3.2 Organizational Controls (Theme 5)

Key Takeaways

  • Theme 5 is the largest thematic group in Annex A, containing 37 organizational controls covering security policies, governance roles, supplier relationships, threat intelligence, cloud services, and business continuity.
  • Control 5.7 (Threat Intelligence) requires organizations to establish formal procedures for gathering, analyzing, and disseminating strategic, tactical, and operational threat data.
  • Controls 5.19 through 5.23 enforce comprehensive supply chain governance, mandating security requirements in vendor contracts, supply chain risk management, and cloud service security controls.
  • Control 5.30 (ICT Readiness for Business Continuity) requires IT infrastructure and application readiness to meet defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) during disruptions.
Last updated: July 2026

ISO/IEC 27001:2022 Theme 5: Organizational Controls

Auditor Focus: Theme 5 comprises 37 controls (Controls 5.1 through 5.37) focused on organizational structures, policies, governance processes, supplier risk management, and business resilience. Lead auditors must verify that organizational controls are supported by executive commitment, formal documentation, clear operational roles, and demonstrable evidence of execution.


1. Structure & Governance of Organizational Controls

Organizational controls establish the managerial and operational baseline of the Information Security Management System (ISMS). They bridge the gap between high-level management Clause requirements (Clauses 4–10) and specific technical implementations.

+-----------------------------------------------------------------------------------+
|                       THEME 5: ORGANIZATIONAL CONTROLS (37)                       |
+-----------------------------------------------------------------------------------+
|  Governance & Policies   ---> 5.1 Policies | 5.2 Roles | 5.3 Segregation of Duties|
|  External Relationships  ---> 5.5 Authorities | 5.6 Interest Groups | 5.7 Threat Intel|
|  Asset & Data Management ---> 5.9 Inventory | 5.10 Acceptable Use | 5.14 Information|
|  Supply Chain & Cloud    ---> 5.19 - 5.22 Supplier Security | 5.23 Cloud Services |
|  Business Continuity     ---> 5.29 Security in Disruption | 5.30 ICT Readiness    |
+-----------------------------------------------------------------------------------+

Core Governance Controls (5.1 – 5.4)

  • 5.1 Policies for information security: Requires top management to define, approve, publish, and periodically review information security policies. Auditors look for approval signatures, annual review logs, and evidence of communication to personnel.
  • 5.2 Information security roles and responsibilities: Security roles must be explicitly defined and allocated across the organization (e.g., CISO, Data Protection Officer, System Owners).
  • 5.3 Segregation of duties: Conflicting duties and areas of responsibility must be segregated to reduce opportunities for unauthorized or unintentional modification or misuse of assets (e.g., separating software developers from production deployment authorization).
  • 5.4 Management responsibilities: Management must require all personnel to apply information security in accordance with established policies.

2. In-Depth Analysis of Critical & New Organizational Controls

Control 5.7: Threat Intelligence (NEW)

Control 5.7 requires organizations to collect and analyze information regarding information security threats to produce actionable threat intelligence.

Lead auditors assess threat intelligence across three operational tiers:

  1. Strategic Intelligence: High-level trends, geopolitical risks, and industry threat landscapes (e.g., board reports on ransomware trends in healthcare).
  2. Tactical Intelligence: Information on threat actor tactics, techniques, and procedures (TTPs) mapped to frameworks like MITRE ATT&CK.
  3. Operational/Technical Intelligence: Specific Indicators of Compromise (IoCs), malicious IP lists, file hashes, and domain blocklists ingested into firewalls and SIEM systems.
+-----------------------------------------------------------------------------------+
|                         THREAT INTELLIGENCE FLOW (5.7)                            |
+-----------------------------------------------------------------------------------+
|  [External Feeds / ISACs] ---> [Ingestion & Analysis] ---> [Actionable Output]    |
|                                                                 |                 |
|  - Commercial Threat Feeds                                      +--> SIEM Rules   |
|  - Government Alerts (CISA)                                     +--> Firewall IP  |
|  - Industry CERTs / ISACs                                       +--> Patch Priority|
+-----------------------------------------------------------------------------------+

Supply Chain & Cloud Security Controls (5.19 – 5.23)

Modern enterprises rely heavily on vendor ecosystems and cloud infrastructure. Theme 5 establishes a multi-tiered supply chain defense:

  • 5.19 Information security in supplier relationships: Establishing processes to manage security risks associated with supplier access to assets.
  • 5.20 Addressing security within supplier agreements: Contractual clauses specifying security requirements, non-disclosure agreements, data location, incident notification SLAs, and right-to-audit provisions.
  • 5.21 Managing security in the ICT supply chain: Addressing risks in hardware, software, and cloud components throughout their lifecycle (e.g., Software Bill of Materials [SBOM], supply chain tamper checks).
  • 5.22 Monitoring, review and change management of supplier services: Regularly auditing vendor compliance, reviewing SOC 2 Type II / ISO 27001 certificates, and managing vendor service changes.
  • 5.23 Information security for use of cloud services (NEW): Establishing governance for acquiring, using, managing, and exiting cloud services. Auditors inspect cloud architecture diagrams, shared responsibility matrices (IaaS/PaaS/SaaS), tenant isolation controls, and automated cloud security posture management (CSPM) alerts.

Business Continuity & ICT Readiness (5.29 – 5.30)

  • 5.29 Information security during disruption: Ensuring security controls remain effective during adverse situations (e.g., maintaining access controls and logging during emergency failover).
  • 5.30 ICT readiness for business continuity (NEW): Focuses specifically on technical availability. ICT readiness must be planned, implemented, tested, and maintained to ensure systems can recover within specified Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

3. Governance & Supply Chain Audit Evidence Matrix

ControlMandatory Audit Evidence / ArtifactsCommon Audit Sampling Techniques
5.1 PoliciesApproved infosec policies, version control matrix, annual review meeting minutes.Sample 5-10 security policies; verify executive sign-off date within past 12 months.
5.3 Segregation of DutiesMatrix of incompatible duties, IAM role definitions, change approval logs.Sample 10 production code deployments; verify developer did not approve their own PR.
5.7 Threat IntelligenceThreat feed subscription logs, vulnerability triage tickets linked to IoCs, CISO threat briefings.Review 3 recent critical CVE advisories; verify time elapsed between intelligence receipt and patching.
5.20 Supplier AgreementsVendor contracts, Master Services Agreements (MSAs), SLA schedules.Sample 5 critical supplier contracts; check for mandatory 24-hr breach notification clause.
5.23 Cloud SecurityCloud security policy, CSPM compliance dashboards, AWS/Azure shared responsibility document.Inspect live CSPM portal (e.g., AWS Security Hub); check for unencrypted S3 buckets or open SSH.
5.30 ICT ReadinessBusiness Impact Analysis (BIA), Disaster Recovery (DR) test reports, RTO/RPO specifications.Review most recent annual DR failover test results; compare actual recovery time against target RTO.

4. Lead Auditor Worked Scenario

Scenario Background

Lead Auditor Marcus is auditing FinTech Express, an online payment processor undergoing certification against ISO/IEC 27001:2022. FinTech Express uses a hybrid cloud infrastructure and outsources customer support to a third-party vendor, CallSupport Ltd.

Audit Findings & Investigation

  1. Auditing Control 5.22 & 5.23 (Supplier & Cloud Management):

    • Marcus requests the vendor security review for CallSupport Ltd.
    • FinTech Express provided a SOC 2 Type II report for CallSupport Ltd dated 3 years prior. No recent audit reports, security assessments, or SLA reviews had been conducted since contract signing.
    • For AWS cloud governance (5.23), FinTech Express demonstrated excellent automated infrastructure deployment via Terraform, but lacked a formal policy for evaluating new AWS service adoptions.
  2. Auditing Control 5.7 (Threat Intelligence):

    • FinTech Express subscribes to a financial sector ISAC threat feed.
    • However, when Marcus interviewed the Incident Response team, they revealed that threat feed emails were delivered to an unmonitored shared mailbox and were not ingested into the SIEM or firewall blocklists.
  3. Auditing Control 5.30 (ICT Readiness for Business Continuity):

    • The BIA specifies an RTO of 2 hours for the core payment gateway.
    • The most recent DR test report showed an actual recovery time of 6 hours due to database restoration bottlenecks. No corrective action plan was logged to resolve the 4-hour RTO gap.

Nonconformities Issued by Marcus

  • Major Nonconformity against Control 5.22 (Supplier Monitoring): FinTech Express failed to monitor and review supplier security performance for critical vendor CallSupport Ltd for over 36 months, exposing customer payment data to unassessed vendor risks.
  • Minor Nonconformity against Control 5.7 (Threat Intelligence): Threat intelligence feeds are received but not analyzed or applied to produce actionable intelligence or automated technical defenses.
  • Minor Nonconformity against Control 5.30 & Clause 10.1 (ICT Readiness & Improvement): The organization identified a 4-hour failure gap between actual DR recovery time and mandatory RTO targets during testing, but failed to initiate corrective action.
Test Your Knowledge

Control 5.7 (Threat intelligence) is a new addition to ISO/IEC 27001:2022. Which of the following activities best demonstrates compliance with this control during an audit?

A
B
C
D
Test Your Knowledge

During an audit of Control 5.30 (ICT readiness for business continuity), the auditor discovers that the organization's business impact analysis specifies a Recovery Time Objective (RTO) of 4 hours for its primary database. However, the last simulation test required 12 hours to restore data. What should the auditor conclude?

A
B
C
D
Test Your Knowledge

An organization relies heavily on a third-party SaaS vendor for core CRM operations. Under Control 5.23 (Information security for use of cloud services), which artifact should a lead auditor request first to verify effective cloud governance?

A
B
C
D