Our clients are asking us what policies we have (as past of our IS 27001 Certification). Since the toolkit is mixing up terms, can you please list what policies are mandatory for ISO 27001? Once we have this list, we can check that we have the documents labelled correctly. For instance, take the example below, is document 11.A.16 a policy document or a procedure document?
Regarding the main clauses of ISO 27001, only the Information Security Policy is required (to fulfill clause 5.2). Regarding Annex A controls, you must consider these policies as mandatory if there are risks which would require their implementation (i.e., controls related to these policies are stated as applicable on the Statement of Applicability):
- Access control policy (if clause A.9.1.1 is applicable on SoA)
- Supplier security policy (if clause A.15.1.1 is applicable on SoA)
The document "11.A. 16_Data_Breach_Response_and_Notification_Procedure_Integrated_EN" is in fact a procedure (its ISO 27001 equivalent is the Incident Management Procedure). It is im portant to note that in the context of ISO 27001 the division between policies and procedures is not very important.