Zum Hauptinhalt springen

Publish and version a TOM

Publishing turns a TOM draft into a versioned, auditable state of your measures. This guide shows how to edit and publish a TOM document, review the Relationships tab as evidence, and use the resulting revision in audits.

Last updated:

As long as a TOM document carries the status “New” or “In progress”, it is a draft. Only publishing creates a versioned, auditable state of your measures that you can submit in an internal or external audit as proof of the level of protection effective at that time. This guide covers the path from the final edit through publishing to the evidence trail in the “Relationships” tab.

Prerequisites

  • You have access to the associated organization, or the TOM document is shared for “All organisations”.
  • You have the permission to edit and, in addition, the permission to publish.
  • You are in the detail view of the technical and organisational measure, tab “Contents”.

Step by step: edit and publish

  1. Open the overview of technical and organisational measures and click anywhere in the row of the table to open the detail view.
  2. Click “Edit” at the top right and complete the measures protection objective by protection objective — from “Ensuring confidentiality” through “Ensuring integrity” and “Pseudonymization and encryption” to “Ensuring availability, resilience and recoverability”.
  3. Click “Preview” at the top right to check the page-formatted version. Empty categories, duplicate measures and references to systems that no longer exist are much easier to spot here than in the individual input fields. Close the preview using the X at the top right.
  4. Click the green “Share” button. It appears only while the status is “New” or “In progress”; alternatively you will find “Share” in the “Actions” menu at the top right.
  5. The document moves to the “Published” status. A new revision is created automatically and can be viewed in the “Revisions” tab; the process also appears in the “Activities” tab.
  6. If a new version replaces the published state, move the old document to the “Archived” status via “Actions → Archive”.

Review the relationships as evidence

The “Relationships” tab shows in three areas what the published state of your measures actually stands for — exactly the information an audit asks for.

  1. Open the “Relationships” tab.
  2. Under “Uses”, check which documents rely on this TOM document, among them “Data processing systems”, “Security incidents”, “Contracts for data processing” and “Processing activities”. The gap between the documented measures and the systems actually in operation is the most common audit finding.
  3. Under “Collaboration & functions”, review the attached “Risk analyses”, “Tasks”, “Checklists” and “Surveys”. The risk analyses make it traceable which risks are reduced by which measure; tasks and follow-ups document the regular effectiveness review.
  4. Under “Linked documents”, check whether the state inherits from a group template or has been passed on to subsidiary organizations via “Create linked document”.
  5. To hand the published state over to auditors, export it via “Actions → Download as PDF” or “Download as DOCX”.

Practical tips

  • Do not publish a TOM document until you have reviewed it at least once, protection objective by protection objective. Publishing creates an archivable revision that later serves as proof of the level of protection effective at that time — gaps or contradictions can hardly be remedied afterwards.
  • Use the “Preview” before every external handover, for example for an audit request or as an attachment to a contract.
  • Observers and assigned users are notified about the publication by email and in the application — so add the people responsible before you publish.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms