A.5.37 Organizational
Documented operating procedures
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CM-2mostlyaligns with — Both controls require establishing and maintaining documented, consistent baseline procedures for secure system installation, configuration, and operation.
- CM-3mostlyaligns with — Both require formal authorization and control of changes to operating procedures and configurations to ensure consistency and reduce risk.
- CM-6mostlyaligns with — Both emphasize applying standardized, documented configuration settings and procedures across systems to achieve consistent, secure operation.
- AU-2partialaligns with — Both require documented procedures for generating, managing, and protecting audit and system log information as part of operational security.
- CP-9partialaligns with — Both require documented backup and recovery procedures as part of ensuring operational resilience and system restoration after failure.
- SI-2partialaligns with — Both require documented procedures for handling errors, exceptions, and flaw remediation during system operation and maintenance.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-04mostlyaligns with — By mandating procedures for managing audit trails, system logs, and monitoring of capacity, performance, and security, the ISO control supports the CSF outcome of generating and making log records available for continuous monitoring.
- GV.PO-02partialaligns with — The ISO control’s mandate to review, update, authorize, and enforce documented operating procedures mirrors the CSF outcome of reviewing, updating, communicating, and enforcing policies to reflect changing requirements.
- ID.IM-03partialaligns with — The requirement to review and update documented operating procedures when changes occur or new risks arise aligns with the CSF outcome of identifying improvements from the execution of operational processes and activities.
- PR.IR-03partialaligns with — Specifying restart, recovery, backup, and resilience instructions within operating procedures supports the CSF outcome of implementing mechanisms to achieve resilience requirements in normal and adverse situations.
- PR.PS-01nonegoverns — The ISO control requires documented, authorized, and consistently applied procedures for secure system installation, configuration, maintenance, and error handling, which directly fulfills the CSF outcome of establishing and applying configuration management practices.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.1.1mostlyaligns with — The ISO requirement to document operational procedures for secure system installation, configuration, and inter-system dependencies directly supports the ASVS mandate that all communication needs and external service dependencies be documented.
- V13.2.6partialaligns with — Documenting scheduling requirements, interdependencies, and maintenance instructions for operational activities aligns with the ASVS expectation that documented configuration rules govern how the application connects to separate services.
- V13.4.2partialaligns with — Requiring documented restart, recovery, and error-handling procedures helps ensure that debug modes and diagnostic features are disabled in production, matching the ASVS control for disabling debug modes.
- V16.1.1partialaligns with — Specifying procedures for managing audit trails, system logs, and monitoring activities corresponds to the ASVS requirement for an inventory documenting what security-relevant events are logged at each layer.
Related weaknesses / CWE (25)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1059mostlyprevents — Documented operating procedures directly require the technical documentation whose absence is CWE-1059.
- CWE-1112mostlyprevents — Documented operating procedures directly require complete specification of program execution mechanisms.
- CWE-1076partialprevents — Documented procedures can specify conventions but do not guarantee they are followed.
- CWE-1118partialprevents — Documented operating procedures must describe error handling and exception processing.
- CWE-15partialmitigates — Documented operating procedures define how configuration changes must be performed.
- CWE-284partialprevents — Documented procedures that explicitly assign responsibilities and mandate consistent, authorized steps reduce the chance that an operator will perform an action outside the intended access-control boundaries.
- CWE-404partialprevents — Including restart, recovery and media-handling instructions reduces the likelihood that resources or sensitive data will be left in an exposed or improperly released state after a failure.
- CWE-732partialprevents — Requiring documented secure-installation and configuration steps prevents default or overly permissive file-system and resource permissions from being left in place.
- CWE-779partialprevents — Documented operating procedures can include logging guidelines, indirectly reducing excessive logging.
- CWE-1068nonenone — Documented operating procedures help keep implementation aligned with stated design, but do not enforce design-level consistency.
- CWE-1078nonenone — Documented operating procedures may mandate coding conventions, but the control addresses general procedural documentation rather than source-code style.
- CWE-1113nonenone — Documented operating procedures can reference coding conventions including comment style.
- CWE-1116nonenone — Documented operating procedures may reference code comments, encouraging their accuracy for operational consistency.
- CWE-250nonenone — Specifying the minimum privileges and responsible individuals for each operational task discourages routine execution with unnecessary administrative rights.
- CWE-400nonenone — Documented capacity, performance and scheduling procedures allow operators to detect and correct resource-exhaustion conditions before they become denial-of-service situations.
- CWE-440nonenone — Documented operating procedures reduce the chance that functions deviate from intended behavior.
- CWE-755nonenone — Documented operating procedures may specify exception handling but do not guarantee implementation.
- CWE-778nonenone — Mandating explicit instructions for the management of audit trails and system logs ensures that security-relevant events are captured rather than omitted.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialprevents — Standardized, authorized procedures for installation, configuration, error handling, and maintenance directly reduce the chance that systems are deployed or operated with insecure defaults or ad-hoc changes.
- A09partialmitigates — Explicit instructions on audit-trail management, log handling, monitoring, and escalation contacts ensure that security-relevant events are captured and responded to rather than overlooked.
- A10nonemitigates — Documented restart, recovery, and exception-handling steps limit the damage and downtime that can occur when unexpected conditions arise during operations.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.