A.5.37A.5 Organizational controls

Documented operating procedures

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.37 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Document operating procedures for information processing facilities and make them available to the staff who need them.

How to meet this control

In short: Document operating procedures and make them available to those who need them.

  1. Step 01Document runbooks for key operational tasks (backups, patching, onboarding, restores, deployments) and store them where operators can find them
  2. Step 02Include error handling, escalation contacts, restart and recovery steps and log management in each procedure
  3. Step 03Cover scheduling dependencies, capacity and performance monitoring and media handling where relevant
  4. Step 04Place procedures under version control and route changes through an authorised change process
  5. Step 05Review and update procedures when systems change and before handing tasks to new staff

Tip: Runbooks for key ops tasks (backups, onboarding, patching) satisfy this.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Prepare documented procedures for activities done the same way by many people or performed rarely
  • ›Document procedures for new activities that carry risk if done wrong, and before handing work to new staff
  • ›Specify the responsible individuals and the secure installation and configuration of systems
  • ›Cover information processing and handling, backup, resilience and scheduling dependencies
  • ›Include instructions for handling errors, support and escalation contacts, and media handling
  • ›Document system restart and recovery procedures and audit trail and log management
  • ›Describe monitoring of capacity, performance and security, plus maintenance instructions
  • ›Review and update the procedures when needed, with authorised changes and consistent tools across systems

Audit evidence to keep

  • - Documented operating procedures or runbooks for key operational tasks
  • - Evidence procedures are accessible to the staff who need them
  • - Version history showing procedures are reviewed and updated
  • - Procedures covering error handling, escalation and recovery steps

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.37. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.