A.5 · 37 controls

ISO 27001 Organizational controls

The 37 organizational controls cover policies, roles, supplier and cloud security, incident management, and legal obligations. They are the governance backbone of the ISMS.

A.5.1

Policies for information security

Keep management direction and support for information security current, suitable and effective and aligned with business, legal and contractual needs.

Guidance and how to meet it →
A.5.2

Information security roles and responsibilities

Set up a clear, approved and understood structure for running and managing information security across the organisation.

Guidance and how to meet it →
A.5.3

Segregation of duties

Lower the risk of fraud, mistakes and circumvention of security controls by splitting conflicting duties.

Guidance and how to meet it →
A.5.4

Management responsibilities

Make sure managers understand their part in security and drive their staff to be aware of and meet their security obligations.

Guidance and how to meet it →
A.5.5

Contact with authorities

Ensure information flows appropriately between the organisation and relevant legal, regulatory and supervisory authorities.

Guidance and how to meet it →
A.5.6

Contact with special interest groups

Support the appropriate flow of security information by maintaining links with specialist groups and forums.

Guidance and how to meet it →
A.5.7New

Threat intelligence

Build awareness of the organisation's threat environment so suitable mitigations can be chosen.

Guidance and how to meet it →
A.5.8

Information security in project management

Make sure security risks tied to projects and their deliverables are handled throughout the project life cycle.

Guidance and how to meet it →
A.5.9

Inventory of information and other associated assets

Identify the organisation's information and associated assets so they can be protected and given proper ownership.

Guidance and how to meet it →
A.5.10

Acceptable use of information and other associated assets

Ensure information and associated assets are properly protected, used and handled.

Guidance and how to meet it →
A.5.11

Return of assets

Protect the organisation's assets when employment, contracts or agreements change or end.

Guidance and how to meet it →
A.5.12

Classification of information

Make sure information's protection needs are identified and understood according to its importance.

Guidance and how to meet it →
A.5.13

Labelling of information

Make the classification of information clear and support automated information handling.

Guidance and how to meet it →
A.5.14

Information transfer

Keep information secure when it is transferred within the organisation and to external parties.

Guidance and how to meet it →
A.5.15

Access control

Allow authorised access and prevent unauthorised access to information and associated assets.

Guidance and how to meet it →
A.5.16

Identity management

Uniquely identify the people and systems accessing assets so access rights can be assigned correctly.

Guidance and how to meet it →
A.5.17

Authentication information

Ensure entities are properly authenticated and prevent failures in authentication processes.

Guidance and how to meet it →
A.5.18

Access rights

Ensure access to information and associated assets is defined and authorised according to business needs.

Guidance and how to meet it →
A.5.19

Information security in supplier relationships

Maintain an agreed level of security in relationships with suppliers.

Guidance and how to meet it →
A.5.20

Addressing information security within supplier agreements

Maintain an agreed level of security by setting and agreeing security requirements with each supplier.

Guidance and how to meet it →
A.5.21

Managing information security in the ICT supply chain

Manage the security risks that come with buying and using ICT products and services through a supply chain.

Guidance and how to meet it →
A.5.22

Monitoring, review and change management of supplier services

Regularly monitor, review and control changes to the security practices and service delivery of suppliers.

Guidance and how to meet it →
A.5.23New

Information security for use of cloud services

Establish processes for acquiring, using, managing and exiting cloud services in line with your security requirements.

Guidance and how to meet it →
A.5.24

Information security incident management planning and preparation

Plan and prepare for incident management by defining the processes, roles and responsibilities needed to respond.

Guidance and how to meet it →
A.5.25

Assessment and decision on information security events

Assess security events and decide whether each one should be classified as a security incident.

Guidance and how to meet it →
A.5.26

Response to information security incidents

Respond to security incidents following documented procedures so they are handled efficiently and consistently.

Guidance and how to meet it →
A.5.27

Learning from information security incidents

Use knowledge gained from incidents to strengthen controls and reduce the chance or impact of future ones.

Guidance and how to meet it →
A.5.28

Collection of evidence

Set up and apply procedures to identify, collect, acquire and preserve evidence relating to security events.

Guidance and how to meet it →
A.5.29

Information security during disruption

Plan how to keep information security at an appropriate level throughout periods of disruption.

Guidance and how to meet it →
A.5.30New

ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness so technology can support business continuity objectives.

Guidance and how to meet it →
A.5.31

Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal, statutory, regulatory and contractual requirements relevant to information security.

Guidance and how to meet it →
A.5.32

Intellectual property rights

Put procedures in place to protect intellectual property rights and ensure compliant use of proprietary products.

Guidance and how to meet it →
A.5.33

Protection of records

Protect records from loss, destruction, falsification, unauthorised access and unauthorised release.

Guidance and how to meet it →
A.5.34

Privacy and protection of PII

Identify and meet the requirements for preserving privacy and protecting PII under applicable laws, regulations and contracts.

Guidance and how to meet it →
A.5.35

Independent review of information security

Have your approach to managing information security reviewed independently at planned intervals and after significant changes.

Guidance and how to meet it →
A.5.36

Compliance with policies, rules and standards

Regularly review compliance with your information security policy, topic-specific policies, rules and standards.

Guidance and how to meet it →
A.5.37

Documented operating procedures

Document operating procedures for information processing facilities and make them available to the staff who need them.

Guidance and how to meet it →