Skip to main content

Document Control

Formal document governance with versioning, approval workflows, and classification.

Document Control

Document control provides formal governance for your incident response playbooks. It tracks ownership, approval status, classification, distribution, and review schedules — essential evidence for ISO 27001 (Clause 7.5), Cyber Essentials+, and regulatory compliance.

Why document control matters

Auditors look for evidence that your incident response documentation is formally managed, reviewed regularly, and distributed to the right people. Document control provides this evidence automatically.

Setting Up Document Control

  1. Open any playbook from your playbook library.
  2. Click Set up document control at the top of the playbook. CrownSync auto-populates sensible defaults based on your organisation profile.
  3. Review and customise the document ID, owner, classification, and distribution list.
  4. Save to create the document control record.

Approval Workflow

Documents progress through a formal lifecycle:

  1. Draft — Initial creation or revision in progress
  2. In Review — Submitted for approval; approvers are notified
  3. Approved — All approvers have signed off
  4. Issued — Published and effective; review date is set
  5. Superseded — Replaced by a newer version
  6. Withdrawn — No longer in use

Classification Markings

CrownSync supports the UK Government Security Classifications plus common internal markings:

ClassificationUsage
OFFICIALDefault for most business documents
OFFICIAL-SENSITIVERequires additional handling controls
CONFIDENTIALRestricted to named individuals
SECRETHighly restricted distribution
INTERNALInternal use only
PUBLICSuitable for external publication

Review Scheduling

Each playbook can be set for quarterly, semi-annual, annual, or biennial reviews. CrownSync calculates the next review date automatically when a document is issued and alerts the document owner when a review is due or overdue.

Document Register Export

The Document Control dashboard provides a complete register of all managed playbooks. Export as CSV for audit evidence — this satisfies ISO 27001 Clause 7.5 requirements for documented information control.

Best Practices

  • Assign a clear owner for every playbook
  • Review annually at minimum; quarterly for critical playbooks
  • Version every change with a clear change summary
  • Use the distribution list to control who sees what
  • Export the document register before each audit

Was this page helpful?