Skip to main content
Category: Security Policies & Standards

Standard Operating Procedures

Also known as: SOP, SOPs, standard operating procedure, standing operating procedure
Simply put

A Standard Operating Procedure (SOP) is a formal document that spells out, step by step, how a specific task or process should be carried out and who is responsible for each part. Its purpose is to make sure people perform work correctly and consistently, so the outcome is reliable every time. In a security program, SOPs turn high-level policies into repeatable instructions that staff can follow.

Formal definition

A Standard Operating Procedure is a standardized, documented set of step-by-step instructions that prescribes how a designated task or process is to be executed routinely, along with the associated roles and responsibilities. Originating in quality management practice, SOPs establish uniform methods intended to produce consistent, quality outcomes and to reduce variability introduced by individual discretion. Within a security leadership context, a virtual or fractional CISO typically directs and reviews the development of SOPs to operationalize governance policies, but the day-to-day authoring, execution, and maintenance of operational SOPs generally remain with the client's internal teams; accountability for adherence and outcomes stays with the client organization unless a contract specifies otherwise. The effectiveness of an SOP depends on organizational maturity, stakeholder cooperation, and periodic review, and an SOP alone documents intended practice rather than guaranteeing compliance with any framework or standard.

Why it matters

Standard Operating Procedures are the connective tissue between policy and practice. A security policy might state that access must be reviewed periodically or that incidents must be reported, but a policy does not tell anyone how to actually do the work. SOPs translate those high-level intentions into concrete, repeatable steps that assign responsibility and reduce the variability that inevitably creeps in when tasks depend on individual memory or judgment. Originating in quality management practice, SOPs exist precisely to make outcomes consistent and reliable rather than dependent on who happens to be performing the task on a given day.

Who it's relevant to

Security and IT operations teams
These teams are typically the primary authors, users, and maintainers of operational SOPs. Documented procedures help them perform recurring tasks correctly and consistently, preserve knowledge across staff turnover, and reduce reliance on undocumented individual expertise.
Virtual and fractional CISOs
A vCISO or fractional CISO often directs and reviews SOP development to ensure procedures operationalize governance policies and reflect the organization's risk priorities. They generally do not own the day-to-day authoring or execution of operational SOPs, and accountability for adherence remains with the client unless a contract states otherwise.
Business and organizational leaders
Executives and officers hold accountability for whether documented procedures are actually followed and produce the intended outcomes. Understanding that SOPs document intended practice rather than guarantee compliance helps leaders invest in the review, training, and stakeholder cooperation that make procedures effective.
Auditors and compliance stakeholders
SOPs can support readiness efforts by demonstrating that intended practices are defined and assigned. Those evaluating a program should distinguish between the existence of a procedure and evidence that it is consistently executed, since an SOP alone does not establish conformance with any framework or standard.

Inside SOP

Purpose and Scope
A statement of what the procedure covers, the tasks it applies to, and the boundaries of when and where it is used. This helps distinguish operational SOPs from higher-level policies and clarifies what is in and out of scope.
Roles and Responsibilities
Identification of who performs, reviews, and approves each step. This section should distinguish responsibility for executing a task from organizational accountability for the outcome, which typically remains with the client's officers rather than an advisory vCISO.
Step-by-Step Instructions
The sequential, repeatable actions required to complete the task consistently. This operational detail is often executed by internal staff or a service provider rather than by a virtual CISO, whose role is typically to advise on and review the procedure.
Triggers and Frequency
The conditions or schedule that initiate the procedure, such as an event-driven trigger for incident escalation or a recurring cadence for access reviews and backup verification.
References to Governing Policies and Standards
Links to the policies, standards, or control frameworks the SOP supports, helping demonstrate how day-to-day operations align with governance intent.
Version Control and Review Cadence
Records of document ownership, revision history, and a defined schedule for review and update so procedures remain current as the environment, tools, or requirements change.

Common questions

Answers to the questions practitioners most commonly ask about SOP.

Does a virtual CISO write and maintain our standard operating procedures directly?
Not usually. A virtual CISO more often defines the governance structure, sets the standards SOPs must meet, and reviews or approves procedures rather than authoring every operational document. Hands-on drafting of detailed operational runbooks, tool configuration steps, or SOC workflows typically falls to internal staff or specialists unless the engagement scope explicitly includes procedure development. This distinction matters because SOPs are largely an operational execution artifact, while the vCISO role is primarily strategy, governance, and oversight. Expect authorship arrangements to vary by provider and by the maturity of your existing documentation.
If we have documented SOPs, does that mean we are compliant with frameworks like ISO 27001 or SOC 2?
No. Having SOPs is one supporting element, not proof of compliance or certification. Frameworks such as ISO 27001, SOC 2, HIPAA, PCI DSS, and CMMC generally expect documented procedures, but they also require that procedures be implemented, followed, and evidenced over time, and in the case of certification, independently assessed. A virtual CISO can help align SOPs to the control expectations of a given framework and support readiness, but documentation alone does not guarantee an audit outcome or a certificate. Accountability for meeting regulatory obligations typically remains with the client organization and its officers.
Who should own each standard operating procedure once it is created?
Ownership is usually assigned to the role or team that performs the underlying work, with a named owner responsible for keeping the procedure accurate and current. A virtual CISO may advise on and direct this ownership model as part of governance, but responsibility for executing and maintaining each SOP generally sits with the operational owner rather than the advisor. Clear ownership matters because SOPs lose value quickly when no one is accountable for updates. In many engagements the vCISO helps establish a review cadence and an ownership register so that documents do not become orphaned.
How often should SOPs be reviewed and updated?
Review frequency varies by organization, risk level, and the rate of change in the underlying process or technology. Many organizations adopt a scheduled review cycle combined with event-driven updates triggered by incidents, tooling changes, audit findings, or regulatory shifts. A virtual CISO can help define a review cadence appropriate to your maturity and framework obligations, but the value depends on client cooperation and on operational owners actually performing the reviews. There is no single universal interval that fits every environment, so the cadence should be set deliberately rather than assumed.
How do SOPs relate to policies and standards in a security program?
These documents typically operate at different levels. Policies express intent and high-level requirements, standards define specific rules or configurations, and SOPs describe the step-by-step actions to carry out the work consistently. A virtual CISO often helps establish this hierarchy so that procedures trace back to policy and align with governance expectations. Confusing the layers is a common mistake; treating a detailed procedure as if it were policy, or vice versa, can create gaps in both governance and execution. The effectiveness of this structure depends on organizational maturity and on stakeholders understanding their respective roles.
What conditions make SOPs actually effective rather than shelfware?
SOP value depends heavily on adoption, defined ownership, accessibility to the people who need them, and integration into day-to-day operations rather than one-time creation. In many engagements, effectiveness also depends on organizational maturity, access to the relevant stakeholders, and a process for capturing and applying feedback. A virtual CISO can advise on how to embed procedures into workflows and how to evidence that they are followed, but sustained execution remains a client responsibility. Documents that are written and then left unmaintained tend to lose relevance and can create a false sense of assurance.

Common misconceptions

SOPs are the same as policies.
They serve different functions. Policies typically state intent and requirements, while SOPs provide the specific step-by-step instructions for executing tasks. Treating them as interchangeable often leaves either the governance intent or the operational detail undocumented.
A virtual CISO will write and then perform the tasks described in the SOPs.
A vCISO typically advises on, structures, or reviews SOPs as part of program development and governance. Hands-on execution of the underlying operational tasks is generally out of scope unless explicitly contracted, and is often handled by internal staff or a separate service provider.
Having SOPs in place guarantees compliance or certification against frameworks such as ISO 27001, SOC 2, or HIPAA.
Documented SOPs can support readiness and demonstrate operational consistency, but they do not by themselves assert compliance or certification. Their value depends on whether the procedures are actually followed, kept current, and evidenced, and outcomes may vary by organizational maturity and client cooperation.

Best practices

Position SOPs within a clear documentation hierarchy, ensuring each procedure maps to a governing policy or standard rather than existing in isolation.
Assign explicit ownership and separate task responsibility from organizational accountability, keeping accountability for enforcement with the client's officers.
Define triggers, frequency, and a review cadence so procedures are updated as tools, environments, and requirements change.
Keep SOPs specific enough to be repeatable by different staff, but review them with stakeholders to confirm they reflect how work is actually performed.
Use SOPs to support framework readiness where relevant, while documenting evidence of adherence rather than assuming the SOP alone demonstrates compliance.
Confirm through the engagement scope whether the virtual CISO's role is to advise on and review SOPs or to execute the operational tasks, and document that boundary.