ISO 27001 Organizational controls
The 37 organizational controls cover policies, roles, supplier and cloud security, incident management, and legal obligations. They are the governance backbone of the ISMS.
Policies for information security
Keep management direction and support for information security current, suitable and effective and aligned with business, legal and contractual needs.
Guidance and how to meet it →Information security roles and responsibilities
Set up a clear, approved and understood structure for running and managing information security across the organisation.
Guidance and how to meet it →Segregation of duties
Lower the risk of fraud, mistakes and circumvention of security controls by splitting conflicting duties.
Guidance and how to meet it →Management responsibilities
Make sure managers understand their part in security and drive their staff to be aware of and meet their security obligations.
Guidance and how to meet it →Contact with authorities
Ensure information flows appropriately between the organisation and relevant legal, regulatory and supervisory authorities.
Guidance and how to meet it →Contact with special interest groups
Support the appropriate flow of security information by maintaining links with specialist groups and forums.
Guidance and how to meet it →Threat intelligence
Build awareness of the organisation's threat environment so suitable mitigations can be chosen.
Guidance and how to meet it →Information security in project management
Make sure security risks tied to projects and their deliverables are handled throughout the project life cycle.
Guidance and how to meet it →Inventory of information and other associated assets
Identify the organisation's information and associated assets so they can be protected and given proper ownership.
Guidance and how to meet it →Acceptable use of information and other associated assets
Ensure information and associated assets are properly protected, used and handled.
Guidance and how to meet it →Return of assets
Protect the organisation's assets when employment, contracts or agreements change or end.
Guidance and how to meet it →Classification of information
Make sure information's protection needs are identified and understood according to its importance.
Guidance and how to meet it →Labelling of information
Make the classification of information clear and support automated information handling.
Guidance and how to meet it →Information transfer
Keep information secure when it is transferred within the organisation and to external parties.
Guidance and how to meet it →Access control
Allow authorised access and prevent unauthorised access to information and associated assets.
Guidance and how to meet it →Identity management
Uniquely identify the people and systems accessing assets so access rights can be assigned correctly.
Guidance and how to meet it →Authentication information
Ensure entities are properly authenticated and prevent failures in authentication processes.
Guidance and how to meet it →Access rights
Ensure access to information and associated assets is defined and authorised according to business needs.
Guidance and how to meet it →Information security in supplier relationships
Maintain an agreed level of security in relationships with suppliers.
Guidance and how to meet it →Addressing information security within supplier agreements
Maintain an agreed level of security by setting and agreeing security requirements with each supplier.
Guidance and how to meet it →Managing information security in the ICT supply chain
Manage the security risks that come with buying and using ICT products and services through a supply chain.
Guidance and how to meet it →Monitoring, review and change management of supplier services
Regularly monitor, review and control changes to the security practices and service delivery of suppliers.
Guidance and how to meet it →Information security for use of cloud services
Establish processes for acquiring, using, managing and exiting cloud services in line with your security requirements.
Guidance and how to meet it →Information security incident management planning and preparation
Plan and prepare for incident management by defining the processes, roles and responsibilities needed to respond.
Guidance and how to meet it →Assessment and decision on information security events
Assess security events and decide whether each one should be classified as a security incident.
Guidance and how to meet it →Response to information security incidents
Respond to security incidents following documented procedures so they are handled efficiently and consistently.
Guidance and how to meet it →Learning from information security incidents
Use knowledge gained from incidents to strengthen controls and reduce the chance or impact of future ones.
Guidance and how to meet it →Collection of evidence
Set up and apply procedures to identify, collect, acquire and preserve evidence relating to security events.
Guidance and how to meet it →Information security during disruption
Plan how to keep information security at an appropriate level throughout periods of disruption.
Guidance and how to meet it →ICT readiness for business continuity
Plan, implement, maintain and test ICT readiness so technology can support business continuity objectives.
Guidance and how to meet it →Legal, statutory, regulatory and contractual requirements
Identify, document and keep current the legal, statutory, regulatory and contractual requirements relevant to information security.
Guidance and how to meet it →Intellectual property rights
Put procedures in place to protect intellectual property rights and ensure compliant use of proprietary products.
Guidance and how to meet it →Protection of records
Protect records from loss, destruction, falsification, unauthorised access and unauthorised release.
Guidance and how to meet it →Privacy and protection of PII
Identify and meet the requirements for preserving privacy and protecting PII under applicable laws, regulations and contracts.
Guidance and how to meet it →Independent review of information security
Have your approach to managing information security reviewed independently at planned intervals and after significant changes.
Guidance and how to meet it →Compliance with policies, rules and standards
Regularly review compliance with your information security policy, topic-specific policies, rules and standards.
Guidance and how to meet it →Documented operating procedures
Document operating procedures for information processing facilities and make them available to the staff who need them.
Guidance and how to meet it →