Skip to content
arrow_back
Annex A 5.37verifiedISO/IEC 27001:2022

Documented Operating Procedures for Information Processing

Ensure procedures are written down and accessible to those who need them.

record_voice_over

Plain language

Imagine running a business where no one knows exactly how to do their job because the instructions aren't written down. This control is basically saying: 'Let's not leave things to chance!' By documenting how information is processed, you ensure everyone knows what to do and how to do it, reducing mistakes and making sure everything runs smoothly.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

18 June 2026

Official control statement

Operating procedures for information processing facilities shall be documented and made available to personnel who need them.
verifiedISO/IEC 27001:2022Annex A 5.37
priority_high

Why it matters

Without documented operating procedures, staff run processing tasks inconsistently, increasing outages, data handling errors and inability to repeat or audit processing steps.

settings

Operational notes

Maintain version-controlled operating procedures for each processing facility; assign owners, review after changes/incidents, and publish them where relevant staff can easily access.

build

Implementation tips

  • The IT manager should take the lead in documenting procedures for all key information processing activities. They can start by listing frequent, rare, and new activities, ensuring every procedure is written down so it can be consistently followed.
  • HR should ensure that new staff receive and understand these documented procedures as part of their onboarding process. This can be done by integrating these procedures into training sessions and making sure they're easily accessible.
  • Department heads should be responsible for keeping procedure documents up-to-date and relevant. They can do this by regularly reviewing the procedures, especially after changes in systems or regulations, to ensure they remain accurate.
  • An operations manager should oversee the secure handling and storage of these documents. This includes setting up a digital library that is backed up regularly, ensuring easy access for authorised personnel only, aligned with the ASD Essential Eight.
  • The compliance officer should verify that procedures include specific details like handling errors and correct sequences of tasks. They can do this by cross-referencing the procedures with actual practices, ensuring compliance with the Australian Privacy Act 1988.
fact_check

Audit / evidence tips

  • AskThe documented operating procedures for all key information processing activitiesGoodA comprehensive set of current documents available to everyone who needs them
  • AskRecords of when procedures were last reviewed and updated
  • AskTo see training records for new staff on these procedures
  • AskEvidence of how exceptions or errors are handled following documented procedures
  • AskHow changes to procedures are communicated to staff
link

Cross-framework mappings

How Annex A 5.37 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ASD ISM

ControlNotesDetails
layersPartially meets(3)expand_less
ISM-0206ISM-0206 requires documented and maintained cable labelling processes and supporting procedures
ISM-0348ISM-0348 requires organisations to develop, implement, and maintain media sanitisation processes and supporting procedures
ISM-0372ISM-0372 mandates a specific operational safeguard for media disposal: two cleared personnel must supervise destruction of media holding ...
sync_altPartially overlaps(3)expand_less
ISM-0576Annex A 5.37 requires operational procedures for information processing to be documented and made available to relevant personnel
ISM-0912Annex A 5.37 requires documented and accessible operating procedures for information processing facilities
ISM-1602ISM-1602 requires cyber security documentation, including change notifications, to be communicated to stakeholders
handshakeSupports(10)expand_less
ISM-0041Annex A 5.37 requires operating procedures for information processing facilities to be documented and accessible to personnel who need them
ISM-0042Annex A 5.37 requires operating procedures for information processing facilities to be documented and made available to personnel who nee...
ISM-0362ISM-0362 enforces following manufacturer’s directions for degaussing magnetic media, whereas Annex A 5.37 calls for documented procedures...
ISM-0499ISM-0499 requires compliance with ASD communications security doctrine and policy for HACE operations
ISM-0888Annex A 5.37 requires operating procedures for information processing facilities to be documented and made available to personnel who nee...
ISM-1359ISM-1359 requires an organisation to implement and maintain a removable media usage policy to control how removable media is used and han...
ISM-1478ISM-1478 requires the CISO to oversee the cyber security program and ensure compliance with organisational and external cyber security re...
ISM-1549ISM-1549 requires an organisation to develop, implement, and maintain a media management policy
ISM-1551ISM-1551 requires an organisation to establish and maintain a policy for managing IT equipment
ISM-1802ISM-1802 requires organisations to operate ASD-approved HACE in line with the latest ACSI, which implies disciplined, documented operatin...

ISO 42001

ControlNotesDetails
handshakeSupports(3)expand_less
Annex A 4.4Annex A 4.4 stipulates documenting AI system tooling resources
Annex A 7.2Annex A 7.2 requires the organisation to define, document and implement data management processes for developing and enhancing AI systems...
Annex A 7.6Annex A 7.6 requires the organisation to define and document criteria for selecting data preparations and the data preparation methods us...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Organisational controls controls, or browse the full ISO 27001 library.

school

Want to implement this control?

Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.

Mapping detail

Mapping

Direction

Controls