Information Security Management
ISO 27001 Organisational Controls Explored
Organisational controls form the backbone of Annex A and any information security management system (ISMS).
They cover the policies, responsibilities, and governance processes that keep information security effective across your business.
ISO 27001 requires you to review them as part of your risk assessment and then respond to each control in a document called “The Statement of Applicability.
Every control is explained in more detail below.
Ready-to-use templates
Step-by-step implementation
Fast-track with expert support
Verified toolkit reviews:
(Includes: Information Security Scope Template)
Select a control family to explore it in more detail
What Are Organisational Controls in ISO 27001?
Organisational controls are the policy and process-based safeguards that guide how your organisation manages information security.
They define who does what, how decisions are made, and how security integrates with everyday operations.
Theyโre often the first controls an auditor will review because they demonstrate that security is managed systematically โ not left to chance.
How ISO 27001 Organisational Controls Fit into Annex A
ISO 27001:2022 includes 37 organisational controls (A.5.1 to A.5.37).
They sit within the wider Annex A structure of four control themes:
- Organisational โ management and governance processes (this page)
- People โ human factors and awareness
- Physical โ premises and equipment
- Technological โ systems and infrastructure
Together, these controls ensure your ISMS runs consistently and aligns with business objectives.
The specific controls you apply โ and how โ are documented in your Statement of Applicability.

Control List (5.1 โ 5.37)
Below is a complete list of the Organisational controls, each linking to its own detailed explanation and examples.
I’ve grouped them into themes to help organise them, but these are not ISO 27001 formal groupings.
Defines how information security is directed, owned, and reviewed.
Ensures the organisation stays informed and connected to its threat and regulatory landscape.
Governs the lifecycle of information and related assets.
Ensures only authorised people have appropriate access.
Manages risks linked to suppliers, cloud, and ICT services.
Enables detection, response, and recovery when incidents occur.
Keeps the ISMS aligned with external requirements.
Get every ISO 27001 document today.
Complete templates pack: policies, procedures, Statement of Applicability, risk register, and records. Updated for ISO 27001:2022
- 130 Word/Excel templates, ready to edit
- Auditor notes: what evidence to show
- Instant download, licence for your organisation
Instant download ยท 30-day upgrade credit to the Course
The Importance of Organisational Controls in 27001
So, why have this group of controls? Well, the benefits include;
- They establish governance and accountability, ensuring decisions are traceable.
- They drive risk-based planning and continuous improvement.
- They help demonstrate compliance with legal and contractual obligations.
- They ensure the ISMS stays aligned with business goals.
Often, when we think of security we think of technological controls, and maybe a little bit about training, but here ISO 27001 is trying to get you to think about governance, and the ‘wrap around’ to the technological controls. How do you manage policies, risk, data types, assets, access control, suppliers, incidents and legal / regulatory compliance.
These are really important aspects of security that need serious consideration and review.
Next Steps and Related Topics
Check out some of the other control families here;
FAQ: Organisational Controls
Are all 37 controls mandatory?
You must consider all of them and justify inclusion/exclusion in your statement of applicability (SoA).
Do these controls replace the old Annex A domains?
Yes โ in 2022 the 14 domains were replaced by the four themes (Organisational, People, Physical, Technological).
Where can I find implementation guidance?
You can refer to ISO 27002, which explains each controlโs purpose and actions, but I’ve added guides to each control above.
Ready-to-use templates
Step-by-step implementation
Fast-track with expert support
Verified toolkit reviews:
