Organisational Controls in ISO 27001
The Essential Measures for Information Security

The Essential Measures for Information Security

Information security is essential for businesses in today's rapidly evolving digital landscape. Cybercrime is on the rise, and UK businesses suffered an estimated 2.39 million cybercrime incidents and 49,000 fraud incidents in the past year. This has resulted in enormous financial losses and reputational damage.
ISO 27001 controls are the essential guide to information security. They provide a framework for organizations to develop, implement, monitor and improve their information security management system (ISMS). ISO 27001 controls are categorized into 14 domains, covering all aspects of information security, from physical and environmental security to access control and incident management.
The ISO 27001 controls were recategorized in 2022 to reflect the current information security landscape. The new categorization also includes organizational measures.
ISO 27001:2022 Annex A defines 93 controls organizations can implement to improve their information security. These controls are divided into four categories:
The four categories facilitate the planning and implementation of reference measures and the selection of the right controls. In 2022, the categories were restructured to reflect current security requirements. The core processes of ISMS management remain the same, but the controls in Annex A have been updated to reflect more modern risks and associated measures.
Organizational controls are measures that help organizations protect their information assets by establishing a culture of security and defining clear roles and responsibilities. They are not targeted at specific personnel, or physical or technological threats, but rather at the organization as a whole.
Organizational controls include:
Organizational controls provide a framework for the basic handling of information assets. They can be used to:

ISO 27001:2022 includes several new organizational controls that respond to today's increasingly complex information security challenges. These include:
A comprehensive list of organizational controls from Annex A of ISO 27001
To build a functioning information security management system, organizations need to know what controls best apply to them. Here is a comprehensive overview of all organizational controls from Annex A of ISO 27001:
|
Organizational Controls |
Annex A 5.1 |
Policies for Information Security |
|
Organizational Controls |
Annex A 5.2 |
Information Security Roles and Responsibilities |
|
Organizational Controls |
Annex A 5.3 |
Segregation of Duties |
|
Organizational Controls |
Annex A 5.4 |
Management Responsibilities |
|
Organizational Controls |
Annex A 5.5 |
Contact with Authorities |
|
Organizational Controls |
Annex A 5.6 |
Contact with Special Interest Groups |
|
Organizational Controls |
Annex A 5.7 |
Threat Intelligence |
|
Organizational Controls |
Annex A 5.8 |
Information Security in Project Management |
|
Organizational Controls |
Annex A 5.9 |
Inventory of Information and Other Associated Assets |
|
Organizational Controls |
Annex A 5.10 |
Acceptable Use of Information and Other Associated Assets |
|
Organizational Controls |
Annex A 5.11 |
Return of Assets |
|
Organizational Controls |
Annex A 5.12 |
Classification of Information |
|
Organizational Controls |
Annex A 5.13 |
Labelling of Information |
|
Organizational Controls |
Annex A 5.14 |
Information Transfer |
|
Organizational Controls |
Annex A 5.15 |
Access Control |
|
Organizational Controls |
Annex A 5.16 |
Identity Management |
|
Organizational Controls |
Annex A 5.17 |
Authentication Information |
|
Organizational Controls |
Annex A 5.18 |
Access Rights |
|
Organizational Controls |
Annex A 5.19 |
Information Security in Supplier Relationships |
|
Organizational Controls |
Annex A 5.20 |
Addressing Information Security within Supplier Agreements |
|
Organizational Controls |
Annex A 5.21 |
Managing Information Security in the ICT Supply Chain |
|
Organizational Controls |
Annex A 5.22 |
Monitoring, Review and Change Management of Supplier Services |
|
Organizational Controls |
Annex A 5.23 |
Information Security for Use of Cloud Services |
|
Organizational Controls |
Annex A 5.24 |
Information Security Incident Management Planning and Preparation |
|
Organizational Controls |
Annex A 5.25 |
Assessment and Decision on Information Security Events |
|
Organizational Controls |
Annex A 5.26 |
Response to Information Security Incidents |
|
Organizational Controls |
Annex A 5.27 |
Learning From Information Security Incidents |
|
Organizational Controls |
Annex A 5.28 |
Collection of Evidence |
|
Organizational Controls |
Annex A 5.29 |
Information Security During Disruption |
|
Organizational Controls |
Annex A 5.30 |
ICT Readiness for Business Continuity |
|
Organizational Controls |
Annex A 5.31 |
Legal, Statutory, Regulatory and Contractual Requirements |
|
Organizational Controls |
Annex A 5.32 |
Intellectual Property Rights |
|
Organizational Controls |
Annex A 5.33 |
Protection of Records |
|
Organizational Controls |
Annex A 5.34 |
Privacy and Protection of PII |
|
Organizational Controls |
Annex A 5.35 |
Independent Review of Information Security |
|
Organizational Controls |
Annex A 5.36 |
Compliance With Policies, Rules and Standards for Information Security |
|
Organizational Controls |
Annex A 5.37 |
Documented Operating Procedures |
You've got an overview of controls—now you need to select the right controls and implement them. This is a process that can be broken down into several steps:
Tips for implementing organizational controls:
Organizational controls play a vital role in building an ISMS by safeguarding information. They help organizations fundamentally improve their information security and protect themselves against cyber-attacks.
The new organizational controls in ISO 27001:2022 take into account today's information security challenges and provide additional opportunities for organizations to improve their information security.
A comprehensive overview of organizational controls facilitates and structures the selection of the right measures and helps to take into account the context of your organization.
Find the right controls and use our ISO 27001 checklist to find out what you need to do to comply with ISO 27001.
Organizational controls define how information security is governed and managed at an organizational level. They cover areas such as policies, roles and responsibilities, risk management, supplier relationships, and incident handling. These controls ensure that information security is embedded into business processes rather than treated as a purely technical issue.
TISAX® is a registered trademark of the ENX Association. DataGuard is not affiliated with the ENX Association. We provide Software-as-a-Service and support for the assessment on TISAX® only. The ENX Association does not take any responsibility for any content shown on DataGuard's website.
All data provided is for information only, based on internal estimates. This information is not indicative of KPIs, and is not given with any warranties or guarantees, expressly stated or implied in relation to accuracy and reliability.
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "Organization",
"@id": "www.dataguard.com#organization",
"name": "DataGuard",
"legalName": "DataCo GmbH",
"description": "DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. We help you identify and manage your security and compliance risks and fast-track your certifications and compliance by combining expert consultancy with AI-powered automation. Our purpose-built, all-in-one platform is developed with the experience of over 1.5 million total hours by a team of certified security and compliance experts.",
"foundingDate": "2018",
"taxID": "DE315880213",
"logo": "https://7759810.fs1.hubspotusercontent-na1.net/hubfs/7759810/DataGuardLogo.svg",
"url": "www.dataguard.com",
"email": "info@dataguard.de",
"telephone": "+49 89 452459 900",
"address": {
"@type": "PostalAddress",
"streetAddress": "Sandstrasse 33",
"addressLocality": "Munich",
"addressRegion": "Bavaria",
"postalCode": "80335",
"addressCountry": "Germany"
},
"sameAs": [
"https://www.linkedin.com/company/dataguard1/",
"https://www.youtube.com/channel/UCEQzPZ6sCBCj9cAoBvaLL6w",
"https://x.com/i/flow/login?redirect_after_login=%2FDataGuard_dg"
]
}
]
}✅ Organization schema markup for "DataGuard" has been injected into the document head.