Define, approve, publish, communicate and regularly review information security policies aligned to business strategy and applicable regulations.
Also written as A5.1, Annex A 5.1, ISO 27001:2022 A.5.1, ISO27001 A.5.1.
Policies for information security is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Define, approve, publish, communicate and regularly review information security policies aligned to business strategy and applicable regulations. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.
When preparing your Statement of Applicability (SoA) for A.5.1, gather artefacts such as:
What actually gets raised against A.5.1, in rough order of how often it comes up:
A.5.1 is applicable to essentially every ISMS — excluding it is very difficult to justify, because the management-system clauses independently require a policy. If your organisation is small enough that one person writes and approves everything, the control still applies; what changes is the formality, not the requirement.
If you run more than one framework, the same evidence usually satisfies all of them. A.5.1 aligns with:
SOC 2: CC1.1 Integrity and ethical values, CC5.3 Policies and procedures
NIST CSF 2.0: GV.PO-01 Policy established and communicated, GV.PO-02 Policy reviewed and updated
A.5.1 consolidates the following ISO 27001:2013 control(s): A.5.1.1, A.5.1.2. If you are transitioning an existing ISMS, map your prior evidence for these to A.5.1 in your updated SoA.
See all 37 Organisational Controls →
Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.1 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.
In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.
ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.
A.5.1 aligns with SOC 2 CC1.1, CC5.3 and NIST CSF GV.PO-01, GV.PO-02. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.
A.5.1 consolidates 2 control(s) from the 2013 edition: A.5.1.1, A.5.1.2. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.
Policies approved by IT rather than by top management, which does not satisfy the Clause 5.2 expectation behind this control. A review date that has passed. An out-of-date review is worse than no schedule at all, because it demonstrates a process you are not following.