TechKnowSurge
ISC2 CISSP 1.6 CompTIA Security+ 5.1 NIST CSF GV.PO-01 NIST 800-53 PM-1 CompTIA Security+ 4.8 EC-Council CEH 4.2 NIST CSF ID.IM-04
VideoSecurityFree

Procedures

Procedures translate policies and standards into actionable, step-by-step instructions that guide how organizations implement processes, manage daily operations, and respond to incidents. Collectively, these procedures form a playbook that strengthens consistency, accountability, and security across the organization.

Complete this video to capture a CTF flag worth 1 point.

About this video

Policies and standards establish the goals and quality benchmarks an organization aims to meet, but they do not specify how to meet them. That is the role of procedures — detailed, step-by-step instructions that guide how processes are implemented, how daily functions are carried out, and how specific events are handled. A disaster recovery policy, for example, sets the standard for recovery objectives, while a disaster recovery plan built from that policy contains the specific procedures for executing a failover to a backup site. Procedures span nearly every operational domain, including asset management, personnel management such as employee onboarding and offboarding, change management, and risk management. Complex processes like risk management can be broken into sub-procedures covering risk identification, analysis, prioritization, mitigation, and monitoring — each of which may itself contain granular steps such as scheduling a kickoff meeting, distributing communications, and conducting an asset inventory. This layered structure produces substantial documentation, but the depth is necessary to ensure every function is carried out correctly and consistently. The full collection of these instructions is commonly referred to as a playbook. Although introducing formal procedures can initially feel like added overhead, the operational and security benefits are significant. A real-world example involves wire transfer fraud, a common attack in which malicious actors impersonate internal stakeholders to trick accounting teams into sending funds. Organizations that have established formal wire transfer approval workflows — incorporating checks and balances and clear separation of duties — are far better positioned to catch and stop these attempts before any financial damage occurs. Documented procedures not only improve efficiency and reduce errors, but they also close the gaps that threat actors actively look to exploit.

What you'll learn

What's covered

Policies, Standards & Procedures

Aligned to

ISC2 CISSP
1.6 Develop, document, and implement security policy, standards, procedures, and guidelines
CompTIA Security+
5.1 Summarize elements of effective security governance.
4.8 Explain appropriate incident response activities.
NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved.
NIST 800-53
PM-1 Information Security Program Plan
EC-Council CEH
4.2 Social Engineering

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Procedure
A detailed, step-by-step set of instructions for carrying out a specific task in alignment with policies and standards.
Playbook
A security playbook is a structured set of predefined response procedures for specific incident types, guiding analysts through detection, containment, eradication, and recovery steps in a consistent and repeatable manner.
Separation of Duty
A security control that divides critical tasks among multiple individuals to reduce the risk of fraud or error.

Topics

Security Governance Security Policies Security Procedures Incident Response Playbooks Social Engineering Organizational Risk Management

Transcript

Policies and standards create that layout of what we're trying to accomplish and achieve, and create the standard, that quality of what we're trying to achieve, but it doesn't tell us how we're going to go about achieving it. That's what procedures do tell us.

Procedures are those step-by-step instructions that tell us how we're going to roll something out, or how we're going to implement something, or how we're going to do our day-to-day functions. So whereas we might have a disaster recovery policy that has our standards built into it, we would then create a plan out of that and create a disaster recovery plan that helps us fulfill what we're trying to achieve. Within this plan, what we can do is specify those procedures that we would carry out - how to do a disaster recovery failover would be one example of that. That would give the actual steps of what we're going to follow to do a failover to another site.

Procedures I like to lay out

Here are some of the procedures that I like to lay out for the departments I work with. For instance, we have some sort of asset management: how do we manage our assets? We have personnel management, things like onboarding and offboarding, so we would have a procedure that we would follow when we'd hire somebody, and then we'd also have to do the same thing when somebody left the company. We also have things like change management: what is the process somebody will follow whenever they're making a change on the system?

Each one of those could be broken down into smaller tasks. Risk management procedures, for example, could be the risk tolerance and then the identification, analysis, prioritization, plan, mitigation and monitoring. If we take a further step into identification of the risk management process, then we can break that down into its smaller components, such as: we would do a risk assessment kickoff meeting, maybe there's some communication that needs to go out, then we do an asset inventory, and so on and so forth. Once again, we could break down that asset inventory into actual steps and procedures that we follow to accomplish the task.

So we end up with a lot of documentation, because there are so many different procedures that we need to follow to carry out our function. One of the things that we call this is a playbook. A playbook is the set of instructions that we use to carry out these different functions.

I can tell you, a lot of times when you roll out something like this, that there are procedures to follow, sometimes you'll get some pushback, because it adds extra complexity to how we're going about doing our job. But there are so many advantages that I've found, that even when I've dragged my feet in implementing some of these changes, once I've implemented them it really has a lot of benefits.

An example: wire transfers

Let me give you one example that I encountered in the past, and it has to do with wire transfers. What a wire transfer is, is a way that we can electronically send money, and a lot of businesses will do wire transfers to get money from one business to another so they can pay for certain services or products.

What happened is that somebody submitted a wire transfer order into our accounting department, and our accounting department was going to process that order, and something kind of clued in with the accountant that was working on this, and they said something doesn't feel quite right. They reached out to the person that they thought was sending in this money, but it ended up being a scam. Luckily we didn't pay this person any money and didn't do the wire transfer.

But what we did do is we took a look at our procedures and we said, how did this fall through the cracks? How did we allow this to even be a risk to us? We looked at those procedures and we made sure that the procedures were set up in such a way where there are these checks and balances, that there is this separation of duty, that we wouldn't pay any wire transfer unless it went through this proper process. Therefore we eliminated the risk that this would happen in the future, as long as people were following those processes and procedures.

So that's a great example, and this is one that happens quite a bit out there and one to watch out for: making sure that you have the proper procedures to make sure that no one could scam you or leverage the situation to be able to get you to send money to them.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →