Document Control
Formal document governance with versioning, approval workflows, and classification.
Document Control
Document control provides formal governance for your incident response playbooks. It tracks ownership, approval status, classification, distribution, and review schedules — essential evidence for ISO 27001 (Clause 7.5), Cyber Essentials+, and regulatory compliance.
Why document control matters
Setting Up Document Control
- Open any playbook from your playbook library.
- Click Set up document control at the top of the playbook. CrownSync auto-populates sensible defaults based on your organisation profile.
- Review and customise the document ID, owner, classification, and distribution list.
- Save to create the document control record.
Approval Workflow
Documents progress through a formal lifecycle:
- Draft — Initial creation or revision in progress
- In Review — Submitted for approval; approvers are notified
- Approved — All approvers have signed off
- Issued — Published and effective; review date is set
- Superseded — Replaced by a newer version
- Withdrawn — No longer in use
Classification Markings
CrownSync supports the UK Government Security Classifications plus common internal markings:
| Classification | Usage |
|---|---|
| OFFICIAL | Default for most business documents |
| OFFICIAL-SENSITIVE | Requires additional handling controls |
| CONFIDENTIAL | Restricted to named individuals |
| SECRET | Highly restricted distribution |
| INTERNAL | Internal use only |
| PUBLIC | Suitable for external publication |
Review Scheduling
Each playbook can be set for quarterly, semi-annual, annual, or biennial reviews. CrownSync calculates the next review date automatically when a document is issued and alerts the document owner when a review is due or overdue.
Document Register Export
The Document Control dashboard provides a complete register of all managed playbooks. Export as CSV for audit evidence — this satisfies ISO 27001 Clause 7.5 requirements for documented information control.
Best Practices
- Assign a clear owner for every playbook
- Review annually at minimum; quarterly for critical playbooks
- Version every change with a clear change summary
- Use the distribution list to control who sees what
- Export the document register before each audit
Was this page helpful?