We use cookies

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. You can also customize your preferences or reject non-essential cookies. Learn more about our cookie policy

    Security

    What are security procedures?

    Security procedures are the step-by-step instructions people follow during access changes, incidents, and day-to-day control of systems. They turn a security policy into actions with owners, steps, and a review date.

    2 min read

    Woman at a workplace desk documenting security procedures on a laptop
    On this page

    A security policy says what must be true (“MFA is required”, “client data stays in the EU”). Security procedures say how staff do it on Tuesday afternoon: which screens to open, who approves, what to log, and what to do when it fails.

    What are security procedures?

    Security procedures are written, repeatable instructions for protecting information and systems. A usable procedure has:

    • A name and type (access, incident, physical, backup, vendor)
    • Scope (which systems, teams, or clients)
    • Steps in order
    • Responsible parties (named roles, not a dead email alias)
    • Evidence (tickets, screenshots, vault items)
    • A review date so the runbook does not describe retired tools

    They exist so the first hour of an incident is not spent hunting Confluence.

    Typical security procedures

    • Account provisioning and offboarding
    • Granting vault or folder access
    • Reporting a lost laptop or phished mailbox
    • Incident response (contain, notify, recover)
    • Backup restore tests
    • Handling of identity documents and NDAs
    • Password and MFA exceptions

    For MSP-oriented policy structure, see our IT security policy template for MSPs. Procedures sit underneath that policy.

    Policy vs procedure vs control

    PolicyProcedureControl
    AsksWhat is required?How do we do it?Is it actually happening?
    ExampleMFA on all vault usersSteps to enrol an authenticator appAdmin report: % of users with MFA

    Auditors ask for procedures because they prove the policy is operational.

    Where to keep them

    Wiki pages go stale and are often readable by the whole company. Sensitive runbooks (break-glass, incident comms) belong in an encrypted digital vault with permissions for security and the people who must execute the steps.

    Hypervault includes a Security procedures template: procedure name, type, department, steps, owners, review date, and attachments.

    Store related secrets (admin logins, emergency contacts) as linked vault items—not in the same open wiki as the marketing site copy.

    Frequently Asked Questions

    security procedurescomplianceincident responsedigital vault

    Related insights