GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-024 Documented Operating Procedures

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Operating procedures for critical information processing activities are documented, maintained, and made available to personnel who require them. Procedures are version-controlled, reviewed at defined intervals, and updated when processes change.

Rationale

Undocumented procedures cannot be consistently executed, audited, or transferred to new personnel. Documented procedures are the mechanism by which policies are operationalised.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.316 makes documentation availability and periodic update required specifications rather than good practice. Availability is owed to the people implementing the procedures, so a procedure held only in a compliance repository fails it.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (11)

GRC-03Organizational Policy Reviewspartial
GRC-03Organizational Policy Reviewspartial
HIPAA-164.306.eMaintenancepartial
HIPAA-164.316.aPolicies and Procedurespartial
HIPAA-164.316.b.1Documentationinformative
HIPAA-164.316.b.2.iiAvailabilityfull
HIPAA-164.316.b.2.iiiUpdatesfull
5.37Documented operating proceduresfull
NIS2-CIR-6.4Change Management, Repairs and Maintenanceinformative
PL-2System Security and Privacy Plansinformative
SA-5System Documentationpartial

Evidence (2)

policydocumentmanual

Operating procedures for critical information processing activities, version-controlled and reviewed at defined intervals.

Example: Set of operating procedures (Confluence runbooks or Google Drive SOPs) for at least five critical processes, e.g. access provisioning, patch management, incident response, backup and recovery, change management, each with: version number, last-reviewed date, named owner, and access control setting.

Test: Request the procedure index or list from the document management system. Select a sample of five procedures covering different security domains. For each, verify: (1) a current version number exists, (2) a last-reviewed or last-updated date is within the defined interval (typically 12 months), (3) a named owner is assigned, (4) the procedures are accessible to the personnel who need them.

recorddocumentmanual

Procedure review log showing each critical procedure has been reviewed and updated (or confirmed current) at the required interval.

Example: Procedure review log or version history (Confluence page history / document management system change log), showing review dates, reviewer names, and disposition (updated/confirmed current) for each procedure within the last 12 months.

Test: Export the revision history or review log for the procedure library. Verify: (1) all listed critical procedures have a review event within the defined interval, (2) the review records show a named reviewer, (3) procedures triggered by process changes (e.g. new system deployment) show an update date aligned to that change.

Questions (3)

boolean

Are operating procedures documented for the critical information processing activities?

Each procedure should carry a version number, a named owner, and a last-reviewed date within the defined interval (typically 12 months).

multi

Which of the following critical process areas have documented operating procedures that are actively maintained?

Access provisioning and deprovisioningPatch and vulnerability managementIncident responseBackup and recoveryChange managementSecure software development lifecycle (SDLC)None of the above

Select all that apply and be prepared to provide the procedure documents with version history. Fewer than three covered areas would be considered a material gap.

multi

Which of the following apply to your documented operating procedures?

Each carries a version numberEach names an ownerEach carries a last-reviewed date within the defined intervalThey are available to the personnel who need them without having to request themThey are updated when the process changesNone of the above

Options run from the most commonly in place to the least. A procedure nobody can reach at the moment they need it is not available, whatever the document management system says about permissions.