GRC

Document ManagerNew

Centralises your security policies, procedures, and governance documentation within the Hakware platform — ensuring the right documents are version-controlled, owned, reviewed on schedule, and linked to the controls they evidence.

Document Manager

Security policy and documentation management

What it does

Key capabilities

Policy Library

Store and manage all security policies, standards, and procedures in a centralised, searchable document repository.

Version Control

Track document versions and full revision history — always know what changed, when, and by whom.

Ownership & Review Cycles

Assign document owners and set review dates — the system flags documents approaching or past their scheduled review date.

Control Linkage

Link documents directly to ISO 27001, NIST, or CIS controls to demonstrate evidence coverage clearly during audits.

Access Control

Role-based access ensures sensitive policies and procedures are visible only to authorised team members.

Audit Evidence Packaging

Package relevant documents into an evidence bundle for compliance audits, regulatory submissions, and board reporting.

Highlights

Why Document Manager?

  • Centralised policy and procedure library with search
  • Full version history and revision tracking
  • Document owner assignment and review cycle management
  • ISO 27001, NIST, and CIS control evidence linkage
  • Role-based access control per document
Included in OneView

Document Manager is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Document Manager is designed for information security governance documents: Information Security Policy, Acceptable Use Policy, Access Control Policy, Business Continuity Plan, Incident Response Procedure, Data Classification Standard, Change Management Procedure, Third-Party Risk Assessment Framework, and any other procedure or standard that evidences ISO 27001 Annex A controls.

Each document has an assigned owner and a review frequency (annual, biannual, or custom). The platform calculates the next review date from the last approval date and flags documents approaching their review deadline in the dashboard. Overdue reviews are highlighted, and document owners receive notifications — preventing policies from becoming stale without a formal review record.

When adding or editing a document, you select which ISO 27001 Annex A controls (or NIST CSF/CIS Controls) the document evidences. These linkages appear in the Compliance Dashboards — the compliance percentage for a control reflects whether a linked, current document exists. This prevents a control from being scored as satisfied when the evidencing policy is outdated.

Auditors require evidence that policies exist, are current, have been reviewed, and are accessible to relevant staff. Document Manager's version history, review timestamps, owner records, and control linkages provide all of this evidence in a structured, auditable form. The evidence packaging feature lets you export all documents linked to a specific clause or Annex A control domain for auditor submission.

See Document Manager in action

Request a personalised demo and we'll show you exactly how Document Manager works within your environment.