ISO/IEC 27001:2022 Annex A · Control 5.37
Documented Operating Procedures: A Practical Implementation Guide
Give operators clear, current instructions for security-relevant tasks that must be performed consistently.
This control concerns documenting operating procedures for information-processing facilities and making them available to personnel who need them.
What should the control achieve?
- Security-relevant operations have appropriate procedures.
- Instructions include roles, prerequisites, steps and evidence.
- Current procedures are accessible and controlled.
- Changes, exceptions and failures feed improvement.
Step-by-step implementation
Identify procedure needs
Prioritize complex, sensitive, infrequent, regulated or high-impact operations.
Write for execution
State purpose, scope, roles, prerequisites, ordered steps, decision points, rollback and escalation.
Include security controls
Cover authorization, segregation, logging, validation, evidence and recovery.
Test with users
Have another competent person perform the task using only the procedure.
Control publication
Assign owner, version, approval, access and review triggers.
Integrate change
Update procedures with system, risk, incident and process changes.
What this could look like in practice
A production restoration runbook lists authority to invoke, backup selection, integrity checks, restoration sequence, credentials, validation, communications and rollback. A second engineer tests it quarterly and records deviations.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Routine operation | Daily security monitoring has steps, thresholds and escalation. | Completed checklist |
| Sensitive change | Key rotation uses dual control and rollback. | Change and procedure record |
| Emergency recovery | Runbook remains available when normal systems fail. | Exercise evidence |
| Handover | Outgoing operator transfers open issues and status. | Shift log |
Implementation evidence
- Procedure inventory
- Approved runbooks
- Owners and review dates
- Version history
- Execution records
- Test results
- Change links
- Exception and failure records
Useful metrics
- Required procedures current
- Procedures tested by another operator
- Operational failures caused by unclear instructions
- Overdue procedure updates
Common mistakes
- Writing policy statements instead of executable steps.
- Depending on screenshots that quickly age.
- Storing procedures only in the affected system.
- No rollback or escalation.
- Updating technology without updating runbooks.
- Documenting every trivial action while neglecting critical tasks.
Questions an auditor may ask
- How do you decide which procedures need documentation?
- Show a procedure another person can execute.
- How are emergency procedures accessed?
- How do changes trigger updates?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.