ISO 27001 Annex A 5.37 Documented Operating Procedures Explained

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Documented Operating Procedures

Moving from ad-hoc, informal processes to a structured, documented framework is a critical step in maturing an organisation’s security posture. Control 5.37 provides the framework for this essential transition, transforming tribal knowledge into a durable corporate asset.

Key Takeaways

ISO 27001 Annex A 5.37 is a control that requires organizations to create, maintain, and follow detailed written instructions for all information security tasks. Its primary goal is to minimise the risk of human error and ensure that critical security processes, like backups and system updates, are performed consistently regardless of who is doing the work.

Purpose

The core purpose is to create a repeatable operational environment. This removes ambiguity and reliance on individual memory, a crucial factor for scalable security.

Definition

The official requirement of ISO 27001:2022 Annex A 5.37 states:

“Operating procedures for information processing facilities should be documented and made available to personnel who need them.”

Explanation

ISO 27001 Annex A 5.37 is a security control that mandates organizations to establish, maintain, and enforce documented standard operating procedures for all critical information processing facilities. The core business benefit is ensuring operational continuity and significantly reducing human error during technical tasks.

Requirement

  • Standard Operating Procedures (SOPs): You must document “recipes” for critical tasks (e.g., user offboarding, patch management, and error handling).
  • Accessibility: Procedures must be readily available to the specific staff members who need them; they cannot be hidden in a generic policy folder.
  • Change Management: Documents must be treated as living records. They require review (at least annually) and must be updated whenever systems change.
  • Audit Verification: Auditors will test that these documents are not just written, but actively used and accurate to the current technical environment.

FREE Training Video

In this free training video you will learn How to implement ISO 27001 Documented Operating Procedures (Annex A 5.37) and Pass Your Audit.

Implementation Guide

The headline guidance is, document all of your process and procedures. Do it to a level that is appropriate to you. Consider documenting common exception steps or steps in the process when the process does not go as intended.

Identify When Procedures Are Needed

You need to start creating these procedures during the planning and implementation phase of your ISO 27001 Information Security Management System (ISMS). They’re a core part of building a robust security framework.

The standard gives examples such as

  • when a procedure is performed by many people and needs to be done in the same way
  • when something is performed rarely and can be forgotten when it is needed again
  • when you do something new and if not done correctly it will create a risk
  • before someone else is taking on the procedure

Documenting Procedures

You need to document every process that you do for information security. The list is long. Take every process that you do for information security and document it. The standard provides examples which are basically the processes and procedures of the standard. The following is the bare minimum:

  • document secure installation and configuration
  • document processing and handling of information, include manual and automatic methods
  • document backups and resilience
  • document scheduling requirements
  • document interdependencies between systems
  • document instructions for handling errors
  • document support and escalation contacts
  • document storage media handling
  • document restart and recovery procedures
  • document the management of audit logs, system logs, video monitoring, audit trails
  • document capacity management
  • document maintenance

Essential SOP Checklist

Procedure NamePriorityWhy?
New User SetupHighEnsuring least privilege is applied every time.
Leaver ProcessCriticalEnsuring access is revoked immediately.
Backup & RestoreCriticalTesting that data can be recovered (Auditor favorite).
Patch ManagementHighHow/When servers are updated.
Antivirus ResponseMediumWhat to do if a virus alert pops up.
Change ManagementHighHow to approve and deploy code changes.

Review, Approval, and Distribution of Documents

Drafts must be formally approved by management and stored in a central repository (e.g., SharePoint/Intranet) accessible to all staff.

Updating procedures

Update and review procedures as needed but at least annually. The standard does not say at least annually. But it will catch you out if you do not.

How to write procedures

Writing these procedures is a team effort. You should:

  • Keep it simple: Use plain language that anyone can understand.
  • Define the purpose: Explain why this procedure is important.
  • List the steps: Break down the task into clear, numbered steps.
  • Assign responsibilities: Make it clear who does what.
  • Get it approved: Have the right people sign off on the procedure.

Authorising changes to procedures

When you change something, that change needs to be authorised with some evidence that the authorisation took place.

CEO at High Table: The Compliance Agency

How to implement it

Implementing ISO 27001 Annex A 5.37 ensures that your organisation maintains consistent, secure, and reliable information processing operations. As an ISO 27001 Lead Auditor, I look for technical evidence that procedures are not just written, but are actively utilised and governed. Follow these ten technical steps to formalise your documented operating procedures and satisfy rigorous audit requirements.

1. Provision an Inventory of Information Processing Facilities

Provision a comprehensive list of all systems and facilities within the organisational Asset Register: result: ensures all hardware, software, and cloud instances requiring documented instructions are identified and scoped.

  • Identify all critical infrastructure components, including servers, networks, and cloud storage.
  • Map technical dependencies between systems to determine where procedures must overlap.
  • Assign an “Asset Owner” for every facility to take responsibility for procedure maintenance.

2. Formalise Standard Operating Procedures for Routine Activities

Formalise detailed instructions for daily, weekly, and monthly system activities: result: establishes a consistent baseline for backups, system restarts, and scheduled technical maintenance.

  • Document specific commands and configurations for starting and stopping systems.
  • Define the exact steps for performing and verifying system backups.
  • Outline procedures for the handling and disposal of information media.

3. Implement Strict Version Control and Document Governance

Implement a formal document control system for all technical procedures: result: prevents the use of obsolete instructions and ensures a clear audit trail for management updates.

  • Utilise unique identifiers and version numbers for every operational document.
  • Record the date of the last review and the name of the individual who approved the content.
  • Automate the archiving of superseded documents to prevent operational errors.

4. Provision Restricted Access via Identity and Access Management

Provision restricted access to sensitive procedures using Identity and Access Management (IAM) roles: result: ensures that only authorised personnel with a legitimate business need can view or modify technical instructions.

  • Apply the Principle of Least Privilege to the centralised procedure repository.
  • Mandate Multi-Factor Authentication (MFA) for any user with “edit” permissions on procedures.
  • Audit access logs monthly to identify any unauthorised attempts to access sensitive technical data.

5. Formalise Emergency Operating and Incident Response Instructions

Formalise high-priority instructions for system failures or security incidents: result: enables rapid recovery and maintains system availability during unexpected outages or cyber attacks.

  • Create “Runbooks” for specific disaster recovery scenarios and known incident types.
  • Document contact details and escalation paths for third-party vendors and internal leads.
  • Ensure instructions include the technical steps for isolating compromised systems.

Audit the content of all operating procedures to ensure compliance with external mandates: result: confirms that technical operations meet statutory requirements like GDPR, NIS2, or DORA.

  • Review procedures for data handling to ensure they align with privacy legislation.
  • Verify that retention periods for logs and backups meet legal and contractual requirements.
  • Document how procedures satisfy specific clauses in the organisation’s Legal Register.

7. Provision a Centralised and Secure Source of Truth

Provision a single, secure digital repository for all documented procedures: result: facilitates timely retrieval by operational staff and provides a clear evidence base for auditors.

  • Ensure the repository is highly available and resilient to local system failures.
  • Organise the structure by system or department to allow for rapid navigation.
  • Enable full-text search capabilities to help staff find instructions during high-pressure events.

8. Formalise a Technical Review and Approval Workflow

Formalise a structured workflow for the creation and updating of procedures: result: ensures that all operating instructions remain technically accurate and aligned with organisational risk appetite.

  • Require a technical peer review for any change to core system procedures.
  • Obtain management sign-off for procedures that impact critical business continuity.
  • Schedule mandatory review cycles for every document, typically occurring every twelve months.

9. Implement Training and Competency Assessments

Implement formal training sessions for all staff expected to execute documented procedures: result: verifies that personnel can perform their duties correctly and securely in accordance with policy.

  • Conduct practical walkthroughs of procedures for new starters and contractors.
  • Document attendance and the results of competency tests to provide audit evidence.
  • Update training materials immediately following any significant change to technical instructions.

10. Audit Operational Effectiveness Through Drills and Spot Checks

Audit the practical application of documented procedures through regular technical drills: result: identifies gaps between theoretical instructions and operational reality for continual improvement.

  • Conduct “Tabletop” exercises to test the clarity and effectiveness of emergency procedures.
  • Perform unannounced spot checks to ensure staff are following the “live” version of instructions.
  • Record all drill findings in the Corrective Action Log to drive necessary technical updates.

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.37 Documented Operating Procedures Templates
ISO 27001 Templates

How to audit it

Auditing ISO 27001 Annex A 5.37 requires a technical deep dive into how your organisation maintains and executes its operational instructions. As a Lead Auditor, I look for evidence that your procedures are not merely static documents, but are accurate, accessible, and consistently applied to ensure system stability and security. Use this 10 step technical roadmap to ensure your documented operating procedures are robust enough to withstand a rigorous certification audit.

1. Audit the Inventory of Information Processing Facilities

Audit the Asset Register to confirm that all hardware, software, and cloud services requiring operational instructions are identified: result: ensures the audit scope covers 100 per cent of critical information processing facilities.

  • Verify that the inventory includes specific technical details for production, test, and development environments.
  • Check that every identified facility has a corresponding set of documented procedures.
  • Confirm that the inventory is current and reflects the latest architectural changes.

2. Inspect Technical Accuracy and Procedural Relevance

Inspect a sample of procedures against the live system configurations to verify technical accuracy: result: ensures that staff are following instructions that actually work in the current environment.

  • Compare documented startup and shutdown sequences against actual system behavior.
  • Verify that technical commands listed in the procedures are valid and safe for execution.
  • Check for “Shadow IT” processes that are being performed without formal documentation.

3. Audit Version Control and Governance Logs

Audit the document management system to ensure that only the latest, approved version of an operating procedure is accessible: result: prevents operational failures caused by the use of obsolete or unverified instructions.

  • Check for unique document identifiers and incremental version numbers.
  • Verify that the history of changes is documented, including who authorised the update.
  • Confirm that superseded documents are clearly marked as archived or are removed from staff access.

4. Verify IAM Roles and Access Permissions for Procedures

Verify that access to sensitive technical procedures is restricted via Identity and Access Management (IAM) roles: result: enforces the principle of least privilege and protects sensitive operational secrets.

  • Inspect permissions for the procedure repository to ensure read/write access is limited to authorised staff.
  • Confirm that Multi-Factor Authentication (MFA) is required to access the centralised document store.
  • Review access logs for any anomalous or unauthorised attempts to download operational runbooks.

5. Audit Backup and Verification Logs

Audit the logs for backup execution and verification as defined in the documented procedures: result: provides evidence that data availability requirements are being met consistently.

  • Review a sample of backup logs to ensure successful completion within defined timeframes.
  • Check for records of restoration testing to prove that backup data is usable.
  • Verify that the backup procedure includes instructions for the secure handling of physical or cloud-based media.

6. Inspect Emergency Operating Procedures and Runbooks

Inspect the availability and clarity of high-priority instructions for system failures or security incidents: result: ensures the organisation is technically prepared to maintain availability during an outage.

  • Verify that emergency procedures are accessible even if the primary network is unavailable.
  • Check that runbooks include updated contact lists for third-party support and internal escalations.
  • Confirm that instructions for failing over to redundant systems are clearly documented and tested.

Audit procedures to ensure technical data handling aligns with the organisational Legal Register: result: confirms that information processing meets requirements for GDPR, DORA, or other relevant legislation.

  • Check that record retention periods specified in procedures match legal requirements.
  • Verify that procedures for information disposal include secure destruction methods.
  • Review audit trail requirements within the procedures to ensure forensic readiness.

8. Verify the Regular Review and Approval Cycle

Verify that operating procedures are reviewed by technical leads at planned intervals: result: maintains the integrity of the ISMS by ensuring documentation evolves with the infrastructure.

  • Check metadata to confirm that procedures have been reviewed within the last twelve months.
  • Inspect the credentials of the individuals performing the technical reviews to ensure competency.
  • Verify that management has signed off on any significant changes to operational logic.

9. Audit Training Records and Staff Competency

Audit the training logs to confirm that staff have been briefed on the procedures they are required to execute: result: reduces the risk of human error causing a security breach or system downtime.

  • Interview a sample of operational staff to verify their understanding of documented instructions.
  • Check for training certificates or records of practical walkthroughs for new systems.
  • Verify that training is updated and delivered immediately following a major procedural change.

Validate that technical changes to systems trigger an automatic update to the relevant operating procedures: result: ensures that documentation remains synchronised with the live production environment.

  • Review the Change Management Log for recent infrastructure deployments.
  • Cross-reference change requests with corresponding updates in the procedure repository.
  • Audit the closure of change tickets to ensure “Documentation Updated” is a mandatory requirement.

Why Documented Operating Procedures are Crucial

  • Consistency and Reduced Errors: Uniformity is the best defense against human error.
  • Clarity and Accountability: Defines who is responsible for specific security tasks.
  • Simplified Training: SOPs serve as the primary training material for new hires.
  • Demonstrable Compliance: Bridges the gap between policy (what you say) and reality (what you do).
  • Operational Continuity: Ensures tasks continue correctly even when key staff are absent.

What an ISO 27001 Auditor Will Look For

Audit Tip: Auditors don’t just want to see the document; they will ask your staff to find it. If your staff cannot locate the procedure in 2 minutes, you may receive a non-conformity.

Audit Readiness Checklist

  • [ ] Are procedures documented for key operational activities?
  • [ ] Do they include sufficient detail for consistent execution?
  • [ ] Is there evidence of management authorization?
  • [ ] Can staff demonstrate where to find them?
  • [ ] Is there a documented review schedule?

Top 3 Common Mistakes to Avoid

  1. Written and Forgotten: Documents created for the audit and never updated.
  2. Lack of Detail: High-level summaries instead of actionable steps.
  3. Inaccessible: Buried in hidden folders where staff cannot find them.

Information Security Standards that need Documented Operating Procedures

The main standard that requires these procedures is, of course, ISO 27001. However, having good documentation is also a best practice for other security frameworks like NIST and SOC 2.

Glossary of Terms

Information security is filled with specific terminology. When dealing with operational procedures, you and your management team must understand the following key terms.

TermISO 27001 Definition / Context
Standard Operating Procedure (SOP)A set of step-by-step instructions compiled by an organisation to help workers carry out routine operations consistently and securely.
RunbookA specialised type of technical SOP, typically used by IT teams, detailing the procedures to maintain system operations or respond to specific technical incidents.
Tribal KnowledgeUnwritten information that is known by some employees but not documented. This is a critical risk under ISO 27001.
Version ControlThe practice of tracking and managing changes to documents. Essential for proving to an auditor that staff are using the correct, up-to-date instructions.
Information Processing FacilityAny information processing system, service, or infrastructure, including the physical locations housing them.
Standard / Framework / LawDomain / RegionMapping to ISO 27001 Annex A 5.37 (Documented Operating Procedures)
NIST Cybersecurity Framework (CSF 2.0)Cybersecurity (Global/USA)Maps directly to the “Govern” (GV.PO) and “Protect” functions. NIST requires that organizational cybersecurity policies, processes, and procedures are established, communicated, and maintained. Annex A 5.37 provides the operational “runbooks” required to prove these processes are documented and repeatable.
NIS2 Directive (EU)Critical Infrastructure (EU)Article 21 mandates risk management measures, including incident handling, business continuity, and system security. Documented operating procedures (A 5.37) provide the mandatory evidentiary baseline that security tasks and IT operations are standardized and not reliant on ad-hoc or tribal knowledge.
Digital Operational Resilience Act (DORA)Financial Sector (EU)Article 9 (Protection and Prevention) requires financial entities to implement ICT security policies, procedures, and protocols. Annex A 5.37 fulfills the requirement to document daily ICT operational tasks, backup routines, and change management workflows, proving operational resilience.
SOC 2 (Trust Services Criteria)Information Security / Auditing (Global)Aligns with Common Criteria (CC) 5.1, 5.2, and 3.2. SOC 2 heavily audits whether management has defined and documented procedures for system operations and security event handling. A 5.37 directly satisfies the requirement to have formally documented and approved operational “recipes.”
EU AI ActArtificial Intelligence (EU)Article 17 requires high-risk AI system providers to put a Quality Management System (QMS) in place, which explicitly demands documented policies, procedures, and instructions. Annex A 5.37 translates to documenting AI model training, data sanitization, and prompt security review procedures.
ISO/IEC 42001 (AI Management System)Artificial Intelligence (Global)Requires documented procedures for managing the lifecycle of AI systems, including data handling, bias monitoring, and model updates. A 5.37 provides the framework to standardize and record these AI-specific operational tasks.
General Data Protection Regulation (GDPR)Data Privacy (EU)Article 24 and Article 32 require controllers to implement “technical and organisational measures” to ensure data security. Annex A 5.37 proves these measures exist by formally documenting how personal data is handled, stored, backed up, and deleted during daily IT operations.
UK Data (Use and Access) Act 2025Data Privacy (UK)While reducing administrative burdens compared to legacy GDPR, it maintains high security thresholds for data processing. A 5.37 ensures that the streamlined operational security measures (like access provisioning and data deletion) remain documented, legally defensible, and consistently applied.
Cyber Security and Resilience Bill (UK)Critical Infrastructure / Supply Chain (UK)As the UK’s counterpart to NIS2, this bill expands requirements for managed service providers and critical sectors. It requires proof of operational resilience; A 5.37 provides the documented procedures for incident logging, system maintenance, and supply chain security operations.
Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)Critical Infrastructure (USA)Mandates 72-hour cyber incident reporting and 24-hour ransom payment reporting. Complying with these strict timelines requires pre-documented incident response, logging, and operational escalation procedures as mandated by Annex A 5.37.
EU Product Liability Directive (PLD) UpdateConsumer Protection / Software (EU)Extends strict liability to software providers for cybersecurity flaws. To defend against liability claims, software creators must prove they followed standard security practices. A 5.37 ensures that secure coding, patch management, and vulnerability remediation processes are formally documented and auditable.
European Cybersecurity Certification Framework (ECCF)Cybersecurity Certification (EU)Requires harmonized security labels for ICT products/services. Achieving higher assurance levels under ECCF necessitates strict, documented proof of how secure operational environments are managed. A 5.37 provides the foundational operational documentation required by ECCF auditors.
Health Insurance Portability and Accountability Act (HIPAA)Healthcare / Data Privacy (USA)The HIPAA Security Rule (45 CFR § 164.316) explicitly states that covered entities must implement reasonable and appropriate policies and procedures. Annex A 5.37 aligns flawlessly by providing documented instructions for handling ePHI, system backups, and emergency IT operations.
California Consumer Privacy Act (CCPA) / CPRAData Privacy (USA – California)Requires businesses to implement and maintain “reasonable security procedures and practices.” Annex A 5.37 provides the tangible documentation (e.g., standard operating procedures for data encryption, access control, and data subject request fulfillment) that proves these practices are in place.

FAQ

Are documented operating procedures mandatory for ISO 27001?

Yes, documented operating procedures are mandatory under the ISO 27001:2022 standard for all critical information processing facilities and activities.
Auditors will look for these as evidence that the ISMS is operational.
Unwritten “tribal knowledge” is considered a risk and can result in non-conformity.
Documenting procedures is essential for meeting the requirements of Annex A 5.37.

What should be included in a documented operating procedure?

An ISO 27001-compliant operating procedure must include step-by-step technical instructions, defined roles and responsibilities, and clear escalation paths.
Hardware and software configuration steps.
Information processing and handling requirements.
Backup, recovery, and business continuity instructions.
Scheduling requirements and dependencies on other systems.
Error handling and incident management procedures.

What is the difference between a security policy and an operating procedure?

An Information Security Policy defines the high-level management direction and goals (“the what”), whereas an operating procedure provides specific technical instructions (“the how”).
Policy: “We must take daily backups of all financial data.”
Procedure: “Log into the backup server, select the ‘Finance’ job, and click run at 02:00.”
Policies are for governance; procedures are for daily execution.

How often should documented operating procedures be reviewed?

ISO 27001 operating procedures should be reviewed at least annually or whenever significant changes are made to the technical environment.
Reviews ensure instructions remain accurate as systems and software are updated.
Changes in personnel or internal roles may require updates to responsibility sections.
Testing procedures (like backup restoration) often triggers mandatory updates.

Where should operating procedures be stored for compliance?

Operating procedures must be stored in a centralised, secure location that is accessible to all authorised personnel who need them to perform their duties.
Common storage solutions include a secure Intranet, DMS (Document Management System), or a Version Control System (like Git).
Procedures should be subject to document control (Annex A 5.37 requires versioning).
Access must be restricted to prevent unauthorised modification or disclosure.

Relevant ISO 27001:2022 controls

Applicability for Modern Businesses

While the control is universal, the application varies by industry. Tailor your documentation to your specific risks.

Business VerticalStrategic Focus AreasStandard Operating Procedure (SOP) ExamplesISO 27001:2022 Mapping
Small BusinessesRevenue processes & core protections.New User Provisioning, Offsite Data Backups, Personnel Leaver Process.5.37 (Operating Procedures)
Tech StartupsSecuring Intellectual Property & Agile Development.Secure SDLC Workflows, Vulnerability Remediation, Cloud Environment Hardening.8.25 (Secure Development)
AI CompaniesLarge Datasets & ML Model Integrity.Data Anonymisation, AI Model Weights Security, Training Data Sanitisation.8.11 (Data Masking)
  • Small Businesses: You can use simple procedures for things like data backup, protecting customer information, and handling employee access.
  • Tech Startups: For you, it’s all about securing your code, customer data, and intellectual property. Procedures for secure development and handling sensitive data are key.
  • AI Companies: You’re dealing with huge amounts of data. You’ll need procedures for data handling, privacy, and ensuring your AI models are secure and fair.

Further Reading

Matrix of ISO 27001 Controls and Attribute values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveAvailabilityProtectAsset managementGovernance and ecosystem
CorrectiveConfidentialityRecoverPhysical securityProtection
IntegritySystem and network securityDefence
Application Security
Secure configuration
Identity and access management
Threat and vulnerability management
Continuity
Information security event management

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 5.37 Documented operating procedures
Shopping Basket
Scroll to Top