ISO 27001 Annex A 5.37 Documented Operating Procedures (The Unofficial Zero BS Guide)

ISO 27001 Annex A 5.37

ISO 27001 Annex A 5.37 Documented operating procedures requires teams to write down clear instructions for information processing facilities. Documented rules ensure system stability, reduce human error, and keep operations secure.

Key Takeaways

  • Document operational processes: Create clear, step-by-step instructions for routine technical tasks and system management workflows.
  • Store guides centrally: Keep all standard operating procedures in a central document repository with formal version controls.
  • Standardise routine tasks: Define explicit steps for system backups, server reboots, patch cycles, and account setups.
  • Maintain formal change management: Update operating documents whenever infrastructure, software, or technical setups change.
  • Ensure operational continuity: Provide clear documentation so team members can run systems smoothly without relying on key individuals.
  • Include incident handling steps: Document emergency restart actions, system failure responses, and escalation paths.
  • Review procedures regularly: Conduct periodic reviews to ensure operational instructions match live production environments.
  • Control procedure access: Restrict edit rights to authorised engineers while making guides easily available to relevant staff.

How to Implement ISO 27001 Annex A 5.37

  • Identify core operations: List all key administrative tasks, backup routines, infrastructure builds, and maintenance schedules.
  • Write clear runbooks: Produce simple, step-by-step operating guides and store them in your central document repository.
  • Define error handling steps: Include clear instructions for handling unexpected system errors, failed jobs, and hardware faults.
  • Set review schedules: Establish planned calendar triggers to re-verify and approve procedure accuracy at least once per year.
  • Implement version control: Track document changes, author names, review dates, and management approvals inside your repository.
  • Protect sensitive details: Redact hard-coded credentials and administrative secrets from procedures, using secure vaults instead.
  • Train operational staff: Walk technical workers through written procedures during onboarding and operational handovers.
  • Link to change management: Make updating operating documentation a mandatory condition for closing infrastructure change tickets.
  • Test emergency steps: Carry out simulated system recovery drills using only written procedures to verify instructions work.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Annex A 5.37

  • Review procedure inventories: Check the central repository to confirm documented operating guides exist for all critical systems.
  • Verify version histories: Inspect document revision logs to confirm operating procedures are up to date and formally approved.
  • Observe operational tasks: Watch engineers carry out routine maintenance or backups to verify they follow documented instructions.
  • Check change request links: Sample completed change tickets to verify teams updated relevant runbooks alongside system changes.
  • Assess error instructions: Inspect procedures to confirm they contain clear troubleshooting steps and escalation contacts.
  • Audit access permissions: Verify that read and write permissions on operating documents are strictly managed and restricted.
  • Check secret protection: Inspect documentation to ensure no plain-text passwords or sensitive access keys appear in guides.
  • Interview technical staff: Speak with system administrators to verify they know where to access current operating manuals.

Audit Evidence Checklist

  • Documented operating procedures: Maintain written runbooks and system maintenance manuals in your central repository.
  • Document review logs: Supply approval records showing annual reviews and sign-offs for all active operating guides.
  • Backup operating instructions: Provide documented steps covering routine backup execution, verification, and restoration.
  • Change management records: Supply closed change tickets showing documentation updates completed during system upgrades.
  • System restart runbooks: Produce step-by-step startup, shutdown, and recovery instructions for key infrastructure.
  • Access permission registers: Supply access lists proving only authorised authors can edit central operational documents.
  • Staff training records: Show attendance logs proving technical staff completed onboarding on standard operating procedures.

What to Teach Employees

  • Follow written instructions: Teach engineers to follow standard runbooks rather than relying on memory for complex tasks.
  • Update documentation promptly: Instruct workers to update procedures immediately whenever system workflows or setups change.
  • Report procedure errors: Encourage staff to flag incorrect, outdated, or confusing steps in existing operational manuals.
  • Protect operational secrets: Warn staff never to record private keys, master passwords, or sensitive client data inside runbooks.
  • Use central repositories: Remind teams to store all procedures in the central hub rather than keeping private local notes.
  • Know escalation paths: Teach staff how to use procedure escalation contacts when encountering unlisted operational errors.

Common Implementation Challenges

  • Outdated instructions: Teams change systems quickly and forget to update runbooks. Make documentation sign-off part of change control.
  • Siloed team knowledge: Key individuals hold operational steps in their heads. Mandate thorough documentation before project sign-off.
  • Scattered procedure files: Instructions stay spread across personal notes and chat threads. Consolidate all guides into a single central hub.
  • Overly complex documentation: Long, confusing documents lead staff to ignore guides. Write concise, checklist-style instructions.
  • Exposing sensitive secrets: Engineers write plain-text passwords directly into manuals. Enforce central secrets management tools.
  • Lack of regular testing: Untested instructions fail during real operational outages. Run regular tabletop drills using only written runbooks.

How to Measure Effectiveness (KPIs)

  • Procedure coverage rate: Track the percentage of critical systems supported by complete, approved operating runbooks.
  • Annual review compliance: Measure the proportion of operating procedures reviewed and approved within the last twelve months.
  • Change documentation rate: Track the percentage of technical change tickets that successfully updated relevant operating guides.
  • Operational incident count: Track the number of system outages or downtime events caused by human operational error.
  • Outdated document discovery rate: Count the number of out-of-date or inaccurate runbooks identified during quarterly checks.
  • Procedure audit finding count: Monitor the number of non-conformities raised against operating procedures during internal audits.

ISO 27001 Control A 5.37 connects to several other ISO 27001 requirements:

ISO 27001 Documented Operating Procedures Explained - Annex A 5.37 - High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply