Documented operating procedures
Purpose
Document operating procedures for information processing facilities and make them available to the staff who need them.
How to meet this control
In short: Document operating procedures and make them available to those who need them.
- Step 01Document runbooks for key operational tasks (backups, patching, onboarding, restores, deployments) and store them where operators can find them
- Step 02Include error handling, escalation contacts, restart and recovery steps and log management in each procedure
- Step 03Cover scheduling dependencies, capacity and performance monitoring and media handling where relevant
- Step 04Place procedures under version control and route changes through an authorised change process
- Step 05Review and update procedures when systems change and before handing tasks to new staff
Tip: Runbooks for key ops tasks (backups, onboarding, patching) satisfy this.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Prepare documented procedures for activities done the same way by many people or performed rarely
- ›Document procedures for new activities that carry risk if done wrong, and before handing work to new staff
- ›Specify the responsible individuals and the secure installation and configuration of systems
- ›Cover information processing and handling, backup, resilience and scheduling dependencies
- ›Include instructions for handling errors, support and escalation contacts, and media handling
- ›Document system restart and recovery procedures and audit trail and log management
- ›Describe monitoring of capacity, performance and security, plus maintenance instructions
- ›Review and update the procedures when needed, with authorised changes and consistent tools across systems
Audit evidence to keep
- - Documented operating procedures or runbooks for key operational tasks
- - Evidence procedures are accessible to the staff who need them
- - Version history showing procedures are reviewed and updated
- - Procedures covering error handling, escalation and recovery steps
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.37. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.