Document the procedures for operating your IT and information processing facilities, and make them available to those who need them. Clear procedures keep operations consistent and reduce mistakes.
What an auditor, or Sekit's evidence engine, asks for.
Backup configuration and restore-test record
How backups are made (what is backed up, how often, where they are stored) and the proof that a restore has been tested successfully.
Disaster recovery plan and runbooks
The plan defining how long each critical system can be down (RTO/RPO) and the step-by-step guides to recover it after a serious failure.
Change and release management records
The process to review and approve changes to production systems before applying them, and how new versions are released in a controlled way.
From the Sekit evidence catalog
In practice
In practice this control shows up as runbooks: a written, step-by-step procedure for each recurring or high-risk operation, from applying a patch to restoring a backup to responding to an incident, kept current enough that someone unfamiliar with the system could follow it. Auditors ask to see the runbook used in the last real incident or restore test and compare it against what happened during that event. The common failure mode is a procedure written once for the audit and never updated after the environment changed underneath it.
Common gaps
Change and release records show approvals happened, but the underlying operating procedure was never updated to match how the change was carried out.
The restore-test record exists for one system but the documented recovery runbook was not followed step by step during the test.
Recovery runbooks reference server names and tools that were retired months ago, so the document would mislead a responder during a real incident.
Questions your auditor will ask
Can you show the runbook a responder followed during a recent incident?
The playbook for that incident type, matched against the disaster recovery plan and runbooks record showing the steps taken and their timestamps.
How current are your operating procedures against the live environment?
Runbooks are reviewed and updated after every system change, verified by the change and release management records showing the procedure was checked at that time.
Is a restore from backup tested on a schedule, or only assumed to work?
The backup configuration and restore-test record shows a scheduled test with a documented outcome, not merely a backup job completing.
Do you have a written procedure for patching systems that cannot be patched on the normal schedule?
The patch and compensating-controls procedure for these systems states the alternative measures used and who signed off on the deferral.
Where regulation demands it
NIS2 6.4 requires documented change management, repairs and maintenance procedures, the exact operating procedures A.5.37 asks the company to write down and keep current.
ENS op.exp.5 requires Gestión de cambios, a documented change process that is one instance of the operating procedures A.5.37 covers.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.