Operational Procedure Library
Procedures are where documentation becomes executable. Each procedure should be short enough to run during real work and specific enough to produce evidence an assessor can inspect.
Required Procedures
| Procedure | Families | Trigger | Evidence |
|---|---|---|---|
| Monthly ConMon Review | CA, RA, CM, SI | First business week of each month. | ConMon issue, scan reports, inventory, POA&M update |
| Vulnerability Scan Triage | RA, SI | New scan output or monthly package. | Triage notes, POA&M items, false-positive approvals |
| Access Review | AC, IA | Monthly for privileged access; quarterly for broader access. | Access-review issue, exports, removals |
| Joiner-Mover-Leaver | AC, IA, PS | Personnel change. | Access request, approval, provisioning or deprovisioning log |
| Break-Glass Use | AC, AU, IR | Emergency privileged access. | Incident or change ticket, audit log, post-use review |
| Production Change | CM, SA, AU | Production release or configuration change. | Pull request, approvals, CI logs, Argo CD sync |
| Emergency Change | CM, IR, AU | Urgent security or availability change. | Emergency approval, retrospective review, POA&M if needed |
| Significant Change Review | CA, CM, RA | Boundary, service, data, crypto, auth, region, or provider change. | Impact analysis, AO notification decision, validation plan |
| Backup Restore Test | CP | Quarterly or after major storage change. | Restore log, validation result, issue closure |
| Incident Response | IR, AU, SI | Security event or suspected compromise. | Incident timeline, evidence bundle, after-action report |
| Key Rotation | SC, IA, AU | Scheduled rotation or suspected exposure. | Rotation record, access review, validation |
| Audit Log Review | AU, SI | Monthly and after sensitive events. | Query results, alert review, retention status |
| Supplier Review | SR, SA, CA | New vendor, renewal, or significant change. | Supplier record, authorization evidence, risk decision |
| Data Retention Review | PT, MP, SI | Quarterly or policy change. | Data inventory update, deletion records |
Procedure Template
| Section | Content |
|---|---|
| Purpose | One sentence describing the control outcome. |
| Trigger | Event or cadence that starts the procedure. |
| Preconditions | Access, tools, approvals, and inputs required. |
| Steps | Ordered actions with exact systems and artifacts. |
| Evidence | Artifact name, format, storage location, and retention. |
| Failure Handling | What to do if a step cannot be completed. |
| Escalation | Who is notified and when. |
| Closure | Conditions that prove the procedure is complete. |
Significant Change Procedure
- Open a significant-change review issue.
- Describe the change, reason, customer impact, and implementation timeline.
- Identify affected controls, Key Security Indicators where applicable, data flows, inherited controls, and evidence sources.
- Complete security, privacy, platform, and application reviews.
- Decide whether AO or FedRAMP notification is required.
- Define validation, rollback, and customer communication steps.
- Attach post-change evidence.
- Update SSP, diagrams, inventory, and POA&M if needed.
Access Review Procedure
- Export current users, groups, roles, service accounts, and privileged assignments.
- Compare access against approved role matrix and ownership records.
- Remove stale, excessive, or unowned access.
- Record exceptions with owner and expiration.
- Review break-glass use since the last review.
- Attach export, removals, exceptions, and approver sign-off.
Vulnerability Triage Procedure
- Import findings from all required scanners.
- Deduplicate by package, image, host, service, or root cause.
- Assign severity using scanner severity plus exploitability and exposure.
- Create POA&M items for findings that cannot close inside the remediation window.
- Mark false positives only with evidence and expiry.
- Re-scan after remediation.
- Attach proof of closure.
Evidence Storage Rules
| Evidence Type | Preferred Format | Storage |
|---|---|---|
| Scan output | SARIF, JSON, XML, or native report | Evidence repository and scanner system |
| Approvals | Pull request, issue, or change ticket | GitHub or change-management system |
| Inventory | JSON, CSV, or generated Markdown | Evidence repository |
| Logs | Query export or immutable log reference | Log platform |
| Attestations | in-toto, SLSA, Sigstore bundle | Artifact registry |
| Diagrams | Source plus rendered image | Documentation repository |
Procedure Completion Standard
- Procedure run has a named owner.
- Inputs and outputs are attached or linked.
- Exceptions have a risk owner and expiration.
- Any failed step creates a POA&M item or incident.
- Evidence is retained in the expected location.