Category 5
Organizational controls
37 controls in the reference set, with dedicated implementation, evidence and audit guidance.
Explore organizational controls →ISO 27001 implementation library
Turn priority Annex A topics into proportionate implementation steps, useful evidence and audit-ready operating examples.
Category 5
37 controls in the reference set, with dedicated implementation, evidence and audit guidance.
Explore organizational controls →Category 6
8 controls in the reference set, with dedicated implementation, evidence and audit guidance.
Explore people controls →Category 7
14 controls in the reference set, with dedicated implementation, evidence and audit guidance.
Explore physical controls →Category 8
34 controls in the reference set, with dedicated implementation, evidence and audit guidance.
Explore technological controls →Control 5.1
Set coherent, approved direction for information security and keep supporting policies aligned with business, risk and compliance needs.
Read the full guide →Control 5.2
Allocate clear accountability and authority for security decisions and recurring activities.
Read the full guide →Control 5.3
Reduce opportunities for error, misuse or concealment by separating incompatible responsibilities or applying compensating oversight.
Read the full guide →Control 5.4
Ensure managers actively reinforce security expectations within the teams and processes they direct.
Read the full guide →Control 5.5
Maintain usable routes for regulatory, law-enforcement and emergency contact when events or obligations require coordination.
Read the full guide →Control 5.6
Use trusted professional and industry communities to stay informed about relevant security developments and good practice.
Read the full guide →Control 5.7
Collect and evaluate relevant threat information so risk, monitoring and protective decisions reflect the current environment.
Read the full guide →Control 5.8
Integrate security risk and control decisions into project governance from initiation through delivery and closure.
Read the full guide →Control 5.9
Maintain a reliable view of information and supporting assets that need protection, including clear ownership and lifecycle accountability.
Read the full guide →Control 5.10
Set practical expectations for how people may use and protect information, devices, services and facilities.
Read the full guide →Control 5.11
Recover organizational assets and information when roles, contracts or relationships change or end.
Read the full guide →Control 5.12
Apply consistent sensitivity and handling decisions to information based on business value, obligations and impact.
Read the full guide →Control 5.13
Communicate classification or handling needs in a usable form so people and systems can apply the right protections.
Read the full guide →Control 5.14
Protect information while it is shared internally or externally through approved channels and accountable arrangements.
Read the full guide →Control 5.15
Set risk-based principles for granting, using, reviewing and removing physical and logical access.
Read the full guide →Control 5.16
Manage identities consistently across creation, verification, change, suspension and removal.
Read the full guide →Control 5.17
Issue, protect, reset and retire credentials and authentication secrets through controlled processes.
Read the full guide →Control 5.18
Approve, provision, review and remove access rights according to role, need and changing employment or supplier status.
Read the full guide →Control 5.19
Identify and manage security risk arising from suppliers and the services, information or systems they support.
Read the full guide →Control 5.20
Translate supplier risk and service expectations into clear, enforceable security terms and responsibilities.
Read the full guide →Control 5.21
Extend supplier assurance to relevant technology dependencies, subcontractors, components and lifecycle risks.
Read the full guide →Control 5.22
Review supplier security performance and control material service changes throughout the relationship.
Read the full guide →Control 5.23
Govern cloud selection, use, shared responsibilities, changes and exit according to information-security risk.
Read the full guide →Control 5.24
Prepare roles, playbooks, communication and resources before security incidents occur.
Read the full guide →Control 5.25
Triage reported events consistently and decide whether escalation, response or other handling is required.
Read the full guide →Control 5.26
Coordinate containment, investigation, communication, recovery and accountable decision-making during incidents.
Read the full guide →Control 5.27
Turn incident evidence into improvements to risks, controls, detection and response capability.
Read the full guide →Control 5.28
Preserve reliable evidence when events may require investigation, disciplinary, contractual or legal action.
Read the full guide →Control 5.29
Maintain essential security protections and risk decisions while normal operating arrangements are disrupted.
Read the full guide →Control 5.30
Prepare and test technology recovery capability that supports prioritized business continuity needs.
Read the full guide →Control 5.31
Identify, maintain and translate applicable obligations into owned security and compliance activities.
Read the full guide →Control 5.32
Protect and use intellectual property in accordance with ownership, licence and contractual conditions.
Read the full guide →Control 5.33
Preserve records against loss, alteration, unauthorized access and premature disposal for required retention periods.
Read the full guide →Control 5.34
Apply privacy and personal-information protections that reflect applicable obligations, purposes and risk.
Read the full guide →Control 5.35
Obtain objective review of whether security governance and arrangements remain suitable and effective.
Read the full guide →Control 5.36
Evaluate whether security requirements are followed and address deviations through accountable action.
Read the full guide →Control 5.37
Provide current, usable instructions where consistent security operation depends on repeatable execution.
Read the full guide →Control 6.1
Apply proportionate pre-engagement checks for roles with access to sensitive information, systems or facilities.
Read the full guide →Control 6.2
Embed relevant security responsibilities and expectations into employment or engagement terms.
Read the full guide →Control 6.3
Build role-relevant understanding and capability, then evaluate whether learning changes behaviour and performance.
Read the full guide →Control 6.4
Use a fair, communicated process for addressing deliberate or negligent breaches of security expectations.
Read the full guide →Control 6.5
Manage continuing obligations, access, assets and knowledge when a person changes role or leaves.
Read the full guide →Control 6.6
Use suitable confidentiality commitments that reflect information sensitivity, roles, jurisdictions and relationship lifecycle.
Read the full guide →Control 6.7
Protect information and services when work occurs away from controlled organizational locations.
Read the full guide →Control 6.8
Give personnel simple, trusted routes for promptly reporting suspected events, weaknesses or unusual activity.
Read the full guide →Control 7.1
Define and protect physical boundaries around information, people and supporting assets according to risk.
Read the full guide →Control 7.2
Authorize, record and review entry to controlled areas while managing visitors and access credentials.
Read the full guide →Control 7.3
Apply proportionate protection to workplaces and facilities, including shared and outsourced locations.
Read the full guide →Control 7.4
Detect and review unauthorized or suspicious physical activity using proportionate monitoring and response.
Read the full guide →Control 7.5
Reduce harm from fire, water, temperature, power, civil disruption and other relevant environmental hazards.
Read the full guide →Control 7.6
Set behaviour and supervision expectations for people working within sensitive physical areas.
Read the full guide →Control 7.7
Reduce accidental exposure of sensitive information in offices, shared spaces and remote-work environments.
Read the full guide →Control 7.8
Position and protect equipment against unauthorized access, observation, damage and environmental exposure.
Read the full guide →Control 7.9
Protect devices, media and information when used, transported or stored outside organizational premises.
Read the full guide →Control 7.10
Control removable and other storage media through authorization, handling, transport, reuse and disposal.
Read the full guide →Control 7.11
Protect information-processing facilities from loss or instability of power, cooling, communications and other utilities.
Read the full guide →Control 7.12
Protect power and communications cabling from interception, interference and damage.
Read the full guide →Control 7.13
Maintain equipment safely and reliably while controlling access, information exposure and service records.
Read the full guide →Control 7.14
Remove or protect information before equipment is disposed of, returned, reassigned or reused.
Read the full guide →Control 8.1
Apply managed security baselines and lifecycle controls to endpoints that access organizational information and services.
Read the full guide →Control 8.2
Restrict, approve, monitor and review powerful access separately from routine user access.
Read the full guide →Control 8.3
Enforce access boundaries according to business need, classification and approved authorization rules.
Read the full guide →Control 8.4
Limit and monitor source-code access to protect integrity, confidentiality and controlled change.
Read the full guide →Control 8.5
Use authentication mechanisms and operating practices proportionate to account, system and transaction risk.
Read the full guide →Control 8.6
Monitor and plan capacity so services remain reliable and security controls continue to operate under expected demand.
Read the full guide →Control 8.7
Combine preventive, detective and recovery measures to reduce malware execution and impact.
Read the full guide →Control 8.8
Identify relevant technical vulnerabilities, determine exposure and drive risk-based remediation and exception decisions.
Read the full guide →Control 8.9
Define, deploy and monitor secure configuration baselines across relevant technology.
Read the full guide →Control 8.10
Delete information when authorized and no longer needed, including relevant copies and service-provider locations.
Read the full guide →Control 8.11
Reduce exposure of sensitive data by obscuring values where full detail is unnecessary.
Read the full guide →Control 8.12
Detect and reduce unauthorized movement or disclosure of sensitive information across people, endpoints and services.
Read the full guide →Control 8.13
Create protected, recoverable copies aligned with business recovery and information-retention needs.
Read the full guide →Control 8.14
Use proportionate redundancy to meet service availability and recovery needs.
Read the full guide →Control 8.15
Generate, protect and retain useful event records that support detection, investigation and accountability.
Read the full guide →Control 8.16
Review systems, networks and user activity for anomalies and indicators requiring investigation or response.
Read the full guide →Control 8.17
Maintain consistent time sources so records, alerts and investigations can be correlated reliably.
Read the full guide →Control 8.18
Restrict and monitor powerful utilities that can bypass normal system or application controls.
Read the full guide →Control 8.19
Authorize and control software installation to protect stability, licensing and security baselines.
Read the full guide →Control 8.20
Design, configure and operate networks to protect information flows and connected services.
Read the full guide →Control 8.21
Define and monitor security expectations for network services, whether internal, outsourced or cloud-delivered.
Read the full guide →Control 8.22
Separate networks, users and services where segmentation reduces exposure or limits movement.
Read the full guide →Control 8.23
Reduce exposure to malicious or prohibited web content through risk-based filtering and exception handling.
Read the full guide →Control 8.24
Govern cryptographic use, algorithms, certificates and keys according to information and service risk.
Read the full guide →Control 8.25
Embed security activities, ownership and assurance throughout development and acquisition.
Read the full guide →Control 8.26
Define testable security and privacy requirements before applications are designed, acquired or changed.
Read the full guide →Control 8.27
Apply documented security principles and risk decisions to system architecture and engineering.
Read the full guide →Control 8.28
Use coding standards, developer practices and review techniques that prevent common weaknesses.
Read the full guide →Control 8.29
Test security requirements and risk scenarios before release and after material change.
Read the full guide →Control 8.30
Apply security requirements, oversight and acceptance criteria when development is performed externally.
Read the full guide →Control 8.31
Separate environments and control movement between them to reduce unauthorized change and data exposure.
Read the full guide →Control 8.32
Assess, authorize, test, implement and review technology changes through controlled workflows.
Read the full guide →Control 8.33
Select, protect and remove test information so testing does not create unnecessary exposure.
Read the full guide →Control 8.34
Plan and control audit testing so assurance activity does not disrupt systems or expose sensitive information.
Read the full guide →The free interactive lookup covers all 93 controls and connects related clauses, evidence and implementation prompts.
Open the Annex A Control Lookup →