ISO/IEC 27000 Documented Operating Procedures, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to documented operating procedures.

Assessment Step

1
Documented Operating Procedures (DocumentedOperatingProcedures)
Has the organization documented its operating procedures for information processing facilities, and does it make them available to personnel who need them?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Documented Operating Procedures
Operating procedures for information processing facilities shall be documented and made available to personnel who need them.
Citations
27001
Annex A, Control 5.37
27002
Section 5.37