Get Demo
↑

ISO 27001 Annex A.5 Organizational Controls Explained (37 controls)

ISO/IEC 27001:2022 Annex A.5 Organizational controls: 37 controls (A.5.1–A.5.37), including policies, threat intelligence, suppliers, and incident themes.

Published: September 2026 Compliance · ISO 27001 10–14 min read

Annex A theme Organizational controls covers 37 controls numbered A.5.1–A.5.37 in ISO/IEC 27001:2022. Topics span policies, roles, asset management themes, supplier relationships, incident management, and compliance-oriented organizational measures.

Count lock: A.5 = 37 controls. Full Annex A = 93 across four themes.

What A.5 Typically Covers

Use your Statement of Applicability to record applicability and implementation status for each A.5 control.

Operationalize ISO 27001:2022 with Continuous Evidence

CyberSilo CSA tracks SoA and mandatory records; ThreatHawk supports logging and monitoring artefacts for technological controls.

Frequently Asked Questions

How many A.5 controls are there?

37 organizational controls: A.5.1 through A.5.37.

Is A.5.7 new in 2022?

A.5.7 Threat intelligence is one of the controls introduced in the 2022 control set (part of the 11 new controls called out in transition guidance).

Do organizational controls replace policies?

No. Clause 5.2 still requires the information security policy. A.5 includes Policies for information security (A.5.1) and related organizational topics.

ISO 27001 hub · 93 controls · SoA · CSA · A.5.7

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!