2.1 Organizational and People Controls (Annex A Themes 5 & 6)
Key Takeaways
- The 2022 revision of ISO/IEC 27001 restructures Annex A into 4 themes with 93 controls, down from 14 domains and 114 controls in the 2013 version.
- Theme 5 (Organizational) contains 37 controls focusing on policies, roles, threat intelligence, asset management, and overarching ISMS governance.
- Theme 6 (People) encompasses 8 controls targeting human resources security, screening, awareness training, and disciplinary processes.
- Information security policies and acceptable use guidelines serve as the bedrock for enforcing organizational discipline and people-centric security measures.
2.1 Organizational and People Controls (Annex A Themes 5 & 6)
Introduction to the 2022 Annex A Structure
The release of ISO/IEC 27001:2022 introduced a significant paradigm shift in how information security controls are categorized and applied. Moving away from the 14-domain structure of the 2013 iteration, the updated Annex A now consolidates 93 controls into four distinct, easy-to-navigate themes: Organizational (Theme 5), People (Theme 6), Physical (Theme 7), and Technological (Theme 8). This restructuring reflects a modern understanding of information security, moving away from purely IT-centric views to a holistic risk management approach. The integration of attributes—such as control types (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities, and security domains—further empowers organizations to filter and align controls with their specific business and compliance requirements.
The four-theme layout is the map every Lead Auditor must carry into planning and fieldwork. The distribution below is the factual baseline for exam questions and Statement of Applicability reviews:
| Theme | Annex A theme number | Control count | Primary focus |
|---|---|---|---|
| Organizational | Theme 5 | 37 | Policies, roles, assets, suppliers, incidents, continuity |
| People | Theme 6 | 8 | Screening, employment terms, awareness, discipline, remote work |
| Physical | Theme 7 | 14 | Perimeters, facilities, equipment, utilities, secure disposal |
| Technological | Theme 8 | 34 | Access, malware, logging, malware, DLP, secure development |
| Total | — | 93 | Full Annex A catalog for SoA inclusion/exclusion |
This section delves into the foundational pillars of any Information Security Management System (ISMS): the organizational frameworks that govern it and the people who operate within it. Without robust organizational policies and a well-trained workforce, even the most advanced technological controls can be easily bypassed or rendered ineffective.
Theme 5: Organizational Controls
Theme 5 is the largest category in Annex A, encompassing 37 controls (Controls 5.1 through 5.37). It provides the administrative, legal, and operational scaffolding required to support information security. Organizational controls ensure that information security is not an isolated IT function but is integrated into the very fabric of the organization's business processes, strategic planning, and daily operations.
When preparing an audit trail through Theme 5, prioritize the following control clusters in sequence:
- Governance and accountability — policies (5.1), roles (5.2), segregation of duties (5.3), and management responsibilities that set direction.
- Threat-informed planning — threat intelligence (5.7) feeding risk assessment and monitoring rules.
- Asset and classification discipline — inventory (5.9), acceptable use (5.10), classification (5.12), and labelling/handling rules.
- Third-party and supply-chain assurance — supplier policy (5.19), agreements (5.20), ICT supply chain (5.21), and monitoring (5.22).
- Incident and continuity readiness — event reporting (5.24), response (5.26), learning (5.28), and ICT readiness for business continuity (5.30).
Policies for Information Security (Control 5.1)
At the apex of organizational controls are the information security policies. Control 5.1 mandates that management must define, approve, publish, and communicate a set of policies for information security. These policies serve as the highest-level expression of management's intent and commitment. An auditor will look for evidence that these policies are not just static documents but are regularly reviewed (Control 5.1 explicitly states this) at planned intervals or when significant changes occur, ensuring their continuing suitability, adequacy, and effectiveness. A policy that has not been updated in five years in a rapidly changing technology landscape is a prime candidate for a nonconformity.
Roles and Responsibilities (Control 5.2)
Information security roles and responsibilities must be clearly defined and allocated according to Control 5.2. Without explicit accountability, security tasks inevitably fall through the cracks. Auditors examine job descriptions, organizational charts, and RACI (Responsible, Accountable, Consulted, Informed) matrices to verify that security duties are assigned and understood. Conflict of interest, particularly regarding the segregation of duties (Control 5.3), is a critical audit point to prevent fraud or unauthorized modifications. For instance, the person who authorizes access should not be the same person who provisions it.
Threat Intelligence (Control 5.7)
A notable addition in the 2022 revision is Control 5.7: Threat Intelligence. Organizations are now explicitly required to collect and analyze information relating to information security threats to produce actionable threat intelligence. This shifts the ISMS posture from reactive to proactive. Implementation involves subscribing to threat feeds, participating in industry sharing groups, and integrating these insights into the risk assessment process. Auditors will expect to see how threat intelligence influences risk treatment plans and security monitoring rules, rather than just seeing a list of subscribed RSS feeds.
Asset Management (Controls 5.9 - 5.14)
Organizational controls extensively cover asset management. Control 5.9 requires an inventory of information and other associated assets, including hardware, software, and data. Control 5.10 dictates the acceptable use of these assets, while Control 5.12 mandates the classification of information based on its criticality and sensitivity. Without knowing what assets exist, where they are, and how critical they are, protecting them is impossible. An auditor will frequently pick an asset at random and ask to see it documented in the inventory with an assigned owner and classification level.
Information Security in Supplier Relationships (Controls 5.19 - 5.23)
Supply chain security is a paramount concern in modern ISMS. The organizational theme dedicates a cluster of controls to managing risks associated with suppliers. This includes establishing an overarching policy (5.19), addressing security within supplier agreements (5.20), and managing the information security in the ICT supply chain (5.21). Auditors will review contracts, right-to-audit clauses, and evidence of regular supplier security reviews and monitoring (5.22) to ensure third-party risks are mitigated effectively.
Incident Management and Business Continuity (Controls 5.24 - 5.30)
Organizational resilience is addressed through controls governing incident management and business continuity. A formalized process must exist for reporting security events (5.24) and responding to incidents (5.26). Furthermore, the organization must learn from these incidents (5.28). In the context of business continuity, Control 5.30 dictates that ICT readiness must be planned, implemented, maintained, and tested to ensure the availability of information during a disruption. Auditing these areas requires reviewing incident logs, post-mortem reports, and disaster recovery test results.
Theme 6: People Controls
Theme 6 recognizes that human error and malicious insider actions remain among the highest risks to information security. Comprising 8 controls (Controls 6.1 through 6.8), this theme addresses the lifecycle of employment, from pre-hire to post-termination.
Lead Auditors commonly sample People controls against this employment lifecycle checklist:
- Before hire: screening proportionate to role risk and information classification (Control 6.1).
- At hire: contractual security responsibilities and NDA/confidentiality obligations (Controls 6.2 and 6.6).
- During employment: ongoing awareness, education, and training with evidence of effectiveness (Control 6.3).
- When rules are broken: a communicated disciplinary process applied consistently (Control 6.4).
- At role change or exit: timely transfer of responsibilities and revocation of access (Control 6.5).
- For distributed work: remote working rules covering physical and logical protections (Control 6.7).
Screening (Control 6.1)
Before individuals are granted access to sensitive information, they must undergo background verification checks (screening) proportional to the business requirements, the classification of the information to be accessed, and perceived risks. Auditors evaluate HR policies against actual practices, ensuring that screening checks are documented, consistently applied, and legally compliant within the jurisdictions the organization operates.
Terms and Conditions of Employment (Control 6.2)
Employment contracts must state the employee's and the organization's responsibilities regarding information security. This includes confidentiality agreements (non-disclosure agreements, Control 6.6), which must remain valid even after the employment terminates. The explicit inclusion of security responsibilities in legal contracts ensures enforceability.
Information Security Awareness, Education, and Training (Control 6.3)
Control 6.3 mandates that all employees and relevant contractors receive appropriate awareness education and training, alongside regular updates on organizational policies and procedures. An auditor will not simply ask if training exists; they will look for evidence of its effectiveness. This means tracking completion rates, evaluating comprehension through quizzes, and verifying that the content is relevant to the evolving threat landscape (such as measuring the failure rates of periodic internal phishing simulations).
Disciplinary Process (Control 6.4)
A formalized disciplinary process must be communicated and applied to employees who have committed an information security violation. This control demonstrates management's commitment to enforcing security policies. Without consequences, policies are merely suggestions. Auditors may seek anonymized examples of the disciplinary process in action to confirm it is not a "paper-only" policy.
Remote Working (Control 6.7)
With the massive shift towards distributed workforces, Control 6.7 addresses the security of teleworking and remote access. Organizations must implement physical and logical controls to protect information accessed, processed, or stored at remote locations. This often intersects with technological controls, but at the people level, it involves clear acceptable use agreements, secure home networking guidelines, and training specific to the unique risks of remote environments.
Synergies Between Organizational and People Controls
These two themes do not operate in isolation; they are deeply interdependent. Organizational policies (Theme 5) set the rules of engagement, while People controls (Theme 6) ensure that the workforce understands, agrees to, and is held accountable for following those rules. For example, a robust Access Control Policy (5.15) relies entirely on HR notifying IT of a termination in a timely manner (6.5, Information security responsibilities after termination or change of employment) to ensure access is revoked promptly. As a Lead Auditor, evaluating the effectiveness of an ISMS requires observing these intersections and ensuring that administrative directives successfully translate into consistent human compliance across the organization.
Under ISO/IEC 27001:2022, which of the following best describes the requirement for Control 5.7 Threat Intelligence?
When auditing Control 6.3 (Information Security Awareness, Education, and Training), what evidence best demonstrates the effectiveness of the control rather than just its existence?
Which of the following is a primary objective of Control 5.3 (Segregation of Duties)?