Control 5.1
Policies for information security
Set coherent, approved direction for information security and keep supporting policies aligned with business, risk and compliance needs.
Read the full guide →Annex A category 5
Governance, suppliers, incidents, continuity and business-facing security processes. Use this category page to understand the control family and move into detailed implementation guides.
Organizational controls provide a structured reference for risk treatment. Applicability follows the organization’s risks, obligations, scope and chosen treatment. Record decisions in the Statement of Applicability and test selected controls in operation.
Use these guides to move from category-level planning into control-specific implementation, evidence and audit testing. The interactive lookup remains available for quick cross-control reference.
Control 5.1
Set coherent, approved direction for information security and keep supporting policies aligned with business, risk and compliance needs.
Read the full guide →Control 5.2
Allocate clear accountability and authority for security decisions and recurring activities.
Read the full guide →Control 5.3
Reduce opportunities for error, misuse or concealment by separating incompatible responsibilities or applying compensating oversight.
Read the full guide →Control 5.4
Ensure managers actively reinforce security expectations within the teams and processes they direct.
Read the full guide →Control 5.5
Maintain usable routes for regulatory, law-enforcement and emergency contact when events or obligations require coordination.
Read the full guide →Control 5.6
Use trusted professional and industry communities to stay informed about relevant security developments and good practice.
Read the full guide →Control 5.7
Collect and evaluate relevant threat information so risk, monitoring and protective decisions reflect the current environment.
Read the full guide →Control 5.8
Integrate security risk and control decisions into project governance from initiation through delivery and closure.
Read the full guide →Control 5.9
Maintain a reliable view of information and supporting assets that need protection, including clear ownership and lifecycle accountability.
Read the full guide →Control 5.10
Set practical expectations for how people may use and protect information, devices, services and facilities.
Read the full guide →Control 5.11
Recover organizational assets and information when roles, contracts or relationships change or end.
Read the full guide →Control 5.12
Apply consistent sensitivity and handling decisions to information based on business value, obligations and impact.
Read the full guide →Control 5.13
Communicate classification or handling needs in a usable form so people and systems can apply the right protections.
Read the full guide →Control 5.14
Protect information while it is shared internally or externally through approved channels and accountable arrangements.
Read the full guide →Control 5.15
Set risk-based principles for granting, using, reviewing and removing physical and logical access.
Read the full guide →Control 5.16
Manage identities consistently across creation, verification, change, suspension and removal.
Read the full guide →Control 5.17
Issue, protect, reset and retire credentials and authentication secrets through controlled processes.
Read the full guide →Control 5.18
Approve, provision, review and remove access rights according to role, need and changing employment or supplier status.
Read the full guide →Control 5.19
Identify and manage security risk arising from suppliers and the services, information or systems they support.
Read the full guide →Control 5.20
Translate supplier risk and service expectations into clear, enforceable security terms and responsibilities.
Read the full guide →Control 5.21
Extend supplier assurance to relevant technology dependencies, subcontractors, components and lifecycle risks.
Read the full guide →Control 5.22
Review supplier security performance and control material service changes throughout the relationship.
Read the full guide →Control 5.23
Govern cloud selection, use, shared responsibilities, changes and exit according to information-security risk.
Read the full guide →Control 5.24
Prepare roles, playbooks, communication and resources before security incidents occur.
Read the full guide →Control 5.25
Triage reported events consistently and decide whether escalation, response or other handling is required.
Read the full guide →Control 5.26
Coordinate containment, investigation, communication, recovery and accountable decision-making during incidents.
Read the full guide →Control 5.27
Turn incident evidence into improvements to risks, controls, detection and response capability.
Read the full guide →Control 5.28
Preserve reliable evidence when events may require investigation, disciplinary, contractual or legal action.
Read the full guide →Control 5.29
Maintain essential security protections and risk decisions while normal operating arrangements are disrupted.
Read the full guide →Control 5.30
Prepare and test technology recovery capability that supports prioritized business continuity needs.
Read the full guide →Control 5.31
Identify, maintain and translate applicable obligations into owned security and compliance activities.
Read the full guide →Control 5.32
Protect and use intellectual property in accordance with ownership, licence and contractual conditions.
Read the full guide →Control 5.33
Preserve records against loss, alteration, unauthorized access and premature disposal for required retention periods.
Read the full guide →Control 5.34
Apply privacy and personal-information protections that reflect applicable obligations, purposes and risk.
Read the full guide →Control 5.35
Obtain objective review of whether security governance and arrangements remain suitable and effective.
Read the full guide →Control 5.36
Evaluate whether security requirements are followed and address deviations through accountable action.
Read the full guide →Control 5.37
Provide current, usable instructions where consistent security operation depends on repeatable execution.
Read the full guide →Browse the complete category. Each control opens a dedicated implementation guide and remains available in the free interactive lookup.
Control 5.1
Control 5.2
Control 5.3
Control 5.4
Control 5.5
Control 5.6
Control 5.7
Control 5.8
Control 5.9
Control 5.10
Control 5.11
Control 5.12
Control 5.13
Control 5.14
Control 5.15
Control 5.16
Control 5.17
Control 5.18
Control 5.19
Control 5.20
Control 5.21
Control 5.22
Control 5.23
Control 5.24
Control 5.25
Control 5.26
Control 5.27
Control 5.28
Control 5.29
Control 5.30
Control 5.31
Control 5.32
Control 5.33
Control 5.34
Control 5.35
Control 5.36
Control 5.37