We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ISO/IEC 27001:2022 · Annex A theme 1 of 4 · 37 controls

Annex A.5: Organizational Controls

The largest theme — 37 controls covering policy, roles, supplier risk, cloud, incident management and legal compliance. This is where the 2022 revision added the controls auditors now probe hardest: threat intelligence, cloud service security and ICT readiness for business continuity.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series

The controls that decide your audit

A.5.1
Policies for information security

A policy set approved by management, published, reviewed at planned intervals — the artefact every other control hangs from.

A.5.7
Threat intelligence (new 2022)

Information about threats collected and analysed to produce actionable intelligence — feeds, advisories (e.g. CERT-In), and evidence it changed a decision.

A.5.19–5.22
Supplier relationships

Security in supplier agreements, managing supplier service delivery, and monitoring/review/change management across the supply chain.

A.5.23
Cloud services security (new 2022)

Processes for acquiring, using, managing and exiting cloud services — selection criteria, shared-responsibility mapping, exit strategy.

A.5.24–5.28
Incident management

Planning, assessment, response, learning and evidence collection for information security incidents.

A.5.30
ICT readiness for business continuity (new 2022)

ICT continuity planned, implemented and TESTED against BC objectives — the control that links the ISMS to real DR exercises.

A.5.31–5.36
Legal, IP, records, privacy, reviews

Identifying legal/regulatory requirements (DPDP for Indian entities), protecting records and PII, and independent review of the ISMS.

Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.

Where audits actually fail

Threat intelligence = a subscribed newsletter

A.5.7 evidence must show intelligence being assessed and acted on — a risk-register update, a rule change, a patch decision — not an unread inbox folder.

Cloud inventory that ends at "we use AWS"

A.5.23 expects per-service governance: which cloud services, what data, who owns the relationship, shared-responsibility matrix, exit plan.

Supplier list without security clauses

Contracts sampled by auditors routinely predate the ISMS and carry no security, breach-notification or audit-rights language (A.5.20).

Incident process that has never fired

Zero recorded incidents in a year reads as "not detecting", not "secure". Near-misses and lessons-learned records prove A.5.26/5.27 operate.

Evidence an auditor accepts

  • Approved policy set with review history and communication records
  • Threat-intel workflow samples: source → assessment → action taken (A.5.7)
  • Supplier register with security clauses, assessments and review records
  • Cloud service register with shared-responsibility and exit documentation (A.5.23)
  • Incident log incl. near-misses, post-incident reviews, evidence-handling procedure
  • ICT continuity test records mapped to BC objectives (A.5.30)

Annex A.5 FAQ

How many controls are in Annex A of ISO 27001:2022?

93 controls in four themes: A.5 Organizational (37), A.6 People (8), A.7 Physical (14), A.8 Technological (34) — down from 114 controls in 14 domains under the 2013 edition, with 11 new controls added.

Do we have to implement all 37 organizational controls?

You must consider all of them: Annex A is a reference set filtered through your risk assessment, and every exclusion needs justification in the Statement of Applicability.

What does an auditor accept as threat-intelligence evidence?

Defined sources, someone accountable for triage, and traceable outcomes — an advisory that led to an emergency patch, a rule update or a risk-register entry. Subscription alone fails A.5.7.

People (A.6)

Annex A.5 in your ISMS

We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.