Compliance
ISO 27001 compliance for document management
ISO/IEC 27001 certifies an information security management system, not a product. A document management system supports certification by evidencing specific Annex A controls — access control, logging and monitoring, secure disposal, and documented information — but the ISMS scope, risk assessment and policies remain yours.
What ISO 27001 certifies, and what it does not
ISO/IEC 27001 certifies an information security management system — a scope, a risk assessment, a set of selected controls and the evidence that they operate. It does not certify a product. No software can be "ISO 27001 certified" in the sense buyers often mean, and a vendor claiming their product makes you compliant is either confused or hoping you are.
What a document management system can do is provide evidence for specific Annex A controls, and remove the manual effort of producing it. That is a real and substantial contribution — for several controls the evidence is exactly the kind of record a document system generates as a byproduct of operating — but the management system remains yours and the audit is of you.
Annex A controls DocumentMS provides evidence for
| Control | What the standard asks for | What DocumentMS contributes |
|---|---|---|
| A.5.10 Acceptable use of information | Rules for acceptable use identified, documented and implemented | Policy library with per-user acknowledgement recorded against a specific version, reissued on supersession |
| A.5.12 Classification of information | Information classified according to confidentiality, integrity and availability needs | Classification as an enforced metadata field per document type, filterable and reportable |
| A.5.15 Access control | Rules for physical and logical access established and implemented | Role-based access per module with preview-only as a distinct level; per-document overrides visible rather than hidden |
| A.5.16 Identity management | Full lifecycle of identities managed | OIDC single sign-on so identity lifecycle is governed in the directory, not separately |
| A.5.18 Access rights | Access rights provisioned, reviewed, modified and removed | Shared-access overview listing every active share, and audit records of every permission change |
| A.5.33 Protection of records | Records protected from loss, destruction, falsification and unauthorised access | Immutable audit trail, version history, administrator-only recycle bin, retention rules with disposition review |
| A.8.10 Information deletion | Information deleted when no longer required | Retention rules by record class, disposition review with recorded authorisation, logged permanent deletion |
| A.8.12 Data leakage prevention | Measures applied to prevent unauthorised disclosure | Preview-only permission, IP restrictions, watermarking, and recorded access so disclosure is detectable |
| A.8.15 Logging | Logs recording activities, exceptions and events produced and protected | Append-only trail recording views and downloads, not editable by any role including administrators |
Where your ISMS still has to do the work
The scope statement, the risk assessment, the risk treatment plan and the statement of applicability are yours, and they are what an auditor examines first. A document system holds them under version control and evidences their approval, which is genuinely useful — but it cannot write them and cannot make them consistent with each other.
Physical security, supplier management, HR security, business continuity and most of the operational controls sit outside a document system entirely. The realistic contribution is that documented information and access-control evidence stop being a manual exercise, which is typically a meaningful fraction of the effort rather than most of it.
FAQ
ISO 27001 questions
Does using DocumentMS make us ISO 27001 compliant?
No, and no product can. Certification covers your management system: scope, risk assessment, selected controls and evidence they operate. DocumentMS provides evidence for several Annex A controls and removes manual effort from producing it. The ISMS remains yours.
Is DocumentMS itself certified?
No. Our controls are implemented and evidenced against the Annex A set and internally audited annually, but we hold no certificate and will not describe ourselves as certified until we do. That is a common and defensible position for a vendor at our stage, and claiming more is exactly what unravels during a security review when the certificate is requested.
How should we structure ISMS documents so an audit goes smoothly?
Tag every policy, procedure and piece of evidence with the Annex A control reference it supports, and tag evidence with the audit period it belongs to. An auditor asks "show me that this control operated during this period", and those two fields turn that into a two-clause filter rather than a hunt.
Can we see your statement of applicability?
Yes, under NDA. We share the full statement of applicability, including the controls marked not applicable and the justification for each, because the exclusions are the part worth reviewing. Ask your account contact and it goes out with the security questionnaire pack.
Zuletzt geprüft: 2026-09-01