Should I Write a Program Profile?
Program profiles are not required but can facilitate a great many other functions including Audit and Training or Organization Requirements Definition. Where a program profile supports the organization to explain a department charter, it is a simple and useful tool that may benefit employees and auditors equally.
Consider whether the following statements are true.
Figure 5. Should I write a program profile?
Where Do I Find the Template?
\\...\PAL\Templates\Program Profile Template.dot
Templates that describe positions or assist in the design of a program organizational chart are located in:
\\...\PAL\IT Process Asset Library\Human Resources\Template\Job Description Template.dot
\\...\PAL\IT Process Asset Library\Human Resources\Template\Employee Warning Notice.dot
\\...\PAL\IT Process Asset Library\Human Resources\Template\Job Analysis Questionnaire.dot
Document Type - Work Instruction or SOP
Work Instructions, also known as Standard Operating Procedures, (SOP) represent:
- The greatest level of technical detail
- Are tool dependent.
- Change when technology changes
- Are updated often
- Stored in knowledge management systems or help desk database
- Associated with specific tools and tasks
- Used to guide and train workers at the task implementation level
- Are part of an already approved process
Work instructions or SOP's can be located within a functional area and are often embedded in help files within systems. RunBooks (explained in the next section) reference work instructions to facilitate answering the question, "Where do I find directions to perform this task?" Whereas process changes are a part of standard change management, work instruction may be updated as a course of an individual's personal need to track how detailed steps are done. A work instruction may have general or highly specialized use. Where work instructions are critical to the control of a process, it is the business manager's responsibility to ensure that routine work procedures exist and are followed within their functional area.
All service-affecting operational processes must be documented to prevent service disruption caused by the absence of primary staff. Any procedure required to maintain operations, that is not already documented as a part of routine system functions, (i.e., already located in general product help files), must be documented to assure that in the absence of primary staff, the process can be sustained by others. At a minimum, all personnel are accountable to documentation to the extent that a similarly trained staff could stand in for emergency coverage and be able to use directions to maintain required operations. Where staff fail to keep their work instructions up to date, the failure is both on the part of the individual and the area manager.
Work instructions or SOPs are a simple list of steps that explain in clear terms, how to achieve a specific result.
Directories containing work instructions and SOPs should be clearly labeled and information should be current. Work instructions can exist in all event-tracking systems and are not centrally located but are accessible and known to all persons within the user department.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics