Key takeaways
- Documentation should describe the actual state, not planned solutions.
- Dependencies, access, backups and emergency procedures matter most.
- Store passwords in a secrets manager, not in an ordinary document.
- Every infrastructure change should update the relevant entry.
What should you document?
Infrastructure
Servers, networks, VLANs, addressing, devices and locations.
Services
Systems, owners, dependencies, licences and suppliers.
Access
Roles, administrator accounts, MFA and the process for approving changes.
Failure
Contacts, recovery order, backups and escalation procedures.
How should documentation be stored?
Choose one controlled location with versioning and restricted access. Separate general information from secrets. Appoint a documentation owner and establish the review frequency and a method for marking outdated entries.
Documentation is not a backup
Files describing the environment should also have a backup and a copy outside the main system.
Common mistakes
- No update date or entry owner.
- Storing passwords in spreadsheets and messages.
- No network diagram or supplier list.
- Documenting only new systems rather than existing ones.
- No test of the emergency procedure.
Plan for organising documentation
- Collect existing materials.
- Verify the actual state.
- Define the structure and owners.
- Fill critical gaps.
- Secure access and backups.
- Introduce reviews after changes.
Checklist
- There is an up-to-date network diagram.
- We know the systems and their owners.
- Licences and suppliers are recorded.
- The emergency procedure includes contacts.
- Secrets are stored securely.
- The documentation has a backup and change history.
Frequently asked questions
Does a small business need extensive documentation?
No. It primarily needs the information required for day-to-day work and service recovery.
How often should documents be updated?
After every significant change and during scheduled reviews, at least once a year.
Can documentation be stored in the cloud?
Yes, provided there is access control, versioning and an independent backup.
Do you need to organise the knowledge about your IT?
We can help collect information, identify gaps and prepare a documentation structure.
Let's talk about your IT