Operational runbooks

Identifies operational runbooks patterns in security and access control contexts. Detects potential exposure of sensitive security information in international systems.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
category-aware structural regex with anchor and context constraints replaces phrase-only detection. Added context gating and exclusion rules improve precision and reduce incidental matches.
Detection quality
Mixed
Jurisdictions
global
Regulations
GDPR
Data categories
credentials, security
Scope
wide
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:operational\s+runbook|runbook\s+procedure|incident\s+response|escalation\s+procedure|troubleshooting\s+guide|standard\s+operating\s+procedure|on[\s-]+call\s+playbook|recovery\s+procedure|maintenance\s+runbook|operations\s+manual)\b

Corroborative evidence keywords

operational runbooks, operational, runbooks, software, engineering, architecture

Proximity: 300 characters

Should match

Should not match

Known false positives

References