2026-09-29 · 5 min read

ISO 27001 Annex A Organizational Controls: 5.1 to 5.37 Explained

ISO 27001:2022 groups 37 controls under the Organizational theme, more than any of the other three themes (People has 8, Physical has 14, Technological has 34). They cover policy, governance, asset handling, access, suppliers, incidents, and compliance, which is why they sit first in Annex A: almost every other control depends on one of these being in place.

Quick answer. ISO 27001:2022 Annex A has 37 organizational controls, numbered 5.1 to 5.37. They cover policy and governance, asset and information handling, access and identity, supplier and cloud relationships, incident management and continuity, and compliance. Auditors spend the most time on access control (5.15-5.18) and supplier relationships (5.19-5.23), since both touch every in-scope system.

Rather than list all 37 in one flat table, here they are grouped into six areas that reflect how the work actually gets done. This groups by what a startup builds, not by the standard's own internal numbering.

Policy and Governance (5.1-5.8)

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.3 Segregation of duties
  • 5.4 Management responsibilities
  • 5.5 Contact with authorities
  • 5.6 Contact with special interest groups
  • 5.7 Threat intelligence
  • 5.8 Information security in project management

What auditors look for: a security policy that is actually approved by named leadership (not a template no one signed), a documented list of who has authority over what, and evidence that security requirements get added to new projects at kickoff rather than bolted on before launch. 5.7, threat intelligence, is new in 2022. For most startups this can be as simple as a documented subscription to a vendor advisory feed or a CISA/vendor mailing list, reviewed on a set cadence.

Asset and Information Handling (5.9-5.14)

  • 5.9 Inventory of information and other associated assets
  • 5.10 Acceptable use of information and other associated assets
  • 5.11 Return of assets
  • 5.12 Classification of information
  • 5.13 Labelling of information
  • 5.14 Information transfer

What auditors look for: a current asset inventory (not a spreadsheet last touched at kickoff), a documented classification scheme (even a simple public/internal/confidential/restricted scale), and an offboarding step that confirms company assets and access are returned or revoked. Auditors will pull a sample of recent leavers and check the return-of-assets record.

Access and Identity (5.15-5.18)

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights

Common gap

Common gap: these four controls describe policy, and A.8.2 through A.8.5 in the Technological theme describe the implementation. Startups often write the policy once and never revisit it as the team grows past its first identity provider migration, leaving the documented policy out of sync with what MFA and SSO actually enforce.

What auditors look for: a documented access control policy that matches your actual identity provider configuration, evidence of periodic access reviews, and a clear process for how authentication credentials (passwords, keys, tokens) are issued and rotated.

Supplier and Cloud Relationships (5.19-5.23)

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services

What auditors look for: a documented vendor risk assessment process applied before onboarding a new supplier, security clauses in vendor contracts (or at minimum, reliance on the vendor's own SOC 2 or ISO 27001 report), and a periodic review of critical suppliers rather than a one-time check at signup. 5.23, cloud services, is new in 2022 and expects a documented process for evaluating a cloud provider's security commitments before you build on it, which for most SaaS startups means your AWS, GCP, or Azure shared-responsibility review.

Incident Management and Continuity (5.24-5.30)

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

What auditors look for: a documented incident response plan with defined severity levels and escalation paths, a log of security events (even a zero-incident log is valid evidence for 5.24-5.27), and a business continuity plan that specifically addresses how information security controls hold up during a disruption, not just how the business keeps operating. 5.30 is a 2022 addition and is often the weakest control in a first-time SoA: it expects you to have thought through what happens to encryption, access control, and logging if your primary infrastructure fails over.

Compliance and Legal (5.31-5.37)

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.32 Intellectual property rights
  • 5.33 Protection of records
  • 5.34 Privacy and protection of PII
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.37 Documented operating procedures

What auditors look for: a maintained register of applicable legal and contractual security requirements (GDPR, sector-specific rules, customer contract clauses), evidence of an independent review of the ISMS (this can be the internal audit, provided the reviewer is independent of the area reviewed), and documented operating procedures for repeatable security tasks like access provisioning or backup verification, not just tribal knowledge.

How This Maps to the Statement of Applicability

Every one of these 37 controls needs a line in your Statement of Applicability: applicable or not, and why. For most SaaS startups, the organizational controls are close to fully applicable, the common exclusions sit in 5.6 (special interest groups, if you have no formal threat-intel relationship yet) and parts of 5.19-5.22 if you genuinely run no third-party suppliers with access to in-scope data, which is rare.

Mapping these 37 controls against your real vendor contracts, incident logs, and access reviews is ongoing work, not a one-time exercise before the audit. A fractional CISO keeps that mapping current instead of reconstructing it under deadline. See pricing or book a call.

Related reading

Frequently asked questions

How many organizational controls are in ISO 27001 Annex A?
37. They run from 5.1 to 5.37 in ISO/IEC 27001:2022 Annex A, and they are the largest of the four control themes (Organizational, People, Physical, Technological).
What changed in the organizational controls between ISO 27001:2013 and 2022?
The 2022 revision reorganized 114 controls into 93 and introduced several new organizational controls, including threat intelligence (5.7), information security for use of cloud services (5.23), and ICT readiness for business continuity (5.30). Several 2013-era controls were merged or renamed rather than dropped.
Can a startup exclude organizational controls from the Statement of Applicability?
Yes, but only with a documented reason tied to actual risk. A common example is 5.6 (contact with special interest groups) for a very early-stage company with no formal threat-intelligence relationships yet. Exclusions without a stated reason are a Stage 1 finding.
Which organizational controls do auditors spend the most time on?
5.15 through 5.18 (access control, identity management, authentication information, access rights) and 5.19 through 5.23 (supplier and cloud relationships), because both areas touch every system in scope and are easy to document poorly.
Do organizational controls overlap with SOC 2?
Significantly. Supplier and cloud controls map closely to SOC 2 CC9 vendor management, and incident management controls map to CC7.2 and CC7.3. A [fractional CISO](/fractional-ciso/) can build the evidence once and reuse it for both frameworks.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.