Purpose and Scope
Procedure Guidelines and Controls Documentation outlines how to create and modify procedures, work instructions, policies, and RunBooks as they currently exist in their correct location and format and as aligned to the requirements of document security.
Change control, information asset location, and documentation format standards are the combined responsibility of Security Management, Quality Assurance, and Process Engineering. In the context of creation, iteration, approval, and posting, the Process Librarian manages documentation.
Process Engineering manages quality over documentation as demonstrated by document templates.
Security Management defines policy and access rules for the recording, adherence to, and monitoring of procedures involving data integrity, privacy, and security across any enterprise-level configuration.
Policy Statement
All changes, additions, and deletions to the production documentation library require management approval. Managers should notify Process Engineering of changes to production process.
Requirements
The primary security elements of any document library management process are:
- Auditable changes
- Evidence of document library and document lifecycle management that is readily available for those who need to monitor this activity.
Documentation strategies need to:
- Reduce complexity.
- Prioritize key control processes
- Reflect COMPANY process architecture
- Represent real functions and real activities
Document Library Management Program
A formal document library management program manages the Process Asset Library and monitors compliance with document lifecycle objectives (i.e., annual document reviews). The program must include, but is not limited to, the following controls:
- Documented procedures for updating production documentation.
- Defined roles and responsibilities that support defined procedures for document and document library maintenance.
- Accountability for document content integrity.
- Education, notification, and awareness process to inform all necessary stakeholders affected by document modifications.
- Separation of production and non-production documentation.
- A defined data retention goal for each document or class of document. Documents are maintained for the lifecycle of the process. If aligned to key controls and loaded in [Name of core product or service], the document is retained as part of SAS 70 evidence.
Document lifecycle control procedures must detail the process for: (Process Profile Creation doc - sections embedded in this doc)
- Reviewing new or changed documents.
- Approving and rejecting documents.
- Posting documentation.
- Documenting information about documentation (metadata).
- Auditing the lifecycle of documents in the library.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics