ISO/IEC 27001:2022 Annex A · 37 controls
Organizational controls
The controls about how the company runs itself: the policies it sets, who is responsible for what, how it handles suppliers and incidents, and how it keeps operating when something goes wrong. This is the largest of the four groups and the one an auditor opens first, because it is where the management system meets the business.
- A.5.1Written security policies, approved and kept current
- A.5.2Who is accountable for what in security
- A.5.3Splitting sensitive tasks between different people
- A.5.4What leadership must require of everyone
- A.5.5Knowing who to contact at the authorities
- A.5.6Staying connected to security communities
- A.5.7Gathering and acting on threat information
- A.5.8Building security into every project
- A.5.9Knowing what information and equipment you hold
- A.5.10Rules for using company information and devices
- A.5.11Getting equipment and data back when people leave
- A.5.12Grading information by how sensitive it is
- A.5.13Marking information with its sensitivity
- A.5.14Sending information safely, inside and out
- A.5.15Deciding who may reach which systems and data
- A.5.16Managing accounts and identities over their life
- A.5.17Handling passwords, keys and other secrets
- A.5.18Granting, reviewing and revoking permissions
- A.5.19Managing the risk that suppliers bring
- A.5.20Putting security terms into supplier contracts
- A.5.21Security through the technology supply chain
- A.5.22Keeping watch on suppliers as they change
- A.5.23Using cloud services safely
- A.5.24Being ready before an incident happens
- A.5.25Judging which events are real incidents
- A.5.26Acting on an incident once it is declared
- A.5.27Learning from incidents afterwards
- A.5.28Preserving evidence after an incident
- A.5.29Holding security together during a crisis
- A.5.30Keeping technology running through disruption
- A.5.31Knowing the laws and contracts that bind you
- A.5.32Respecting copyright and software licensing
- A.5.33Keeping records safe for as long as required
- A.5.34Protecting personal data
- A.5.35Having security checked by someone independent
- A.5.36Checking your own rules are actually followed
- A.5.37Writing down how things are actually done
Every control here needs an applicability decision and a justification in your Statement of Applicability, including the ones you exclude. What certification costs, and which clauses StandardOS covers.
Decide all 37 in one pass
StandardOS pre-fills applicability and a draft justification for every Annex A control from a seven-question profile, keeps each draft marked as unreviewed until you have made it yours, and tracks implementation against each one.