Annex A: organizational controls
Annex A: Organizational controls require the establishment of a governance framework that manages information security through policies, defined roles, and operational processes. It ensures that security is integrated into the organization's structure rather than treated as a purely technical function.
What it means
These controls focus on the "administrative" side of security. While technological controls (A.8) protect data with software, organizational controls ensure there are rules in place to decide who gets access, how suppliers are managed, and who is accountable when something goes wrong.
In practice, this means moving from ad-hoc decision-making to a documented system. The scope covers everything from the high-level Information Security Policy down to specific registries of assets and the management of third-party cloud services.
The intent is to create consistency. By defining roles and responsibilities, an organization ensures that security tasks are not overlooked and that there is clear ownership for every critical asset and process within the ISMS (Information Security Management System).
How to meet it
- Develop a comprehensive set of information security policies approved by management and communicated to all employees.
- Create a formal organizational structure or RACI matrix that assigns specific security roles and responsibilities to individuals.
- Maintain an accurate asset register that identifies critical information assets and assigns an owner to each.
- Establish a supplier management process that includes risk assessments of third parties and security requirements in contracts.
- Implement a documented incident management procedure for reporting, escalating, and responding to security events.
- Define access control policies based on the principles of "least privilege" and "need-to-know."
- Set up a regular review cycle for all organizational policies to ensure they remain current with changing threats and business needs.
Evidence an auditor asks for
- Approved Information Security Policy (ISP) and supporting sub-policies (e.g., Access Control, Supplier Management).
- An Asset Register containing descriptions of assets, their classification, and assigned owners.
- Signed contracts or Service Level Agreements (SLAs) with suppliers that include specific security clauses.
- Incident logs showing the timeline from detection to resolution, including evidence of "lessons learned" reviews.
- Job descriptions or appointment letters confirming that individuals understand their assigned security responsibilities.
Common pitfalls
- Creating "shelfware" policies—documents that are written to satisfy an auditor but are not communicated to staff or followed in daily operations.
- Maintaining a static asset register that is not updated when new software, hardware, or cloud services are onboarded.
- Assuming that a signed contract with a vendor equals security; auditors look for evidence of ongoing monitoring and periodic risk reviews of those vendors.
- Vague role definitions where security tasks are assigned to "the IT team" generally rather than specific roles or individuals.