7.2 Annex A Organizational (37) and People (8) Controls

Key Takeaways

  • Organizational controls (A.5.1-A.5.37) cover policies, roles, supplier relationships, threat intelligence, cloud services, and ICT readiness for business continuity
  • People controls (A.6.1-A.6.8) cover screening, terms of employment, awareness, disciplinary process, confidentiality, remote working, and information transfer
  • A.5.1 Policies for information security is the anchor control — it is the parent policy that all other ISMS documentation references
  • A.5.7 Threat intelligence, A.5.23 Cloud services, and A.5.30 ICT readiness are 2022 additions frequently tested
  • A.6.3 Information security awareness, education, and training must be ongoing and role-appropriate, not a one-time onboarding event
Last updated: July 2026

Annex A's Organizational and People themes together address the human and procedural side of information security. They are the largest non-technical portion of Annex A and consistently appear in Foundation exam questions about policy, supplier management, awareness, and remote work. This section walks through the exam-relevant controls in each theme — not all 45, but the ones the exam actually targets.

Organizational Theme (A.5.1 – A.5.37, 37 controls)

The Organizational theme is the largest of the four themes. It contains the controls that govern how the organization directs, documents, and manages information security as a business process. Many of these controls produce the documented information the auditor will first ask to see during Stage 1.

Anchor Control: A.5.1 Policies for Information Security

A.5.1 requires a set of organization-wide information security policies, approved by top management, published, communicated to employees and relevant interested parties, and reviewed at planned intervals or when significant changes occur. A.5.1 is the parent policy — every other policy in the ISMS (access control policy, acceptable use policy, clear desk/clear screen policy, etc.) is a child of A.5.1.

Representative Major Controls

ControlTitleExam Significance
A.5.1Policies for information securityParent policy; top management approval; reviewed at planned intervals
A.5.2Roles and responsibilitiesSeparation of duties; asset/risk owners assigned
A.5.7Threat intelligence (NEW 2022)Collect and analyze threat intelligence; inform risk assessment
A.5.9Inventory of information and other associated assetsAsset inventory is the foundation of risk assessment
A.5.10Acceptable use of information and other associated assetsWhat users may and may not do with assets
A.5.15Access controlTopic-level access control; pairs with A.8.3-A.8.5
A.5.16Identity managementUnique user IDs; lifecycle from joiner-mover-leaver
A.5.17Authentication informationPassword, MFA, token management; secrets handling
A.5.19Information security in supplier relationshipsSupplier agreements must address security
A.5.20Addressing information security within supplier agreementsSecurity requirements flow into contracts
A.5.23Information security for use of cloud services (NEW 2022)Cloud-specific policy; responsibilities shared with provider
A.5.27Protection of recordsLegal, regulatory, contractual retention
A.5.30ICT readiness for business continuity (NEW 2022)ICT must meet business continuity requirements
A.5.32Intellectual property rightsRespect IP rights in software and content use
A.5.37Evidence collectionForensic-ready evidence handling for incidents

Why Organizational Controls Matter Most for the Foundation Exam

The Foundation syllabus weights policy, roles, supplier, and awareness heavily because they are the questions that distinguish a Foundation candidate from a Lead Implementer candidate. Expect questions like:

  • "Who is responsible for approving the information security policy?" → Top management (A.5.1, Clause 5.1).
  • "What is the purpose of A.5.7 Threat intelligence?" → To provide context for risk assessment and treatment decisions.
  • "What should supplier agreements include?" → Appropriate security requirements, responsibilities, and handling of incidents (A.5.20).

2022 Additions in the Organizational Theme

Three of the eleven new 2022 controls live here:

  • A.5.7 Threat intelligence — formalizes intelligence collection and dissemination.
  • A.5.23 Information security for use of cloud services — establishes processes for acquiring, using, managing, and protecting cloud services; aligns with shared responsibility.
  • A.5.30 ICT readiness for business continuity — ensures ICT services support business continuity requirements during disruption.

People Theme (A.6.1 – A.6.8, 8 controls)

The People theme is the smallest theme (8 controls) but covers some of the highest-likelihood exam questions because every organization must implement them, and they map cleanly to lifecycle stages of employment.

The 8 People Controls

ControlTitleStage / Topic
A.6.1ScreeningBefore employment (background checks proportional to role and risk)
A.6.2Terms and conditions of employmentAt hire — security responsibilities written into contract
A.6.3Information security awareness, education, and trainingDuring employment — ongoing, role-appropriate
A.6.4Disciplinary processAfter a policy violation — sanction framework
A.6.5Responsibilities after termination or change of employmentAt exit — duties survive termination
A.6.6Confidentiality or non-disclosure agreementsThroughout — legally binding protection
A.6.7Remote workingWhere work happens — protect information at remote sites
A.6.8Information security event reportingWhen something happens — report to designated point

Exam-Relevant Highlights

A.6.1 Screening. Background verification checks on candidates for employment should be carried out in accordance with laws, regulations, and ethics, and proportional to business requirements, classification of information to be accessed, and perceived risk. The exam tests two angles: (1) screening must be lawful and proportionate, not blanket; (2) screening applies to contractors and temporary staff too, not only permanent employees.

A.6.2 Terms and conditions of employment. Information security responsibilities must be written into the employment contract or equivalent agreement before the employee is granted access. A common distractor says these can be communicated verbally — they must be documented.

A.6.3 Awareness, education, and training. Awareness must be:

  • Ongoing — not a one-time onboarding event
  • Role-appropriate — developers get secure coding training; finance staff get anti-fraud training
  • Covered in onboarding within a reasonable time after hire
  • Updated in response to changes in threats or policies

The exam frequently tests the ongoing and role-appropriate qualifiers. A question may say "annual training is sufficient" — that is wrong, because annual alone does not satisfy "ongoing."

A.6.4 Disciplinary process. A formal, communicated process exists so that employees who commit an information security breach know that a sanction framework exists. This deters negligence and ensures consistent treatment. The exam usually tests that the process must be documented and communicated before an incident, not invented afterward.

A.6.6 Confidentiality or NDA. NDAs should be signed before access is granted and maintained for the period required by the information's sensitivity, including after termination where appropriate.

A.6.7 Remote working. The 2022 standard elevates remote working to its own control (previously folded into acceptable use). It requires that remote work sites be protected against threats such as malware, unauthorized access, and disclosure — covering VPNs, endpoint security, and physical handling of assets at home. This became far more prominent after the pandemic shift to mass remote work.

A.6.8 Information security event reporting. Employees must report events through a designated channel to a designated point of contact without delay. The exam may try to trick you with "report to your immediate line manager who will report upward" — the standard requires a designated reporting channel, not an ad-hoc chain.


Common Exam Traps

  • Trap 1 — Awareness training is a one-time onboarding activity. Wrong. A.6.3 explicitly requires ongoing awareness, education, and training, updated as threats and policies change.
  • Trap 2 — Background screening applies only to permanent employees. Wrong. A.6.1 applies screening to all candidates including contractors and temporary staff when they will have access to information.
  • Trap 3 — Disciplinary process is invented after a breach. Wrong. A.6.4 requires a pre-existing, documented, communicated disciplinary process.
  • Trap 4 — Cloud services control is in the Technological theme. Wrong. A.5.23 Information security for use of cloud services is in the Organizational theme because it addresses process and supplier relationship, not the technology itself.
  • Trap 5 — Threat intelligence (5.7) is purely technical. Wrong. The control lives in Organizational and is about the process of acquiring, analyzing, and acting on threat intelligence.

Key Takeaways

  • Organizational theme (A.5.1-A.5.37) is the largest theme and covers policies, roles, supplier relationships, and the three 2022 additions (5.7, 5.23, 5.30).
  • People theme (A.6.1-A.6.8) maps to the employment lifecycle: screening, terms, awareness, discipline, exit, confidentiality, remote work, event reporting.
  • A.5.1 Policies for information security is the parent policy that top management approves and reviews at planned intervals.
  • A.6.3 Awareness must be ongoing and role-appropriate, not a one-time event.
  • A.5.23 Cloud services is an Organizational control, not a Technological one — the technology detail lives in A.8 themes.
Test Your Knowledge

An organization conducts a single information security awareness session at employee onboarding and considers awareness training complete. Which Annex A control does this approach most directly violate?

A
B
C
D
Test Your Knowledge

Under A.5.1 Policies for information security, who is responsible for approving the information security policies?

A
B
C
D
Test Your Knowledge

Which theme of ISO/IEC 27001:2022 Annex A contains the control 'Information security for use of cloud services' (5.23)?

A
B
C
D