Procedures - Are the way to ensure that the intent of policy is enforced through a mandated series of steps that must be followed to accomplish a task.
Required step-by-step actions - Procedures are statements of step-by-step actions to be performed in order to accomplish a security requirement, process, or objective. They are one of the most powerful tools available in the security arsenal and must be used wisely. Procedures cover such matters as password changing, incident response, implementing anti-virus software, etc.
Procedures:
Reduce mistakes in a crisis.
Ensure that important steps are not missed.
Provide for places within the process to conduct assurance checks.
Like policies and standards, procedures are mandatory requirements.