Annex A — Organizational Controls (5.1-5.37)

Survey the 37 Organizational controls by cluster — policies, asset management, access control, supplier relationships, incident management, and compliance — rather than memorizing each in isolation.

Medium 70m 2 tasks

Learning Objectives

  • Name the 9 logical clusters the 37 Organizational controls fall into
  • Explain what at least 2 controls in each cluster actually require in practice
  • Distinguish 5.31 (legal/regulatory) from 5.34 (privacy/PII) as separate, related controls
  • Recognize why 'Annex A control number' alone is rarely how Foundation exams test this material

At 37 controls, the Organizational theme is the largest of the four Annex A themes. Trying to memorize all 37 as an unordered list is the least effective way to learn this — instead, group them into the clusters below, which mirror how they actually get implemented together in practice.

The 9 clusters

Cluster Controls What it's really about
Policies & roles 5.1-5.4 The governance foundation: written policy, defined roles, segregation of duties, management responsibilities
External contacts 5.5-5.6 Staying connected to authorities and security communities
Threat intel & project security 5.7-5.8 Proactively tracking threats; building security into projects from the start, not bolted on after
Asset & information management 5.9-5.14 Knowing what you have, classifying it, labelling it, transferring it safely
Access control 5.15-5.18 Who can get to what, and how that's managed over someone's lifecycle
Supplier relationships 5.19-5.23 Extending your own security expectations to vendors, including cloud providers
Incident management 5.24-5.28 The full lifecycle from planning through evidence collection
Business continuity 5.29-5.30 Staying secure and operational during disruption
Legal, compliance & assurance 5.31-5.37 Legal obligations, IP, records, privacy, independent review, documented procedures

A closer look at the clusters most often tested

Policies & roles (5.1-5.4)

5.1 requires a top-level information security policy (which you met as clause 5.2's output in lesson 3 — Annex A 5.1 is the control-level echo of that same requirement). 5.3, segregation of duties, is a favorite exam topic: the same person should not both request and approve their own access, or both write and deploy code to production without review — the point is preventing a single person from having enough unchecked power to cause or hide a problem.

Asset & information management (5.9-5.14)

5.9 (inventory) and 5.12 (classification) work together: you can't classify what you haven't inventoried, and you can't decide appropriate protection without classification. A common real-world gap: organizations classify documents ("Confidential," "Internal") but never actually inventory where confidential data lives across systems — 5.9 exists precisely to close that gap.

Access control (5.15-5.18)

5.15 is the umbrella access control policy; 5.16 (identity management) and 5.18 (access rights) cover the full lifecycle — provisioning on joining, changing on role change, and critically, revoking promptly on leaving (the exact scenario from lesson 6's corrective action example). 5.17, authentication information, covers how credentials themselves (passwords, tokens) are protected — not just who has access, but how the "keys" are safeguarded.

Supplier relationships (5.19-5.23)

This cluster exists because your ISMS scope doesn't stop at your own infrastructure. 5.19-5.20 concern the relationship and agreement terms; 5.21 addresses the wider ICT supply chain (a vulnerability in a vendor's vendor can still reach you); 5.22 requires ongoing monitoring, not a one-time vendor questionnaire at signup; 5.23 specifically addresses cloud service usage, reflecting how central cloud infrastructure has become.

Legal, compliance & assurance (5.31-5.37)

Two controls here are easy to conflate but distinct: 5.31 covers legal, statutory, regulatory, and contractual requirements broadly (data protection and other laws, contracts, IP licensing obligations) — while 5.34 is specifically about privacy and protection of personally identifiable information (PII). An organization can have a strong 5.31 (aware of and tracking all applicable laws) while still having a weak 5.34 (no actual PII inventory or retention policy) — they are related but answer different audit questions. 5.35 (independent review) requires that the ISMS itself be periodically reviewed by someone independent of its day-to-day operation — echoing the same independence principle from clause 9.2's internal audit requirement, but applied to the whole ISMS rather than a single audit cycle.

Why exams rarely ask "what is control 5.19?"

Foundation-level questions are much more likely to describe a scenario and ask which control area it maps to, or to test whether you can tell two similarly-named controls apart (like 5.31 vs 5.34 above) than to ask you to recite a control's number from memory. Learning the clusters and the reasoning behind each — not just the numbers — is what actually transfers to both the exam and real audit work.

A company discovers that a departing employee's access to a customer database was not revoked for two weeks after their last day, and separately, that no one can say with confidence which systems contain customer PII. Identify which of the 9 clusters each issue belongs to, and name the specific control number most directly implicated by each.

✦ Answer the questions to complete this task

Which specific control is most directly implicated by access not being revoked promptly after departure?

Which specific control is most directly implicated by not knowing which systems contain customer PII?

A company tracks every law and contractual clause that applies to it in a legal register (satisfying one control well) but has never mapped where personal data of EU customers is stored, how long it's retained, or how a deletion request would be fulfilled. Explain, in your own words, why this company can be strong on one of these two controls and weak on the other simultaneously.

✦ Answer the questions to complete this task

Why can an organization be strong on 5.31 but weak on 5.34 at the same time?

💪 Exercises & Challenges

📝 MCQ Medium +20 XP

Annex A Organizational Controls — MCQ

Annex A Organizational Controls — MCQ

Start →
⚙️ Practical Medium +30 XP

Build a Cluster Reference Map

Build a Cluster Reference Map

Start →
🚩 Challenge Medium +40 XP

The Audit Trail Puzzle

The Audit Trail Puzzle

Start →