PAL Contents - File Location, Use
| Management\Function Folder | Document Type Subfolders | Content Description | Subfolders allowed | Classification | |
| Backup and Recovery | |||||
| Backup and Recovery | Flowcharts | Backup and Recovery Flowcharts folder contain process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Backup and Recovery | Process and Procedure | Backup and Recovery Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Backup and Recovery | Program Definition | Backups and Recovery Program Definition folder contain program profile documentation. | No | Confidential | |
| Backup and Recovery | Template | Backup and Recovery Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Change Management |
|||||
| Change Management | Flowcharts | Change Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Change Management | Process and Procedure | Change Management Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Change Management | Program Definition | Change Management Program Definition folder contains program profile documentation. | No | Confidential | |
| Change Management | Template | Change Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Configuration Management |
|||||
| Configuration Management | Flowcharts | Configuration Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Configuration Management | Process and Procedure | Configuration Management Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Configuration Management | Program Definition | Configuration Management Program Definition folder contains program profile documentation. | No | Confidential | |
| Configuration Management | RunBook CMDB | Configuration Management RunBook CMDB folder contains RunBook process and guidelines. | Temporary/ Until all data is moved to database | Confidential | |
| Configuration Management | Module Configuration | Configuration Management Solutions Development-Client Configuration folder contains program profile documentation. This is limited to the area of Master Template configuration guidelines | Subfolder as needed | Confidential | |
| Configuration Management | Template | Configuration Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Human Resources |
|||||
| Human Resources | Flowcharts | Human Resources Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Human Resources | Process and Procedure | Human Resources Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Human Resources | Program Definition | Human Resources Program Definition folder contains program profile documentation. | No | Confidential | |
| Human Resources | Template | Human Resources Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Network Management |
|||||
| Network Management | Architectures | Architecture as Diagrams, long-term strategic IT Vision, infrastructure planning and technical documentation. | Subfolder as needed |
Sensitive |
|
| Network Management | Flowcharts | Network Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Network Management | Process and Procedure | Network Management Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Network Management | Program Definition | Network Management Program Definition folder contains program profile documentation. | No | Confidential | |
| Network Management | Template | Network Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Performance Management |
|||||
| Performance Management | Flowcharts | Performance Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Performance Management | Process and Procedure | Performance Management Process and Procedure folder contain process profile documentation. This area includes database process optimization. | No | Confidential | |
| Performance Management | Template | Performance Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Process Engineering Management |
|||||
| Process Engineering Management | Flowcharts | Process Engineering Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Process Engineering Management | Process and Procedure | Process Engineering Management Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Process Engineering Management | Process Profile | Process Engineering Management Process Profile folder contains program profile documentation. | No | Confidential | |
| Process Engineering Management | Template | Process Engineering Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
| Product Management | |||||
| Product Management | Flowcharts | Product Management Flowcharts folder contains process flow diagrams including those used in the process and procedure documentation. | No | Confidential | |
| Product Management | Process and Procedure | Product Management Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Product Management | Program Definition | Product Management Program Definition folder contains program profile documentation. | No | Confidential | |
| Product Management | Template | Product Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Quality Assurance |
|||||
| Quality Assurance | Flowcharts | Quality Assurance Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Quality Assurance | Process and Procedure | Quality Assurance Process and Procedure folder contain process profile documentation. | No | Confidential | |
| Quality Assurance | Program Definition | Quality Assurance Program Definition folder contains program profile documentation. | No | Confidential | |
| Quality Assurance | Template | Quality Assurance Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Security Management |
|||||
| Security Management | Flowcharts | Security Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Security Management | Process and Procedure | Security Management Process and Procedure folder contains process profile documentation. | No | Confidential | |
| Security Management | Program Profiles | Security Management Program Profiles folder contains program profile documentation. | No | Confidential | |
| Security Management | Program Test Plans | Security Management Program Test Plans folder contains security specific program control test plans. | No | Confidential | |
| Security Management | Template | Security Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Software Development |
|||||
| Software Development | Flowcharts | Software Development Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Software Development | Process and Procedure | Software Development Process and Procedure folder contains process profile documentation. | No | Confidential | |
| Software Development | Program Profiles | Software Development Program Profiles folder contains program profile documentation. | No | Confidential | |
| Software Development | Template | Software Development Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Standard Operation Procedures |
|||||
| Standard Operation Procedures | Forms | No | Confidential | ||
| Standard Operation Procedures | General Use Flowcharts | Standard Operation Procedures General Use Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Standard Operation Procedures | RunBook | Output of the RunBook Database is a paper copy of the RunBook. RunBooks live in the database, but a single paper copy may be posted here as SAS70 summary evidence. This folder could also be removed. | No | Confidential | |
| Standard Operation Procedures | SOP By Domain | Standard operating procedures are any set of directions used to maintain or operate any production system. | Folders should be set but if an area is needed/ add | Confidential | |
| Standard Operation Procedures | …\Citrix …\Desktop …\LAN Access Distribution …\Oracle DB …\Oracle Server …\SQL Server …\Unix …\VPN …\WAN Backbone …\WINTEL | Each folder is a holding place for short instructions related to the maintenance and care of any technology type. If a person creates any work instructions, be it in email or as a word file, this a place to store a record of the work so that the SOP doesn't have to be created again. SOP is less strict than process in that the owner of the technology maintains their current instructions and does not require approval to add to their folder. Manager is responsible for insuring that any high risk process is documented and that the process could be followed by a person of equal skill in the event that the primary support staff was not available. | Sub folder as needed for specific servers and systems. | Sensitive | |
| Standard Operation Procedures | Template | Standard Operation Procedures Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
|
Support Management |
|||||
| Support Management | Flowcharts | Support Management Flowcharts folder contains process flow diagrams including those used in process and procedure documentation. | No | Confidential | |
| Support Management | Process and Procedure | Support Management Process and Procedure folder contains process profile documentation. | No | Confidential | |
| Support Management | Program Definition | Support Management Program Definition folder contains program profile documentation. | No | Confidential | |
| Support Management | Template | Support Management Template folder contains shortcuts to approved templates and forms as required for this management function. | No | Confidential | |
| IT Work Product Library | |||||
|
Change Management |
|||||
| Change Management | Production Release and Change Review Meetings | This area will be relocated to RiskConsole once the Change Management program is operational | No | Confidential | |
| Change Management | …\Agendas …\Meeting Minutes | Change requests and change review meeting records | No | Confidential | |
|
Network or Data Center Operations Planning and Infrastructure |
|||||
| Network or Data Center Operations Planning and Infrastructure | Infrastructure Planning | Documentation pertaining to infrastructure planning and development including any current projects. This area will support numerous project specific subfolders. | No | Confidential | |
| Network or Data Center Operations Planning and Infrastructure | …\patch | Create a folder for infrastructure item and keep all planning for that change or project in the folder | Sub folder on a per project basis | Confidential | |
| Network or Data Center Operations Planning and Infrastructure | Performance Management | Output of monitoring performance, shows evidence of monitoring activity | Sub folder on a per monitoring area as needed | Confidential | |
|
Process Meeting Minutes |
|||||
| Process Meeting Minutes | Meeting Minutes and Review Planning | Meeting Minutes and approvals for Process Engineering team and program | No | Confidential | |
|
Product Management |
|||||
| Product Management | Meetings | Meetings pertaining to any release are captured and stored here | No | Confidential | |
| Product Management | Project Planning | Release tasks by release and other evidence of project structure | No | Confidential | |
| Product Management | Requirements | Current list of requirements belongs in VSS, but this location is an evidence pointer showing the requirements in play and recent past. This folder should have a short cut the actual location in VSS and someone who can walk the auditor through those folders. | No | Confidential | |
| Product Management | [Company Core Product or Service] Release Notes | Past and current release notes, evidence folder | No | Confidential | |
| Product Management | Module Configuration | Output of planning for Master Template service related tasks. | Subfolder as needed | Confidential | |
| Product Management | Status Reports | Staff reports to managers regarding work activity |
Sensitive |
||
|
Product Training |
|||||
| Product Training | [Company Core Product or Service] User Guide-External | Product training output/ evidence folder | No | Confidential | |
| Product Training | [Company Core Product or Service] User Technical Guide-Internal | Product training output/ evidence folder | No | Confidential | |
|
Quality Assurance |
|||||
| Quality Assurance | Quarterly Reports | Documentation pertaining to infrastructure planning and development including any current projects. This area will support numerous project specific subfolders. | Subfolders created by quarter as needed | Confidential | |
| Quality Assurance | [Company Core Product or Service] QA Testing By Release | Test planning documentation and a link to the current tests in Test in Product. This is a "pointer file" used to assist auditor in finding the evidence. | Subfolders are not limited. This is a place to store in process work. | Confidential | |
| Quality Assurance | Test Output | Used to gather the Internal Controls Testing Plans and the most current snapshot of testing as used for evidence in the upcoming SAS 70. The actual testing information must reside in its secure location within Test Director. This is an output for evidence purposes only. | Subfolders limited to the Internal Control Testing program | Confidential | |
| Quality Assurance | fs02 main Quality Assurance | the QA folder on FILESSHARE should be relocated to the process and work product areas. | Confidential | ||
|
Release-Software Development |
|||||
| Release-Software Development | Release Plan-Evidence Copy for current review cycle | Documentation in VSS must remain in VSS. This is a pointer file and demonstration of current content on current release. VSS link should be here. | No | Confidential | |
| Release-Software Development | Release Request | Email outtakes and meeting notes where a release related activity is requested. Release requests live in Development Software, but can start as emails or notes. This is where the document record is stored. All details would show up as a Development Tracking ID. | No | Confidential | |
| Release-Software Development | [Company Core Product or Service] | Design Specifications from VSS are here as process evidence and are read-only. This is a placeholder for audit data. Auditors should not be in VSS clicking through directories as this would raise issues around items that are out of date. Better strategy is to put what we want to show here. | No | Confidential | |
|
Security Management |
|||||
| Security Management | Exemption Requests | Business requests for policy exception-based in need to maintain operations with given technology constraints. All exemptions should also be logged in a table where CSO can maintain visibility on such items. RC is a good candidate for this, especially as tied to Risk area. | No |
Sensitive |
|
| Security Management | ...\Situation Evaluation Forms | Output of situation review and decisions based on Exceptions to policy. | No |
Sensitive |
|
| Security Management | Meetings Notes and Incident Review Records | Meeting notes from any security meeting or incident response meeting | No |
Sensitive |
|
| Security Management | ...\ Agendas …\Minutes | Recommend a format for file name that shows Security, date and meeting type. Agenda can be a place holder for meeting plans and meeting minutes are just meeting minutes. | No |
Sensitive |
|
| Security Management | Program Policy Approval | Email outtakes and copy of documents indicating approval to implement security programs. I have a concern about storing electronic image of signatures and request that files state that signature is locked in a file. | Straight evidence folder/ NO |
Sensitive |
|
| Security Management | Security Infrastructure and Program Planning | Infrastructure planning document and information related to the planning of any security program. | Create a subfolder for any program. |
Sensitive |
|
| Security Management | …\Awareness | Awareness program documents, including planned presentations and documents for the development of the program | Subfolder as needed |
Sensitive |
|
| Security Management | Test Output | DS5 related internal control test plans and output | One folder per program tested |
Sensitive |
|
| Security Management | Tracking and Reconciliation Reports | Output of security scans and processes. | Subfolder as needed |
Sensitive |
|
| Security Management | …\Tools ….\...\Last Login Scripts …\...\...\enterprisegrc Domain …\...\...\Company Domain | Evidence of security monitoring activity | Subfolder as needed |
Sensitive |
|
This template is my own creation. I published it first on PBSP.COM as procedureguidelines.html in December of 2003 as part of my graduate work for my Masters in IT. It was published in the ISACA Journal in 2005. I can't count the number of companies that took this and sold it to the world, but it was always here with me, and it was always free.
Copyright © 2006 ISACA. All rights reserved. www.isaca.org.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics