A.5.37 Organizational
Documented operating procedures
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (20)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CM-2mostlyaligns with — Both controls require establishing and maintaining documented, consistent baseline procedures for secure system installation, configuration, and operation.
- CM-3mostlyaligns with — Both require formal authorization and control of changes to operating procedures and configurations to ensure consistency and reduce risk.
- CM-6mostlyaligns with — Both emphasize applying standardized, documented configuration settings and procedures across systems to achieve consistent, secure operation.
- AU-2partialaligns with — Both require documented procedures for generating, managing, and protecting audit and system log information as part of operational security.
- CP-9partialaligns with — Both require documented backup and recovery procedures as part of ensuring operational resilience and system restoration after failure.
- SI-2partialaligns with — Both require documented procedures for handling errors, exceptions, and flaw remediation during system operation and maintenance.
- AU-2governs — A.5.37's requirement to document operating procedures for secure operation of facilities directly implies that the procedures must cover how event logging is identified, coordinated, and specified per au-2
- CM-2governs — A.5.37's mandate for documented operating procedures directly encompasses the requirement to develop, document, and maintain baseline configurations as a core operational procedure for secure system operation.
- CM-3governs — A.5.37's requirement for documented operating procedures directly encompasses the procedural domain of determining, reviewing, documenting, and implementing configuration changes, which is the core of CM-3.
- CM-6governs — A.5.37's requirement to document operating procedures directly supplies the governance layer that mandates establishing, documenting, and enforcing secure/restrictive configuration baselines as named in CM-6
- SI-2governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (20)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-04mostlyaligns with — By mandating procedures for managing audit trails, system logs, and monitoring of capacity, performance, and security, the ISO control supports the CSF outcome of generating and making log records available for continuous monitoring.
- GV.PO-02partialaligns with — The ISO control’s mandate to review, update, authorize, and enforce documented operating procedures mirrors the CSF outcome of reviewing, updating, communicating, and enforcing policies to reflect changing requirements.
- ID.IM-03partialaligns with — The requirement to review and update documented operating procedures when changes occur or new risks arise aligns with the CSF outcome of identifying improvements from the execution of operational processes and activities.
- PR.IR-03partialaligns with — Specifying restart, recovery, backup, and resilience instructions within operating procedures supports the CSF outcome of implementing mechanisms to achieve resilience requirements in normal and adverse situations.
- PR.PS-01nonegoverns — The ISO control requires documented, authorized, and consistently applied procedures for secure system installation, configuration, maintenance, and error handling, which directly fulfills the CSF outcome of establishing and applying configuration management practices.
- GV.PO-02covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.IM-03governs — A.5.37 mandates documented operating procedures whose execution supplies the operational data from which ID.IM-03 improvements are identified; the governance link is present by subject-area membership in operational processes but the control does not name improvement identification.
- ID.IM-03implements — A.5.37's documented operating procedures give operational effect to the improvements-from-execution outcome in ID.IM-03 within the shared operational-processes domain, but without either naming the other
- PR.IR-03governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.1.1mostlyaligns with — The ISO requirement to document operational procedures for secure system installation, configuration, and inter-system dependencies directly supports the ASVS mandate that all communication needs and external service dependencies be documented.
- V13.2.6partialaligns with — Documenting scheduling requirements, interdependencies, and maintenance instructions for operational activities aligns with the ASVS expectation that documented configuration rules govern how the application connects to separate services.
- V13.4.2partialaligns with — Requiring documented restart, recovery, and error-handling procedures helps ensure that debug modes and diagnostic features are disabled in production, matching the ASVS control for disabling debug modes.
- V16.1.1partialaligns with — Specifying procedures for managing audit trails, system logs, and monitoring activities corresponds to the ASVS requirement for an inventory documenting what security-relevant events are logged at each layer.
Related weaknesses / CWE (16)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1059prevents — Documented operating procedures directly require the technical documentation whose absence is CWE-1059.
- CWE-1076prevents — Documented procedures can specify conventions but do not guarantee they are followed.
- CWE-1112prevents — Documented operating procedures directly require complete specification of program execution mechanisms.
- CWE-1118prevents — Documented operating procedures must describe error handling and exception processing.
- CWE-15mitigates — Documented operating procedures define how configuration changes must be performed.
- CWE-284prevents — Documented procedures that explicitly assign responsibilities and mandate consistent, authorized steps reduce the chance that an operator will perform an action outside the intended access-control boundaries.
- CWE-404prevents — Including restart, recovery and media-handling instructions reduces the likelihood that resources or sensitive data will be left in an exposed or improperly released state after a failure.
- CWE-732prevents — Requiring documented secure-installation and configuration steps prevents default or overly permissive file-system and resource permissions from being left in place.
- CWE-779prevents — Documented operating procedures can include logging guidelines, indirectly reducing excessive logging.
Mitigated MITRE ATT&CK techniques (209)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.