Skip to content

Runbook

What is Runbook?

A documented set of standardized procedures and actions that guide operators in performing routine operations and responding to specific scenarios.

Information Security

What the standards actually require on runbook

Requirements naming runbook across 6 standards, quoted from the control text.

NIST SP 800-922 controls

Establish a log management programme per NIST SP 800-92 Chapter 2 (Introduction to Computer Security Log Management) + Chapter 4 (Log Management Planning).

NISTSP92-1 · Log Management Programme, Policy, Roles, and Operational Runbooks
HKMA TM-G-12 controls

HKMA TM-G-1 IT Operations. (1) IT OPERATIONS MANAGEMENT (TM-G-1.5.1) - 24x7 operations + monitoring + service delivery + ITIL + ITSM + ServiceNow + BMC + others + operations runbooks + procedures + sound operational practices + automation + DevOps + SRE + IT s...

HKMA-TMG1-Operations-Capacity-Problem-Incident · TM-G-1 IT Operations + Capacity + Performance + Problem + Incident Management

Run blameless post-incident reviews, capture root causes and contributing factors, and feed improvements back into controls, runbooks and training.

SEC10-BP08 · Establish a framework for learning from incidents

HKMA C-RAF Domain 5 RESPONSE AND RECOVERY + Domain 6 SITUATIONAL AWARENESS. DOMAIN 5 RESPONSE AND RECOVERY (3 sub-areas): (1) INCIDENT RESPONSE PLANNING - documented IR plan + playbooks + runbooks + RACI + escalation criteria + decision trees + communication p...

HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness · HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

Kuwait NCF Detect function. Security Monitoring and Logging: comprehensive logging (Identity + Network + Endpoint + Cloud + Application + Database + Privileged Access + Network Devices + Cloud Trail + Container + IoT/OT) + centralised log management + Security...

KNCF-Detect-Monitoring-SIEM-SOC-Threat-Intel-CTI-MITRE-ATT-CK-EDR-XDR-MDR-24-7-Continuous · Kuwait NCF Detect + Monitoring + SIEM + SOC + Threat Intel + EDR + XDR + 24/7

Apply NIST SP 800-146 Section 9.4 (Security Recommendations) and Section 9.5 (Privacy Recommendations) across the cloud portfolio. Security recommendations must address (a) shared responsibility model documented per service-model, (b) identity and access manag...

NISTSP146-6 · Cloud Security and Privacy Recommendations

Questions people ask about runbook

What is Runbook?
A documented set of standardized procedures and actions that guide operators in performing routine operations and responding to specific scenarios.
Why is Runbook important for compliance?
Runbook is a key concept in Information Security. Understanding runbook helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Runbook?
Runbook appears in the requirement text of NIST SP 800-92, HKMA TM-G-1, AWS Well-Architected Security Pillar, HKMA Cyber Resilience Assessment Framework (C-RAF), Kuwait National Cybersecurity Framework. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Runbook?
Explore our compliance framework pages to see how runbook applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Runbook applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.