Document Type - RunBook
A RunBook, sometimes known as playbook, is a document containing detailed procedures that collectively keep a mission-critical system running. A RunBook is sometimes viewed as an element of Business Continuity Planning (BCP) or Disaster Recover (DR). This is because they are written to assure that an equally skilled administrator would be able to use the RunBook to step in and administer the system until such time that normal staffing and conditions apply. RunBooks are a system current document with all the required information needed to understand how a service or system is kept running. RunBooks are not project plans and do not maintain information unless it is "in use" and a part of the working system.
A RunBook is used to verify and gather the location of all operational information. A production RunBook is evidence of documentation and control over a service or system. It provides information on "how" to run procedures without necessarily providing background for the process. RunBooks are detailed instructions that a user references when performing the process.
On a per system instance, a RunBook can document a small set of operational procedures and reference various guidelines. On a larger scale, a service-oriented RunBook details the combination of systems and their dependencies in keeping service available. This is a valid form of meeting both BCP and various other levels of compliance requirements. Determining this requirement can be as follows:
Why Do RunBooks Focus on Service?
A RunBook is Service-Oriented vs. single system-oriented. When documentation does not meet the requirements mentioned above, it is probable that listing the device in an inventory system is sufficient and further documentation is not required.
Where the availability of a critical or core business function depends upon the accurate working of interdependent systems, it is advisable to have a business owner who assures the current and complete Service RunBook. As is true for any controlled system, the RunBook explains the day-to-day system procedures, but additionally adds some or all of the following elements:
- Functional Overview
- Functional Overview Diagram
- List of Interfaces
- System Overview
- System Overview Diagram (s)
- Network Management Process
- Hardware
- Hardware Management Process
- Software Development and Release
- Third Party Vendor / Software Management
- Performance Monitoring Process
- Database Administration Process
- Quality Assurance
- Vendor Information
- Back Up Processes
- Disaster Recovery Process
- Security
- Problem Management
- Configuration Overview:
- Server/ HW/OS
- Application
- Database Configuration
- Daily cycle
- Fail-over
- Maintenance
- Troubleshooting and Error Messages
- Glossary
- List of files
- Financial Processes
- Test procedure
Should I Write a RunBook?
Consider whether the following statements are true.
Figure 7. Should I create a RunBook?
Where Do I Get the Information That Goes into the RunBook?
Consider the following sources.
RunBooks bring visibility to an aggregation of documents and details that collectively support service availability or product delivery.
When Is a RunBook Complete?
Consider whether the following statements are true.
RunBooks can be maintained as a word report that is output from a single database system or from a collection of systems. The form used to gather RunBook elements (today) is in Facilitated Compliance Management. This is a location that is subject to change. The tool that gathers RunBook details is not critical to the process. The tool for gathering elements can also be a word document, as identified in the template section. The process for generating RunBook information is not important, so long as visibility of how systems run is maintained for the business owner and technology support personnel.
Figure 8. RunBook Process
Example Interface for gathering RunBook elements by Service Title
Where Do I Find the Template?
\\...\pal\Facilitated Compliance Management\...
\\...\pal\Templates\RunBook Template.dot
The current procedure for RunBook is to use our system database and generate a RunBook report as needed.
RunBook Document Elements
The following section is written to address addition questions pertaining to document elements, storing and managing information and how steps and controls are specifically captured to support the internal audit of IT program and application level controls. Sections include:
Where Does My Document Belong?
\\...\PAL\IT Process Asset Library\
- Static Process versus Process Output (Evidence of Using Process)
\\...\PAL\IT Work Product Library\
- Other Work Products and Controlled Documentation:
- Version Control versus VSS (Microsoft Visual SourceSafe)
- Test Scripts, Utilities, and Event Tracking Systems
- Assets, Inventories and Configuration Baselines
- Controls and Key Controls
- Product, Application Development, and Quality Templates
- Flow Diagram






Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics