1. Confidentiality level mandatory on each document?
Answer: The label displaying confidentiality level is mandatory only if control A.8.2.2 Labeling of information is applicable to your ISMS, because of results of risk assessment, legal requirements, or top management decision.
2. Confidentiality Statement for Employees: [name of contract on the basis of which the person will have access to confidential information], is this the employment contract?
Answer: This information can be in the employment contract for regular employees, but also can be on a service agreement for temporary employees. This situation must be considered on a case by c ase basis.
3. Do I also have to list the records and / or appendices in the 'Statement of Acceptance of ISMS Documents' ?
Answer: You have to make reference to all documents you want the person to state acknowledge to. For example, if the Backup policy is not referred on the 'Statement of Acceptance of ISMS Documents' the person cannot be held responsible for not complying with it.
< 4. Control A.11.2.1 Equipment siting and protection: I assume this does not include the work laptops of the employees, this only includes network and system architecture, right?
Answer: This control includes all equipment included in the ISMS scope, even work laptops of the employees. The mobile nature of laptops may also require additional controls related to security off-premises, but protection on premises is mostly accomplished by control A.11.2.1.
5. List of legal, regulatory, statutory and contractual requirements:
a) Do we have to document all the employment contracts, NDAs, SLAs, etc...?
Answer: Contracts normally have clauses establishing rights and duties regarding information security, and in these cases they must be documented.
b) Also, to be ISO 27001 certified, we don't have to be compliant with GDPR as an example right?
Answer: If you have to comply with some law or regulation that defines information security requirements related to your ISMS scope, then you need to be compliant with them to become ISO 27001 certified. For example if your ISMS scope handles EU citizens personal data, then you have to be compliant with EU GDPR Article 32.