---
title: Procedures
description: Learn what a procedure is, how it provides step-by-step instructions, and how it differs from policies and processes.
---

[Skip to content](https://support.futurefeed.co/knowledge-base/hc/en-us/articles/360057155932-procedures#main-content)

[![FutureFeed-White-Green-SupportCenter](https://support.futurefeed.co/hs-fs/hubfs/FutureFeed-White-Green-SupportCenter.png?width=400&height=99&name=FutureFeed-White-Green-SupportCenter.png)](https://support.futurefeed.co/?hsLang=en)

- [HawkAI™ Support Home](https://support.futurefeed.co/)
- [Knowledge Base](https://support.futurefeed.co/knowledge-base)
- [Submit Ticket](https://support.futurefeed.co/support-forms)
- [My Tickets](https://support.futurefeed.co/support?status=all&view=my_tickets&offset=0)

Open main navigation

Close main navigation

- [HawkAI™ Support Home](https://support.futurefeed.co/)
- [Knowledge Base](https://support.futurefeed.co/knowledge-base)
- [Submit Ticket](https://support.futurefeed.co/support-forms)
- [My Tickets](https://support.futurefeed.co/support?status=all&view=my_tickets&offset=0)

 FutureFeed's Knowledge Base

- There are no suggestions because the search field is empty.

1. [FutureFeed Support](https://support.futurefeed.co/knowledge-base?hsLang=en)
2. [Manage Compliantly](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en)
3. [Technology Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#technology-subway-stop)

# Procedures

## Also called: How-To, Step Guide, SOP (standard operating procedure), Procedure

**What it is**

A **Procedure** is a **step-by-step set of instructions** to accomplish **one specific outcome**.

It answers:

- “How do we do this task correctly?”

**Why it exists**

Because “do backups” is a policy-level expectation. A procedure is what stops you from discovering you’ve been backing up the wrong folder for 9 months.

**Characteristics of effective procedures**

- **Clear scope** – Defines when and to whom the procedure applies
- **Step-by-step structure** – Logical, ordered actions
- **Roles & responsibilities** – Identifies who performs each step
- **Triggers & inputs** – Describes when the procedure starts
- **Outputs & evidence** – Specifies expected results or records
- **Version control** – Includes owner, review cycle, and approval

**Examples**

- “How to reset a password”
- “How to onboard a new employee account”
- “How to run the monthly vulnerability scan”

**How to use it**

- Follow it when doing the task.
- Update it when reality changes (new tool, new workflow).
- Use it to train new people without turning into a bottleneck.

**Common confusion**

**Procedure vs List:**

- A list of *results* = artifact
- A list of *steps to do* = procedure

**For CMMC**

There are 194 documents separately referenced in the CMMC Assessment Guide.  After separating those that are procedures and FutureFeed's deduplication for those that have similar titles but slight variances in naming, 27 remain.

**CMMC Documented Procedures Listing**

The current CMMC Assessment Guide identifies the following procedures or groups of procedures as it describes the sorts of documents an assessor may look to review.  To be clear, this isn't a list of specific procedures.  Many are groups of them.  But you can use the list to make sure that the procedure documentation that you have addresses as many of these areas as possible:

1. Access Control Procedures - Including Mobile and Privileged
2. Asset Management Procedures
3. Audit Procedures - Events, Record Generation, Record Reduction, Analysis, Review, Reporting, Retention, Protection, and Access
4. Audit and Accountability Procedures – High Level
5. Authenticator Management Procedures
6. Change Management Procedures - Security Impact Analysis and System Configuration
7. Configuration Management Procedures
8. Data Protection Procedures
9. External Systems Use Procedures
10. Identification and Authentication Procedures
11. Information Flow Enforcement Procedures
12. Information Security Procedures
13. Insider Threat Procedures
14. Investigation of and Response to Suspicious Activities
15. Least Privilege, Divisions of Responsibility and Separation of Duties Procedures
16. Plan of Action (POA&M) Procedures
17. Publicly Accessible Content Procedures
18. Remote Access Procedures
19. Security Assessment Planning and Implementation Procedures
20. Security Awareness Training Implementation Procedures
21. Session Control Procedures - Lock, Termination Etc.
22. System Inventory Procedures
23. SSP Development and Management Procedures
24. System Use Notification Procedures
25. Time Stamp Generation Procedures
26. Unsuccessful Logon Attempts Procedures
27. User Installed Software Procedures

Organizations need not have exactly this list of procedures but should have a set of procedures that address these items.  Future versions of FutureFeed will allow tagging of uploaded procedures with the above list.

 Why Do It? The Importance of Process Documentation

Source: [Process Documentation Guide: Learn How to Document Processes (creately.com)](https://creately.com/blog/diagrams/process-documentation-guide/)

Documenting a process will help you achieve 5 key things:

1. **Helps improve processes.** Identify bottlenecks and inefficiencies by documenting the exact processes. You’ll quickly see what processes that you need to improve or get rid of.
2. Compliance.  Following documented process proves a pattern of compliance, especially if checklists are used and kept as a record.
3. **Helps train employees.** You can use process documents to help new employees understand their job roles and familiarize themselves with the processes they’ll be involved in.  Even experienced employees can still refer to these documents whenever they want to make sure that they are executing the process right.
4. **Helps preserve company knowledge.** Keep a record of processes known only to a few people specialized in doing them. That way even when they leave, the newcomers can resume the work easily.
5. **Helps mitigate risks and maintain operational consistency**.

![project-2021-03-04\_11-03\_AM.png](https://support.futurefeed.co/hubfs/Knowledge%20Base%20Import/project-2021-03-04_11-03_AM.png)

 

### Tips and Tricks: Process Documentation Best Practices

- Keep the document **simple and concise**. While it should be **technically accurate**, it should be **easy to follow**.
- Have a proper **plan in place to update the documents** when/if the process would change. Make sure to **review them at least once a year**.  Note the review date in the document.
- **Assign a process owner (Accountability in FutureFeed)** who can do regular reviews and notify others of the changes.
- When documenting processes for the first time, avoid covering the entire organization at once. **Start from a single process within a department** or a major process common to the entire organization.
- Store the documents in FutureFeed or a location that is **easy to be accessed** by anyone who is looking for it.
- Make sure that it is **easy to be revised** when needed and the new version can **easily be distributed** to everyone involved.  FutureFeed will be adding functionality in the future to help get this done.
- Use appropriate **examples, graphics, color coding, screenshots, multiple platforms** etc. as necessary.
- **Add swimlanes to your business process flowcharts** to distinguish different process roles, timelines etc.
- **Create a process documentation guide**, which anyone can refer to as a standard template for documenting a process.
- **Make use of existing documentary material**, records, interviews, case studies, field-diaries of project staff and the knowledge of employees to gather information for process documentation.

- [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program-regulation-guidance?hsLang=en#main-content)

    - [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program-regulation-guidance?hsLang=en#cmmc-program)
- [Product Information](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#main-content)

    - [Basic Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#basic-pricing)
    - [Advanced and Volume Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#advanced-and-volume-pricing)
    - [Features](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#features)
    - [Additional Details](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#additional-details)
    - [CMMC Express Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#cmmc-express-pricing)
- [How-to's](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#main-content)

    - [How-to... Build and Manage Projects in "Your FutureFeed"](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-build-and-manage-projects-in-your-futurefeed)
    - [How-to... Deliverables](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-deliverables)
    - [Other Features](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#other-features)
    - [How-to... Manage Tools, Services, and Documentation](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-tools-services-and-documentation)
    - [How To... Onboarding Rocket](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-onboarding-rocket)
    - [How-to... Big Picture](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-big-picture)
    - [How to... Work in the Assess Subway Stop](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-work-in-the-assess-subway-stop)
    - [How-to.... Manage People and Users](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-people-and-users)
    - [How To... Complete the SSP](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-complete-the-ssp)
    - [How to ... Manage a Marketplace Listing](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-a-marketplace-listing)
    - [How To.... Recurring Tasks](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-recurring-tasks)
- [Terminology](https://support.futurefeed.co/knowledge-base/terminology?hsLang=en#main-content)

    - [Glossary](https://support.futurefeed.co/knowledge-base/terminology?hsLang=en#glossary)
- [Getting started](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#main-content)

    - [Navigation](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#navigation)
    - [Subscription Management](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#subscription-management)
    - [Platform Access](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#platform-access)
    - [Compliance Standards - Background Information](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#compliance-standards-background-information)
- [Manage Compliantly](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#main-content)

    - [Technology Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#technology-subway-stop)
    - [Company Profile](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#company-profile)
    - [Deliverables Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#deliverables-subway-stop)
    - [Your FutureFeed Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#your-futurefeed-subway-stop)
    - [SSP Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#ssp-subway-stop)
- [Webinars and Features](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#main-content)

    - [NIST SP 800-171 R3](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#nist-sp-800-171-r3)
    - [2023 User Webinars](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#2023-user-webinars)
    - [Features](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#features)
- [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#main-content)

    - [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#cmmc-program-regulation-guidance)
- [FutureFeed Support](https://support.futurefeed.co/knowledge-base/futurefeed-support?hsLang=en#main-content)

    - [Product Information](https://support.futurefeed.co/knowledge-base/futurefeed-support?hsLang=en#product-information)
- [Frameworks](https://support.futurefeed.co/knowledge-base/frameworks?hsLang=en)
- [Tools and Services](https://support.futurefeed.co/knowledge-base/tools-and-services?hsLang=en)
- [Hawk AI](https://support.futurefeed.co/knowledge-base/hawk-ai?hsLang=en)
- [CMMC Fundamentals](https://support.futurefeed.co/knowledge-base/cmmc-fundamentals?hsLang=en#main-content)

    - [SPRS & Compliance Reporting](https://support.futurefeed.co/knowledge-base/cmmc-fundamentals?hsLang=en#sprs-compliance-reporting)

[![FutureFeed-White-Green-SupportCenter](https://support.futurefeed.co/hs-fs/hubfs/FutureFeed-White-Green-SupportCenter.png?width=300&height=74&name=FutureFeed-White-Green-SupportCenter.png "FutureFeed-White-Green-SupportCenter")](https://support.futurefeed.co/?hsLang=en)

FutureFeed Footer – Newest

## Footer

[1-844-725-8252](tel:14105605602) [support@futurefeed.co](mailto:support@futurefeed.co)

- [Facebook](http://facebook.com/FutureFeedCompliance/)
- [X (Twitter)](https://x.com/futurefeedco/)
- [LinkedIn](https://www.linkedin.com/company/futurefeed/)

Attain. Maintain. Prove It Anytime.

### Resources

- [15-Min with FutureFeed](https://zoom.us/meeting/register/WKkYTumjR6OOUjNRwZi91A#/registration)
- [User - Schedule a Training](https://futurefeed.co/schedule-training/)
- [Partner - Schedule a Training](https://futurefeed.co/schedule-training/)
- [Download the Everything Book](https://futurefeed.co/cmmc_guide/)

### Legal

- [Terms of service](https://futurefeed.co/terms/)
- [Privacy policy](https://futurefeed.co/privacy/)
- [Security](https://futurefeed.co/security/)
- [Legal](https://futurefeed.co/legal/)

©  FutureFeed.co. All rights reserved.

Disclaimer: The appearance of U.S. Department of Defense (DoD) visual information does not imply or constitute DoD endorsement.