Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.37

Documented Operating Procedures: A Practical Implementation Guide

Give operators clear, current instructions for security-relevant tasks that must be performed consistently.

This control concerns documenting operating procedures for information-processing facilities and making them available to personnel who need them.

Practical interpretation: Procedures should reduce reliance on memory and individual knowledge. They must be usable during normal work, handovers, emergencies and staff absence.

What should the control achieve?

  • Security-relevant operations have appropriate procedures.
  • Instructions include roles, prerequisites, steps and evidence.
  • Current procedures are accessible and controlled.
  • Changes, exceptions and failures feed improvement.

Step-by-step implementation

1

Identify procedure needs

Prioritize complex, sensitive, infrequent, regulated or high-impact operations.

2

Write for execution

State purpose, scope, roles, prerequisites, ordered steps, decision points, rollback and escalation.

3

Include security controls

Cover authorization, segregation, logging, validation, evidence and recovery.

4

Test with users

Have another competent person perform the task using only the procedure.

5

Control publication

Assign owner, version, approval, access and review triggers.

6

Integrate change

Update procedures with system, risk, incident and process changes.

What this could look like in practice

A production restoration runbook lists authority to invoke, backup selection, integrity checks, restoration sequence, credentials, validation, communications and rollback. A second engineer tests it quarterly and records deviations.

ActivityPractical implementationEvidence
Routine operationDaily security monitoring has steps, thresholds and escalation.Completed checklist
Sensitive changeKey rotation uses dual control and rollback.Change and procedure record
Emergency recoveryRunbook remains available when normal systems fail.Exercise evidence
HandoverOutgoing operator transfers open issues and status.Shift log

Implementation evidence

  • Procedure inventory
  • Approved runbooks
  • Owners and review dates
  • Version history
  • Execution records
  • Test results
  • Change links
  • Exception and failure records

Useful metrics

  • Required procedures current
  • Procedures tested by another operator
  • Operational failures caused by unclear instructions
  • Overdue procedure updates

Common mistakes

  • Writing policy statements instead of executable steps.
  • Depending on screenshots that quickly age.
  • Storing procedures only in the affected system.
  • No rollback or escalation.
  • Updating technology without updating runbooks.
  • Documenting every trivial action while neglecting critical tasks.

Questions an auditor may ask

  • How do you decide which procedures need documentation?
  • Show a procedure another person can execute.
  • How are emergency procedures accessed?
  • How do changes trigger updates?
Implementation test: Ask a competent substitute to execute a critical task using only the approved procedure and record every ambiguity or missing prerequisite.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.