New devices and systems are described in the chat exactly as they are. The platform updates the asset inventory, the related documents and their metadata: version, approver and review date.
No form and no separate spreadsheet: the list is enough as it is.
The asset inventory is updated, and the linked guidelines and risks are raised for review.
Version, editor, approver and the next review are logged automatically.
From question to answer and from answer to source: three clicks, no guesswork.
The answer states the rule, your own implementation and the control in the standard. Every point links to the document it came from.
The guideline shows the version, status, owner and approver, the practical implementation, responsibilities, the evidence for the audit and the items still open.
Confidential information is not left visible on the desk or the screen when the user leaves. This prevents unauthorised viewing, disclosure or theft.
Clear screen: defined in 3.1 Acceptable use policy: “Lock your screen when you leave the device, at the home office too.”
Clear desk: paper documents are hardly used at all.
The same chain continues to the control in the standard, so you can show the auditor directly which requirement your guideline answers.
Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.
ISO/IEC 27002 detailed guidance: 7.7 Clear desk and clear screen
See ISO/IEC 27002:2022 for the full implementation guidance, purpose, and other information.
A policy becomes an awareness and training module (7.3), the module a quick test, and the test a reading acknowledgement. Completions are logged per person, so awareness can be verified without a separate spreadsheet.
The module is the same document that is versioned and approved. When the policy changes, the training changes with it.
Go through the basic module below carefully (about 12 min to read). Scroll to the end, then take the test and sign the acknowledgement below.
About 18 min to read. After that, take the quick test (5 questions, pass mark 4/5) and sign the electronic acknowledgement in the system. The completion is visible to management and the CISO automatically.
If you meet an abbreviation you do not know, scroll to the section 16. Abbreviations and glossary.
Five questions about real work situations, pass mark 4/5. The test shows the guideline was read and understood.
The reading acknowledgement is logged against the person and the version as evidence of awareness. The acknowledgement rate shows in the status picture and can be shown to the auditor.
I have read the basic security training module (version 0.1) and commit to following the practices in it. I confirm this acknowledgement electronically with my own credentials.
Servers in the EU. No vendor lock-in: the data can always be exported out of the system.
A source link always, in every answer.
Changes, approvals and acknowledgements kept for the auditor.
Usable without training or technical support.
Version control, approvals and acknowledgements form an unbroken record chain. Every version and approval is traceable and verifiable from a single view.
Every document states who owns it, who approved it and which requirement it answers. The timeline shows what happened before this version.
Half an hour is enough to see what you already have in place and what is missing.