycle and linkage to Annex A controls. The same register serves NIS2, ISO 22301 and ISO 42001 evidence without re-export.
Yes. Acknowledgement requests are sent by email with a secure link. Recipients confirm they have read the policy in a browser, no account required. All acknowledgements are recorded and visible in the policy audit trail.