Annex A category 5

ISO 27001 Organizational controls

Governance, suppliers, incidents, continuity and business-facing security processes. Use this category page to understand the control family and move into detailed implementation guides.

How this category supports the ISMS

Organizational controls provide a structured reference for risk treatment. Applicability follows the organization’s risks, obligations, scope and chosen treatment. Record decisions in the Statement of Applicability and test selected controls in operation.

Use these guides to move from category-level planning into control-specific implementation, evidence and audit testing. The interactive lookup remains available for quick cross-control reference.

Published organizational control guides

Control 5.1

Policies for information security

Set coherent, approved direction for information security and keep supporting policies aligned with business, risk and compliance needs.

Read the full guide →

Control 5.2

Information security roles and responsibilities

Allocate clear accountability and authority for security decisions and recurring activities.

Read the full guide →

Control 5.3

Segregation of duties

Reduce opportunities for error, misuse or concealment by separating incompatible responsibilities or applying compensating oversight.

Read the full guide →

Control 5.4

Management responsibilities

Ensure managers actively reinforce security expectations within the teams and processes they direct.

Read the full guide →

Control 5.5

Contact with authorities

Maintain usable routes for regulatory, law-enforcement and emergency contact when events or obligations require coordination.

Read the full guide →

Control 5.6

Contact with special interest groups

Use trusted professional and industry communities to stay informed about relevant security developments and good practice.

Read the full guide →

Control 5.7

Threat intelligence

Collect and evaluate relevant threat information so risk, monitoring and protective decisions reflect the current environment.

Read the full guide →

Control 5.8

Information security in project management

Integrate security risk and control decisions into project governance from initiation through delivery and closure.

Read the full guide →

Control 5.9

Inventory of information and other associated assets

Maintain a reliable view of information and supporting assets that need protection, including clear ownership and lifecycle accountability.

Read the full guide →

Control 5.10

Acceptable use of information and other associated assets

Set practical expectations for how people may use and protect information, devices, services and facilities.

Read the full guide →

Control 5.11

Return of assets

Recover organizational assets and information when roles, contracts or relationships change or end.

Read the full guide →

Control 5.12

Classification of information

Apply consistent sensitivity and handling decisions to information based on business value, obligations and impact.

Read the full guide →

Control 5.13

Labelling of information

Communicate classification or handling needs in a usable form so people and systems can apply the right protections.

Read the full guide →

Control 5.14

Information transfer

Protect information while it is shared internally or externally through approved channels and accountable arrangements.

Read the full guide →

Control 5.15

Access control

Set risk-based principles for granting, using, reviewing and removing physical and logical access.

Read the full guide →

Control 5.16

Identity management

Manage identities consistently across creation, verification, change, suspension and removal.

Read the full guide →

Control 5.17

Authentication information

Issue, protect, reset and retire credentials and authentication secrets through controlled processes.

Read the full guide →

Control 5.18

Access rights

Approve, provision, review and remove access rights according to role, need and changing employment or supplier status.

Read the full guide →

Control 5.19

Information security in supplier relationships

Identify and manage security risk arising from suppliers and the services, information or systems they support.

Read the full guide →

Control 5.20

Addressing information security within supplier agreements

Translate supplier risk and service expectations into clear, enforceable security terms and responsibilities.

Read the full guide →

Control 5.21

Managing information security in the ICT supply chain

Extend supplier assurance to relevant technology dependencies, subcontractors, components and lifecycle risks.

Read the full guide →

Control 5.22

Monitoring, review and change management of supplier services

Review supplier security performance and control material service changes throughout the relationship.

Read the full guide →

Control 5.23

Information security for use of cloud services

Govern cloud selection, use, shared responsibilities, changes and exit according to information-security risk.

Read the full guide →

Control 5.24

Information security incident management planning and preparation

Prepare roles, playbooks, communication and resources before security incidents occur.

Read the full guide →

Control 5.25

Assessment and decision on information security events

Triage reported events consistently and decide whether escalation, response or other handling is required.

Read the full guide →

Control 5.26

Response to information security incidents

Coordinate containment, investigation, communication, recovery and accountable decision-making during incidents.

Read the full guide →

Control 5.27

Learning from information security incidents

Turn incident evidence into improvements to risks, controls, detection and response capability.

Read the full guide →

Control 5.28

Collection of evidence

Preserve reliable evidence when events may require investigation, disciplinary, contractual or legal action.

Read the full guide →

Control 5.29

Information security during disruption

Maintain essential security protections and risk decisions while normal operating arrangements are disrupted.

Read the full guide →

Control 5.30

ICT readiness for business continuity

Prepare and test technology recovery capability that supports prioritized business continuity needs.

Read the full guide →

Control 5.31

Legal, statutory, regulatory and contractual requirements

Identify, maintain and translate applicable obligations into owned security and compliance activities.

Read the full guide →

Control 5.32

Intellectual property rights

Protect and use intellectual property in accordance with ownership, licence and contractual conditions.

Read the full guide →

Control 5.33

Protection of records

Preserve records against loss, alteration, unauthorized access and premature disposal for required retention periods.

Read the full guide →

Control 5.34

Privacy and protection of PII

Apply privacy and personal-information protections that reflect applicable obligations, purposes and risk.

Read the full guide →

Control 5.35

Independent review of information security

Obtain objective review of whether security governance and arrangements remain suitable and effective.

Read the full guide →

Control 5.36

Compliance with policies, rules and standards for information security

Evaluate whether security requirements are followed and address deviations through accountable action.

Read the full guide →

Control 5.37

Documented operating procedures

Provide current, usable instructions where consistent security operation depends on repeatable execution.

Read the full guide →

All organizational controls

Browse the complete category. Each control opens a dedicated implementation guide and remains available in the free interactive lookup.