Procedure Guidelines and Controls Documentation - Why Do RunBooks Focus On Service?

Procedure Guidelines and Controls Documentation - Why Do RunBooks Focus On Service?
Friday, 30 September 2011 15:09
Print E-mail
User Rating: / 16
PoorBest 
Publications and Whitepapers
Article Index
Procedure Guidelines and Controls Documentation
Document Library Management Program
Process Librarian
Access Control
Data Classification and Data Owners
Document Types and Their Use
How Do I Validate My Document?
Should I Write A Process Profile?
Where Do I Find the Template?
Should I Write A Work Instruction - SOP?
Why Do RunBooks Focus On Service?
How Do I Find Or Store My Document?
Where Are Devices Inventoried As Assets?
Controls and Key Controls (see Control Self Assessment Portal)
Controls and Key Controls - Where Do I Find The Form or Template?
When Do I Use A Flow Diagram?
WAcronym Glossary and Definitions
Risks and Associated Controls (SAMPLE)
IT Process Asset Library - Recommendations for information organization and visibility over document assets
All Pages
Why Do RunBooks Focus On Service?

A RunBook is Service Oriented vs. single system oriented.  When documentation does not meet the requirements mentioned above, it is probable that listing the device in an inventory system is sufficient and further documentation is not required.

Where the availability of a critical or core business function depends upon the accurate working of interdependent systems, it is advisable to have a business owner who assures the current and complete Service RunBook.   As is true for any controlled system, the RunBook explains day to day system procedures, but additionally adds some or all of the following elements:

  • Functional Overview
  • Functional Overview Diagram
  • List of Interfaces
  • System Overview
  • System Overview Diagram (s)
  • Network Management Process
  • Hardware
  • Hardware Management Process
  • Software Development and Release
  • Third Party Vendor / Software Management
  • Performance Monitoring Process
  • Database Administration Process
  • Quality Assurance
  • Vendor Information
  • Back Up Processes
  • Disaster Recovery Process
  • Security
  • Problem Management
  • Configuration Overview:
  • Server/ HW/OS
  • Application
  • Database Configuration
  • Daily cycle
  • Fail-over
  • Maintenance
  • Troubleshooting and Error Messages
  • Glossary
  • List of files
  • Financial Processes
  • Test procedure

Should I Write A RunBook?

Consider whether the following statements are true.

RunBook SOAProjects

Figure 7. Should I write a RunBook?

Where Do I Get The Information That Goes Into The RunBook?

Consider the following sources.

What Goes in a Runbook

RunBooks bring visibility to an aggregation of documents and details that collectively support service availability or product delivery.

When Is A RunBook Complete?

Consider whether the following statements are true.

New Process in RunBook

RunBooks can be maintained as a word report that is output from a single database system or from a collection of systems.  The form used to gather RunBook elements (today) is in Facilitated Compliance Management. This is a location that is subject to change.  The tool that gathers RunBook details is not critical to the process.  The tool for gathering elements can also be a word document, as identified in the template section.  The process for generating RunBook information is not important, so long as visibility of how systems run is maintained for the business owner and technology support personnel.

RunBook Lifecycle

Figure 8. RunBook Process

runbook

Example Interface for gathering RunBook elements by Service Title

Where Do I Find The Template?

\\...\pal\Facilitated Compliance Management\...

\\...\pal\Templates\RunBook Template.dot

The current procedure for RunBook is to use our system database and generate a RunBook report as needed.

RunBook Document Elements

The following section is written to address addition questions pertaining to document elements, storing and managing information and how steps and controls are specifically captured to support the internal audit of IT program and application level controls.  Sections include:

Where Does My Document Belong?

\\...\PAL\IT Process Asset Library\

  1. Static Process versus Process Output (Evidence of Using Process)

\\...\PAL\IT Work Product Library\

  1. Other Work Products and Controlled Documentation:
  2. Version Control versus VSS (Microsoft Visual SourceSafe)
  3. Test Scripts, Utilities and Event Tracking Systems
  4. Assets, Inventories and Configuration Baselines
  5. Controls and Key Controls
  6. Product, Application Development and Quality Templates
  7. Flow Diagram



Last Updated on Thursday, 03 May 2012 17:29
 
New Services
The GRC Buzz

 

Now Available - Cloud & Virtualization Essentials™

 

 

 

Push 2 Check

http://rymatech.com/

 

HISPIHolistic Information Security Practitioner Institute (HISPI) welcomes EnterpriseGRC Solutions as member of their HISP Certification Board/Committee Read More

GRC Solutions

ITpreneursITpreneurs is proud to name EnterpriseGRC Solutions as its newest certified partner. ITpreneurs and EnterpriseGRC Solutions will collaborate to increase Cloud and Virtualization concepts and controls, ISO 27001, COBIT and ITIL courses offered through EnterpriseGRC Solutions. “Every member of my organization has achieved at least one certification through ITpreneurs, and this is the second company that I’ve founded with that same promise. [...] It is a proud day, that we can be a part of ITpreneurs’ landmark efforts to bring forward CompTIA Cloud Essentials training and certification. - Robin Basham, Managing Partner.

ComplianceExchange A Blog We Love

Spontaneous Kudos - We've really been digging our digest from The Compliance Exchange

Review enterprisegrc.com on alexa.com

Have you read Value of a Conversation?

Please Join us on Facebook

Read More

Partners and Client Information
EnterpriseGRC Solutions is recently named as a member of the Cloud Credential Council. Holistic Information Security Practitioner Institute names CEO, Robin Basham, to their Education Advisory Board.

Ryma Technology Solutions names EnterpriseGRC Solutions as an Affiliate Partner.  More. Recent Wins: EnterpriseGRC Provides IS0 27001 Policy and SOA readiness for NetSuite Inc.  EnterpriseGRC Solutions Sponsor to ISACA ITGI.  Recent Partner Alignments include ITpreneurs, Control Solutions International

Request For Information? Please fill out our Wufoo form.

Wordle: EnterpriseGRC.com Blog
Cloud Credential Council
Read More

ISACA Silicon Valley LogoAre you attending "Enabling Trust: Business In the Cloud"? Learn more.