Free Website Tool

ISO 27001 Annex A Control Lookup

Explore all ISO/IEC 27001 Annex A controls with practical implementation guidance, evidence examples, audit questions and related controls.

Tool summary

Control groups
4
Controls
93
Access
Free
Format
Interactive browser tool

Find a control

Browse all Annex A controls

Search and filtering happen locally in your browser. Suggested actions and evidence should be adapted to your scope, risk and operating environment.

Control 5.1 · Organizational

5.1 — Policies for information security

Practical purpose

Set coherent, approved direction for information security and keep supporting policies aligned with business, risk and compliance needs.

Read the full Control 5.1 implementation guide →

What good implementation looks like

Typical implementation actions include:

  • Define ownership, scope and operating criteria for policies for information security.
  • Implement policy or procedure that fits the organization’s risks, services and working practices.
  • Integrate the activity with relevant change, exception and review processes.
  • Review performance and improve the arrangement when risks, technology or obligations change.

Common evidence

Common evidence may include:

  • approved policy or procedure
  • governance records
  • assigned ownership and approval evidence
  • sample implementation, review and exception records

Questions an auditor may ask

  • How is policies for information security implemented in practice?
  • Who owns the activity and how are decisions approved?
  • Show me a recent example from operation through review.
  • How are exceptions, changes or overdue actions handled?

Common implementation mistakes

  • documenting policies for information security without consistent operation
  • unclear ownership or review frequency
  • evidence that does not cover the full ISMS scope
  • exceptions accepted without risk-based approval or follow-up

Related Annex A controls

Related ISO 27001 clauses

Risk treatment context

How Annex A fits into ISO 27001

Annex A supports risk treatment by providing a reference set against which necessary controls can be checked. Organizations determine the controls they need from their risks and circumstances, compare those decisions with Annex A, and record applicability and implementation positions in the Statement of Applicability.

Build your Statement of Applicability Read Clause 6.1.3 guidance

ISO/IEC 27001 is published by the International Organization for Standardization and the International Electrotechnical Commission. AuditPrepared provides independent implementation guidance.