ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.37: Documented operating procedures

Procedures for operating information processing facilities are to be written down and made available to the staff who need them. Purpose: make information processing facilities run correctly and securely. Guidance: document procedures for security-related operational activities, for example when many people must do the task the same way, when it is done so rarely that people will have forgotten how, when it is new and risky if done wrongly, or before it is handed to new staff. Procedures should state who is responsible; how systems are securely installed and configured; how information is processed and handled automatically and manually; backup (8.13) and resilience; scheduling needs and dependencies on other systems; how to deal with errors and exceptional conditions during jobs, including limits on utility programs (8.18); who to call for support or escalation, including outside suppliers, for unexpected operational or technical problems; storage media handling (7.10, 7.14); restart and recovery after system failure; management of audit trails and system logs (8.15, 8.17) and of video monitoring (7.4); monitoring of capacity, performance and security (8.6, 8.16); and maintenance. Procedures are reviewed and updated as needed, changes to them are authorized, and where technically possible systems are run consistently with the same procedures, tools and utilities.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 105 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 16 controls

  • 1.1.1 1.1.1 Requirement 1 policies and procedures governed
  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.2.1 2.2.1 System configuration standards maintained
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

ISO 22301:2019 · 10 controls

  • 4.4 Business continuity management system
  • 7.5 Documented information
  • 7.5.1 General
  • 7.5.2 Creating and updating
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 8.3.1 General
  • 8.4 Business continuity plans and procedures
  • 8.4.2 Response structure
  • 8.4.4 Business continuity plans

ISO/IEC 42001:2023 · 10 controls

  • 7.5 Documented information
  • 7.5.1 General
  • 7.5.2 Creating and updating documented information
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • A.5.3 Documentation of AI system impact assessments
  • A.6.2.6 AI system operation and monitoring
  • A.6.2.7 AI system technical documentation
  • A.7.2 Data for development and enhancement of AI system
  • A.8.2 System documentation and information for users

ISO 27701:2019 · 8 controls

  • 5.2.4 Information security management system
  • 5.4 Planning
  • 5.5 Support
  • 5.5.5 Documented information
  • 5.6 Operation
  • 5.6.1 Operational planning and control
  • 6.9 Operations security
  • 6.9.1 Operational procedures and responsibilities

NIST SP 800-53 Rev 5 · 8 controls

FedRAMP High · 5 controls

  • CM-9 Configuration Management Plan
  • CP-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • SA-10 Developer Configuration Management
  • SA-5 System Documentation

FedRAMP Moderate · 5 controls

  • CM-9 Configuration Management Plan
  • CP-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • SA-10 Developer Configuration Management
  • SA-5 System Documentation

HIPAA Security Rule · 5 controls

  • ISM-0042 System administration processes and procedures
  • ISM-1211 Administration under change and configuration management
  • ISM-1602 Communication of cyber security documentation
  • ISM-2084 AI model and system cards
  • A.7.2 A.7.2 Documented performance criteria and operational control procedures
  • B.6.11 B.6.11 Procurement and installation
  • B.9 B.9 Security policies and procedures

ISO/IEC 27041:2015 · 3 controls

  • 5.7.1 5.7.1 Overview
  • 5.7.2 5.7.2 Tool choice: guidance for deployment
  • 7.4 7.4 Maintenance of validation

NIST SP 800-66 Rev 2 · 3 controls

  • 5.5.4.C.01 5.5.4.C.01 Procedures required in the ITSM SOPs
  • 5.5.5.C.01 5.5.5.C.01 Procedures required in the system administrator SOPs
  • 5.5.6.C.01 5.5.6.C.01 Procedures required in the system user SOPs

CIS Controls v8 · 2 controls

  • CIS-12.4 Establish and Maintain Architecture Diagram(s)
  • CIS-4.1 Establish and Maintain a Secure Configuration Process

MTCS (Singapore) · 2 controls

  • 19.2 Operations management policies and procedures
  • 19.3 Documentation of service operations and external dependencies

SOC 2 · 2 controls

  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

C5 (Germany) · 1 control

  • C5-SP-01 Documentation, communication and provision of policies and instructions

CMMC 2.0 · 1 control

DORA · 1 control

GDPR · 1 control

  • GDPR-Art.29 Processing under the authority of the controller or processor

ISO 27001:2022 · 1 control

  • 5.37 Documented operating procedures

ISO 27018:2019 · 1 control

  • 12.1.1 Documented operating procedures
  • ISO29115-12.1 Documented Operating Procedures

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.37 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 105 it maps to, and the evidence behind each claim, over MCP and REST.