ISO 27001 A.5 Organizational Controls
- A5.1: Policies for Information Security
- A5.2: Information Security Roles and Responsibilities
- A5.3: Segregation of Duties
- A5.5: Contact with Authorities
- A5.6: Contact with Special Interest Groups
- A5.7: Threat Intelligence
- A5.8: Information Security in Project Management
- A5.9: Inventory of Information and Other Associated Assets
- A5.10: Acceptable Use of Information and Other Associated Assets
- A5.11: Return of Assets
- A5.12: Classification of Information
- A5.13: Labelling of Information
- A5.14: Information Transfer
- A5.15: Access Control
- A5.16: Identity Management
- A5.17: Authentication Information
- A5.18: Access Rights
- A5.19 Information security in supplier relationships
- A5.20 Addressing information security within supplier agreements
- A5.21 Managing information security in the information and communication technology (ICT) supply chain
- A5.22 Monitoring, review and change management of supplier services
- A5.23 Information security for use of cloud services
- A5.24 Information security incident management planning and preparation
- A5.25 Assessment and decision on information security events
- A5.26 Response to information security incidents
- A5.27 Learning from information security incidents
- A5.28 Collection of evidence
- A5.29 Information security during disruption
- A5.30 ICT readiness for business continuity
- A5.31 Legal, statutory, regulatory and contractual requirements
- A5.32 Intellectual property rights
- A5.33 Protection of records
- A5.34 Privacy and protection of personal identifiable information (PII)
- A5.35 Independent review of information security
- A5.36 Compliance with policies, rules and standards for information security
- A5.37 Documented operating procedures
- A.5 Organizational Controls