ISO 27001 Annex A Organizational Controls: 5.1 to 5.37 Explained
ISO 27001:2022 groups 37 controls under the Organizational theme, more than any of the other three themes (People has 8, Physical has 14, Technological has 34). They cover policy, governance, asset handling, access, suppliers, incidents, and compliance, which is why they sit first in Annex A: almost every other control depends on one of these being in place.
Quick answer. ISO 27001:2022 Annex A has 37 organizational controls, numbered 5.1 to 5.37. They cover policy and governance, asset and information handling, access and identity, supplier and cloud relationships, incident management and continuity, and compliance. Auditors spend the most time on access control (5.15-5.18) and supplier relationships (5.19-5.23), since both touch every in-scope system.
Rather than list all 37 in one flat table, here they are grouped into six areas that reflect how the work actually gets done. This groups by what a startup builds, not by the standard's own internal numbering.
Policy and Governance (5.1-5.8)
- 5.1 Policies for information security
- 5.2 Information security roles and responsibilities
- 5.3 Segregation of duties
- 5.4 Management responsibilities
- 5.5 Contact with authorities
- 5.6 Contact with special interest groups
- 5.7 Threat intelligence
- 5.8 Information security in project management
What auditors look for: a security policy that is actually approved by named leadership (not a template no one signed), a documented list of who has authority over what, and evidence that security requirements get added to new projects at kickoff rather than bolted on before launch. 5.7, threat intelligence, is new in 2022. For most startups this can be as simple as a documented subscription to a vendor advisory feed or a CISA/vendor mailing list, reviewed on a set cadence.
Asset and Information Handling (5.9-5.14)
- 5.9 Inventory of information and other associated assets
- 5.10 Acceptable use of information and other associated assets
- 5.11 Return of assets
- 5.12 Classification of information
- 5.13 Labelling of information
- 5.14 Information transfer
What auditors look for: a current asset inventory (not a spreadsheet last touched at kickoff), a documented classification scheme (even a simple public/internal/confidential/restricted scale), and an offboarding step that confirms company assets and access are returned or revoked. Auditors will pull a sample of recent leavers and check the return-of-assets record.
Access and Identity (5.15-5.18)
- 5.15 Access control
- 5.16 Identity management
- 5.17 Authentication information
- 5.18 Access rights
Common gap
Common gap: these four controls describe policy, and A.8.2 through A.8.5 in the Technological theme describe the implementation. Startups often write the policy once and never revisit it as the team grows past its first identity provider migration, leaving the documented policy out of sync with what MFA and SSO actually enforce.
What auditors look for: a documented access control policy that matches your actual identity provider configuration, evidence of periodic access reviews, and a clear process for how authentication credentials (passwords, keys, tokens) are issued and rotated.
Supplier and Cloud Relationships (5.19-5.23)
- 5.19 Information security in supplier relationships
- 5.20 Addressing information security within supplier agreements
- 5.21 Managing information security in the ICT supply chain
- 5.22 Monitoring, review and change management of supplier services
- 5.23 Information security for use of cloud services
What auditors look for: a documented vendor risk assessment process applied before onboarding a new supplier, security clauses in vendor contracts (or at minimum, reliance on the vendor's own SOC 2 or ISO 27001 report), and a periodic review of critical suppliers rather than a one-time check at signup. 5.23, cloud services, is new in 2022 and expects a documented process for evaluating a cloud provider's security commitments before you build on it, which for most SaaS startups means your AWS, GCP, or Azure shared-responsibility review.
Incident Management and Continuity (5.24-5.30)
- 5.24 Information security incident management planning and preparation
- 5.25 Assessment and decision on information security events
- 5.26 Response to information security incidents
- 5.27 Learning from information security incidents
- 5.28 Collection of evidence
- 5.29 Information security during disruption
- 5.30 ICT readiness for business continuity
What auditors look for: a documented incident response plan with defined severity levels and escalation paths, a log of security events (even a zero-incident log is valid evidence for 5.24-5.27), and a business continuity plan that specifically addresses how information security controls hold up during a disruption, not just how the business keeps operating. 5.30 is a 2022 addition and is often the weakest control in a first-time SoA: it expects you to have thought through what happens to encryption, access control, and logging if your primary infrastructure fails over.
Compliance and Legal (5.31-5.37)
- 5.31 Legal, statutory, regulatory and contractual requirements
- 5.32 Intellectual property rights
- 5.33 Protection of records
- 5.34 Privacy and protection of PII
- 5.35 Independent review of information security
- 5.36 Compliance with policies, rules and standards for information security
- 5.37 Documented operating procedures
What auditors look for: a maintained register of applicable legal and contractual security requirements (GDPR, sector-specific rules, customer contract clauses), evidence of an independent review of the ISMS (this can be the internal audit, provided the reviewer is independent of the area reviewed), and documented operating procedures for repeatable security tasks like access provisioning or backup verification, not just tribal knowledge.
How This Maps to the Statement of Applicability
Every one of these 37 controls needs a line in your Statement of Applicability: applicable or not, and why. For most SaaS startups, the organizational controls are close to fully applicable, the common exclusions sit in 5.6 (special interest groups, if you have no formal threat-intel relationship yet) and parts of 5.19-5.22 if you genuinely run no third-party suppliers with access to in-scope data, which is rare.
Mapping these 37 controls against your real vendor contracts, incident logs, and access reviews is ongoing work, not a one-time exercise before the audit. A fractional CISO keeps that mapping current instead of reconstructing it under deadline. See pricing or book a call.