Zum Hauptinhalt springen

Link a document to a requirement

How to attach an existing document — a set of rules, a measure or an audit — to a requirement from your list of requirements in the “Links” section, and use it as evidence of implementation.

Last updated:

A requirement from ISO/IEC 27001 or BSI IT baseline protection only counts as evidenced in an audit if it is clear which document implements it. In the “Links” section you attach a document that already exists in the system — for example a set of rules, a measure (TOM) or an audit — directly to the requirement, instead of uploading it again as a file.

Prerequisites

  • At least one list of requirements has been loaded.
  • You have permission to edit requirements.
  • The document you want to link already exists.

Step by step

  1. Open the “ISMS cockpit” or the detail view of the list of requirements and click the requirement you want to evidence.
  2. Stay on the “Contents” tab and scroll to the “Links” section.
  3. Click “New”.
  4. Select the document type and then the document to be linked.
  5. Confirm the selection. The link then appears in the list in the “Links” section.

Adjust an existing link

  1. Open the link in the “Links” section.
  2. Under “Edit link”, edit the “Description” field and record which part of the requirement the document covers.
  3. Save the change.

What happens next

  • The process is logged in the activity history of the requirement (tab “Activities”).
  • Links complement the “Evidence” section: evidence holds uploaded or requested supporting files, while “Links” holds the documents maintained in the system.

A tip from practice: link the governing document (set of rules or measure) rather than every single file it contains. Link a set of rules that covers several requirements to each of those requirements, and use the “Description” field to note which section applies in each case. That keeps the implementation traceable even when the document is revised later.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms