Moving from ad-hoc, informal processes to a structured, documented framework is a critical step in maturing an organisation’s security posture. Control 5.37 provides the framework for this essential transition, transforming tribal knowledge into a durable corporate asset.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.37 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex A 5.37
- 1. Provision an Inventory of Information Processing Facilities
- 2. Formalise Standard Operating Procedures for Routine Activities
- 3. Implement Strict Version Control and Document Governance
- 4. Provision Restricted Access via Identity and Access Management
- 5. Formalise Emergency Operating and Incident Response Instructions
- 6. Audit Alignment with Legal and Regulatory Obligations
- 7. Provision a Centralised and Secure Source of Truth
- 8. Formalise a Technical Review and Approval Workflow
- 9. Implement Training and Competency Assessments
- 10. Audit Operational Effectiveness Through Drills and Spot Checks
- ISO 27001 Templates
- Why Documented Operating Procedures are Crucial
- What an ISO 27001 Auditor Will Look For
- Top 3 Common Mistakes to Avoid
- ISO 27001 Annex A 5.37 FAQ
- Relevant ISO 27001:2022 controls
- Further Reading
- Matrix of ISO 27001 Controls and Attribute values
- Stuart Barker
Purpose & Definition
The core purpose is to create a repeatable operational environment. This removes ambiguity and reliance on individual memory, a crucial factor for scalable security.
The official requirement of ISO 27001:2022 Annex A 5.37 states:
“Operating procedures for information processing facilities should be documented and made available to personnel who need them.”
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.37 Training Video
In this free training video you will learn How to implement ISO 27001 Documented Operating Procedures (Annex A 5.37) and Pass Your Audit.
Implementation Guide
The headline guidance is, document all of your process and procedures. Do it to a level that is appropriate to you. Consider documenting common exception steps or steps in the process when the process does not go as intended.
Identify When Procedures Are Needed
You need to start creating these procedures during the planning and implementation phase of your ISO 27001 Information Security Management System (ISMS). They’re a core part of building a robust security framework.
The standard gives examples such as
- when a procedure is performed by many people and needs to be done in the same way
- when something is performed rarely and can be forgotten when it is needed again
- when you do something new and if not done correctly it will create a risk
- before someone else is taking on the procedure
Documenting Procedures
You need to document every process that you do for information security. The list is long. Take every process that you do for information security and document it. The standard provides examples which are basically the processes and procedures of the standard. The following is the bare minimum:
- document secure installation and configuration
- document processing and handling of information, include manual and automatic methods
- document backups and resilience
- document scheduling requirements
- document interdependencies between systems
- document instructions for handling errors
- document support and escalation contacts
- document storage media handling
- document restart and recovery procedures
- document the management of audit logs, system logs, video monitoring, audit trails
- document capacity management
- document maintenance
Review, Approval, and Distribution of Documents
Drafts must be formally approved by management and stored in a central repository (e.g., SharePoint/Intranet) accessible to all staff.
Updating procedures
Update and review procedures as needed but at least annually. The standard does not say at least annually. But it will catch you out if you do not.
How to write procedures
Writing these procedures is a team effort. You should:
- Keep it simple: Use plain language that anyone can understand.
- Define the purpose: Explain why this procedure is important.
- List the steps: Break down the task into clear, numbered steps.
- Assign responsibilities: Make it clear who does what.
- Get it approved: Have the right people sign off on the procedure.
Authorising changes to procedures
When you change something, that change needs to be authorised with some evidence that the authorisation took place.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

How to implement ISO 27001 Annex A 5.37
Implementing ISO 27001 Annex A 5.37 ensures that your organisation maintains consistent, secure, and reliable information processing operations. As an ISO 27001 Lead Auditor, I look for technical evidence that procedures are not just written, but are actively utilised and governed. Follow these ten technical steps to formalise your documented operating procedures and satisfy rigorous audit requirements.
1. Provision an Inventory of Information Processing Facilities
Provision a comprehensive list of all systems and facilities within the organisational Asset Register: result: ensures all hardware, software, and cloud instances requiring documented instructions are identified and scoped.
- Identify all critical infrastructure components, including servers, networks, and cloud storage.
- Map technical dependencies between systems to determine where procedures must overlap.
- Assign an “Asset Owner” for every facility to take responsibility for procedure maintenance.
2. Formalise Standard Operating Procedures for Routine Activities
Formalise detailed instructions for daily, weekly, and monthly system activities: result: establishes a consistent baseline for backups, system restarts, and scheduled technical maintenance.
- Document specific commands and configurations for starting and stopping systems.
- Define the exact steps for performing and verifying system backups.
- Outline procedures for the handling and disposal of information media.
3. Implement Strict Version Control and Document Governance
Implement a formal document control system for all technical procedures: result: prevents the use of obsolete instructions and ensures a clear audit trail for management updates.
- Utilise unique identifiers and version numbers for every operational document.
- Record the date of the last review and the name of the individual who approved the content.
- Automate the archiving of superseded documents to prevent operational errors.
4. Provision Restricted Access via Identity and Access Management
Provision restricted access to sensitive procedures using Identity and Access Management (IAM) roles: result: ensures that only authorised personnel with a legitimate business need can view or modify technical instructions.
- Apply the Principle of Least Privilege to the centralised procedure repository.
- Mandate Multi-Factor Authentication (MFA) for any user with “edit” permissions on procedures.
- Audit access logs monthly to identify any unauthorised attempts to access sensitive technical data.
5. Formalise Emergency Operating and Incident Response Instructions
Formalise high-priority instructions for system failures or security incidents: result: enables rapid recovery and maintains system availability during unexpected outages or cyber attacks.
- Create “Runbooks” for specific disaster recovery scenarios and known incident types.
- Document contact details and escalation paths for third-party vendors and internal leads.
- Ensure instructions include the technical steps for isolating compromised systems.
6. Audit Alignment with Legal and Regulatory Obligations
Audit the content of all operating procedures to ensure compliance with external mandates: result: confirms that technical operations meet statutory requirements like GDPR, NIS2, or DORA.
- Review procedures for data handling to ensure they align with privacy legislation.
- Verify that retention periods for logs and backups meet legal and contractual requirements.
- Document how procedures satisfy specific clauses in the organisation’s Legal Register.
7. Provision a Centralised and Secure Source of Truth
Provision a single, secure digital repository for all documented procedures: result: facilitates timely retrieval by operational staff and provides a clear evidence base for auditors.
- Ensure the repository is highly available and resilient to local system failures.
- Organise the structure by system or department to allow for rapid navigation.
- Enable full-text search capabilities to help staff find instructions during high-pressure events.
8. Formalise a Technical Review and Approval Workflow
Formalise a structured workflow for the creation and updating of procedures: result: ensures that all operating instructions remain technically accurate and aligned with organisational risk appetite.
- Require a technical peer review for any change to core system procedures.
- Obtain management sign-off for procedures that impact critical business continuity.
- Schedule mandatory review cycles for every document, typically occurring every twelve months.
9. Implement Training and Competency Assessments
Implement formal training sessions for all staff expected to execute documented procedures: result: verifies that personnel can perform their duties correctly and securely in accordance with policy.
- Conduct practical walkthroughs of procedures for new starters and contractors.
- Document attendance and the results of competency tests to provide audit evidence.
- Update training materials immediately following any significant change to technical instructions.
10. Audit Operational Effectiveness Through Drills and Spot Checks
Audit the practical application of documented procedures through regular technical drills: result: identifies gaps between theoretical instructions and operational reality for continual improvement.
- Conduct “Tabletop” exercises to test the clarity and effectiveness of emergency procedures.
- Perform unannounced spot checks to ensure staff are following the “live” version of instructions.
- Record all drill findings in the Corrective Action Log to drive necessary technical updates.
ISO 27001 Templates

Why Documented Operating Procedures are Crucial
- Consistency and Reduced Errors: Uniformity is the best defense against human error.
- Clarity and Accountability: Defines who is responsible for specific security tasks.
- Simplified Training: SOPs serve as the primary training material for new hires.
- Demonstrable Compliance: Bridges the gap between policy (what you say) and reality (what you do).
- Operational Continuity: Ensures tasks continue correctly even when key staff are absent.
What an ISO 27001 Auditor Will Look For
Audit Tip: Auditors don’t just want to see the document; they will ask your staff to find it. If your staff cannot locate the procedure in 2 minutes, you may receive a non-conformity.
Top 3 Common Mistakes to Avoid
- Written and Forgotten: Documents created for the audit and never updated.
- Lack of Detail: High-level summaries instead of actionable steps.
- Inaccessible: Buried in hidden folders where staff cannot find them.
ISO 27001 Annex A 5.37 FAQ
Yes, documented operating procedures are mandatory under the ISO 27001:2022 standard for all critical information processing facilities and activities.
Auditors will look for these as evidence that the ISMS is operational.
Unwritten “tribal knowledge” is considered a risk and can result in non-conformity.
Documenting procedures is essential for meeting the requirements of Annex A 5.37.
An ISO 27001-compliant operating procedure must include step-by-step technical instructions, defined roles and responsibilities, and clear escalation paths.
Hardware and software configuration steps.
Information processing and handling requirements.
Backup, recovery, and business continuity instructions.
Scheduling requirements and dependencies on other systems.
Error handling and incident management procedures.
An Information Security Policy defines the high-level management direction and goals (“the what”), whereas an operating procedure provides specific technical instructions (“the how”).
Policy: “We must take daily backups of all financial data.”
Procedure: “Log into the backup server, select the ‘Finance’ job, and click run at 02:00.”
Policies are for governance; procedures are for daily execution.
ISO 27001 operating procedures should be reviewed at least annually or whenever significant changes are made to the technical environment.
Reviews ensure instructions remain accurate as systems and software are updated.
Changes in personnel or internal roles may require updates to responsibility sections.
Testing procedures (like backup restoration) often triggers mandatory updates.
Operating procedures must be stored in a centralised, secure location that is accessible to all authorised personnel who need them to perform their duties.
Common storage solutions include a secure Intranet, DMS (Document Management System), or a Version Control System (like Git).
Procedures should be subject to document control (Annex A 5.37 requires versioning).
Access must be restricted to prevent unauthorised modification or disclosure.
Relevant ISO 27001:2022 controls
- ISO 27001 Clause 8.1 Operational Planning and Control
- ISO 27001 Annex A 5.24 Information Security Incident Management Planning and Preparation
Further Reading
- How To Implement ISO 27001: A Step By Step Guide
- ISO 27001 Change Management Policy Beginner’s Guide
- ISO 27001 Logging and Monitoring Policy Beginner’s Guide
Matrix of ISO 27001 Controls and Attribute values
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.
