A.5 37 controls · 3 new in 2022

ISO 27001 Organisational Controls (A.5)

The largest of the four Annex A themes, covering governance, policy, supplier relationships, incident management and compliance.

What the Organisational Controls theme covers

A.5 is where an ISO 27001 audit starts and where most non-conformities are raised, because these controls are about decisions and accountability rather than technology. There is rarely a product you can buy to satisfy them: the evidence is a named owner, an approval trail, and proof the control is exercised on a defined cadence. Organisations transitioning from ISO 27001:2013 find the heaviest consolidation here — several 2013 controls frequently collapse into a single 2022 control, so the transition work is usually re-pointing existing evidence rather than building new controls.

All 37 Organisational Controls

A.5.1 Policies for information security
Define, approve, publish, communicate and regularly review information security policies aligned to business strategy and applicable regulations.
A.5.2 Information security roles and responsibilities
Define and allocate information security responsibilities across the organisation and communicate them clearly.
A.5.3 Segregation of duties
Separate conflicting duties and areas of responsibility to reduce opportunities for unauthorised modification or misuse of information.
A.5.4 Management responsibilities
Require all managers to apply information security in accordance with established policies within their areas of responsibility.
A.5.5 Contact with authorities
Maintain appropriate contacts with relevant authorities (law enforcement, regulators, emergency services) for IS purposes.
A.5.6 Contact with special interest groups
Maintain appropriate contacts with security forums, professional associations, and special interest groups to stay current on threats and best practices.
A.5.7 Threat intelligence New
Collect, analyse and act on information about threats to information security to make risk management decisions.
A.5.8 Information security in project management
Integrate information security into project management processes regardless of project type.
A.5.9 Inventory of information and other associated assets
Identify information and associated assets and define appropriate ownership and protection responsibilities.
A.5.10 Acceptable use of information and other associated assets
Define rules for acceptable use and procedures for handling information and assets, covering all personnel.
A.5.11 Return of assets
Ensure all assets are returned by employees and external parties upon change or termination of employment or contract.
A.5.12 Classification of information
Classify information according to confidentiality, integrity and availability needs based on legal, value and sensitivity criteria.
A.5.13 Labelling of information
Develop and implement procedures for labelling information in accordance with the classification scheme.
A.5.14 Information transfer
Define, implement and manage rules and controls for information transfer, covering all transfer types and channels.
A.5.15 Access control
Define and implement rules to control physical and logical access to information and information assets based on business and security requirements.
A.5.16 Identity management
Manage the full lifecycle of identities — creation, maintenance, disabling and removal — for all users of information systems.
A.5.17 Authentication information
Control the allocation and use of secret authentication information, ensuring appropriate secrecy is maintained.
A.5.18 Access rights
Provision, review, modify and revoke access rights in line with the access control policy.
A.5.19 Information security in supplier relationships
Define and implement controls to manage information security risks associated with using products or services from suppliers.
A.5.20 Addressing information security within supplier agreements
Establish and maintain relevant IS requirements in agreements with each supplier that may access, process or provide IT infrastructure for the organisation.
A.5.21 Managing information security in the ICT supply chain
Define and implement processes and procedures to manage IS risks related to the ICT products and services supply chain.
A.5.22 Monitoring, review and change management of supplier services
Regularly monitor, review and audit supplier service delivery including changes to ensure agreed levels of IS and service are maintained.
A.5.23 Information security for use of cloud services New
Specify, implement and manage information security controls for cloud service acquisition, use, management and exit.
A.5.24 Information security incident management planning and preparation
Plan and prepare for managing IS incidents by defining processes, roles and responsibilities.
A.5.25 Assessment and decision on information security events
Assess IS events and determine whether they should be classified as IS incidents.
A.5.26 Response to information security incidents
Respond to IS incidents following documented procedures — containment, eradication, recovery and communication.
A.5.27 Learning from information security incidents
Use knowledge gained from IS incidents to improve controls and reduce the likelihood or impact of future incidents.
A.5.28 Collection of evidence
Define and apply procedures for identifying, collecting, acquiring and preserving evidence related to IS incidents.
A.5.29 Information security during disruption
Plan how to maintain information security at an appropriate level during disruption.
A.5.30 ICT readiness for business continuity New
Plan, implement, maintain and test ICT readiness to ensure information availability during disruption.
A.5.31 Legal, statutory, regulatory and contractual requirements
Identify, document and keep up-to-date all relevant legal, statutory, regulatory and contractual requirements for IS.
A.5.32 Intellectual property rights
Implement controls to protect intellectual property rights, including software licences and proprietary data.
A.5.33 Protection of records
Protect records from loss, destruction, falsification, unauthorised access and unauthorised release, in accordance with legal, regulatory and business requirements.
A.5.34 Privacy and protection of PII
Identify and meet requirements for the preservation of privacy and protection of personally identifiable information as required by applicable legislation.
A.5.35 Independent review of information security
Review the IS approach and its implementation independently at planned intervals or when significant changes occur.
A.5.36 Compliance with policies, rules and standards for information security
Regularly review compliance with the organisation's IS policy, topic-specific policies, rules and standards.
A.5.37 Documented operating procedures
Document, maintain and make available to authorised personnel operating procedures for information processing facilities.

Other Annex A themes

A.6 People Controls A.7 Physical Controls A.8 Technological Controls
Crosswalk to SOC 2 & NIST CSF →
Map these controls across frameworks in the Control Mapper.
Search all 93 controls →
Filter Annex A by keyword, theme or control ID.

Frequently asked questions

How many Organisational Controls are there in ISO 27001:2022?

There are 37 controls in the A.5 Organisational Controls theme, of which 3 are new in the 2022 revision. Annex A defines 93 controls in total across four themes: Organisational (37), People (8), Physical (14) and Technological (34).

Do I have to implement every Organisational Controls control?

No. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify any exclusion in the Statement of Applicability — it does not require you to apply all 93. What auditors test is whether the justification is risk-based and documented, not whether the count is high.

What replaced the ISO 27001:2013 domains?

The 2013 edition organised 114 controls into 14 domains (A.5–A.18). The 2022 revision restructured them into 93 controls across four themes, merging 57 and introducing 11 new ones. Each control page below lists its 2013 predecessors so you can re-point existing evidence during transition.