New Zealand Information Security Manual (NZISM)
Chapter 5: Information security documentation – New Zealand Information Security Manual (NZISM)

New Zealand Information Security Manual (NZISM) 5.5.4.C.01: 5.5.4.C.01 Procedures required in the ITSM SOPs

The ITSM's SOPs should document procedures for the following topics, as set out in the table in this control: access control (authorising who may access applications and data); asset musters (labelling assets, media included, entering them in a register and mustering them); audit logs (reviewing manual logs and system audit trails, especially those relating to users with privileged access); configuration control (approving changes to configurations or system software and releasing them); information security incidents (detecting, reporting and managing potential incidents, establishing whether an incident's cause was accidental or deliberate, actions to recover and to minimise exposure, and further actions to prevent it happening again); data transfers (managing review of media holding classified information that is to go off-site, and review of media coming in for malware or software that is not approved); IT equipment (managing disposal and destruction of IT equipment and media that are no longer serviceable); system patching (advising on and recommending patches, updates and version changes in the light of advisories and security notices); system integrity audit (reviewing system parameters, user accounts and access controls to confirm the system is secure, verifying that system software has integrity, and testing the access controls); system maintenance (managing system software so it stays secure and functional over time, including keeping aware of current software vulnerabilities, testing and applying patches, updates and signatures, and applying suitable hardening techniques); and user account management (authorising new system users).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.37 Documented operating procedures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter 5: Information security documentation – New Zealand Information Security Manual (NZISM)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.