Auditen
Home / Frameworks / ISO 27001 / Annex A: organizational controls
ISO 27001 · A.5

Annex A: organizational controls

Annex A: Organizational controls require the establishment of a governance framework that manages information security through policies, defined roles, and operational processes. It ensures that security is integrated into the organization's structure rather than treated as a purely technical function.

What it means

These controls focus on the "administrative" side of security. While technological controls (A.8) protect data with software, organizational controls ensure there are rules in place to decide who gets access, how suppliers are managed, and who is accountable when something goes wrong.

In practice, this means moving from ad-hoc decision-making to a documented system. The scope covers everything from the high-level Information Security Policy down to specific registries of assets and the management of third-party cloud services.

The intent is to create consistency. By defining roles and responsibilities, an organization ensures that security tasks are not overlooked and that there is clear ownership for every critical asset and process within the ISMS (Information Security Management System).

How to meet it

Evidence an auditor asks for

  • Approved Information Security Policy (ISP) and supporting sub-policies (e.g., Access Control, Supplier Management).
  • An Asset Register containing descriptions of assets, their classification, and assigned owners.
  • Signed contracts or Service Level Agreements (SLAs) with suppliers that include specific security clauses.
  • Incident logs showing the timeline from detection to resolution, including evidence of "lessons learned" reviews.
  • Job descriptions or appointment letters confirming that individuals understand their assigned security responsibilities.

Common pitfalls

  • Creating "shelfware" policies—documents that are written to satisfy an auditor but are not communicated to staff or followed in daily operations.
  • Maintaining a static asset register that is not updated when new software, hardware, or cloud services are onboarded.
  • Assuming that a signed contract with a vendor equals security; auditors look for evidence of ongoing monitoring and periodic risk reviews of those vendors.
  • Vague role definitions where security tasks are assigned to "the IT team" generally rather than specific roles or individuals.