3.6 Organizational Controls: Continuity, Legal & Compliance (A.5.29–A.5.37)

Key Takeaways

  • A.5.29 and A.5.30 require information security during disruption and ICT readiness for business continuity, distinguishing security continuity from broader disaster-recovery execution.
  • A.5.31–A.5.34 address legal, statutory, regulatory, and contractual requirements, intellectual property, records protection, and privacy/PII obligations identified from interested parties.
  • A.5.35 and A.5.36 require independent review of information security and ongoing compliance with policies, rules, and standards.
  • A.5.37 requires documented operating procedures for information processing activities where needed for correct and secure operation.
  • Lead Implementer scenarios often test whether continuity plans preserve confidentiality and integrity—not only availability—during failover.
Last updated: July 2026

3.6 Organizational Controls: Continuity, Legal & Compliance (A.5.29–A.5.37)

The remaining organizational controls close the loop between operational resilience, legal obligations, independent assurance, and day-to-day operating procedures. Controls A.5.29 through A.5.37 are frequent Stage 2 interview topics because they connect the ISMS to business continuity programs, regulatory registers, privacy programs, and the documented procedures staff actually follow.


Control Map (A.5.29 – A.5.37)

ControlTitlePrimary implementer focus
A.5.29Information security during disruptionMaintain security controls when normal operations fail
A.5.30ICT readiness for business continuity (new 2022)Plan, implement, maintain, and test ICT continuity
A.5.31Legal, statutory, regulatory and contractual requirementsCompliance register and obligation owners
A.5.32Intellectual property rightsSoftware licensing, proprietary IP protection
A.5.33Protection of recordsIntegrity, availability, and confidentiality of records
A.5.34Privacy and protection of PIIPrivacy controls aligned to applicable law
A.5.35Independent review of information securityIndependent assessment of approach and implementation
A.5.36Compliance with policies, rules and standards for information securityOngoing conformity monitoring
A.5.37Documented operating proceduresProcedures for correct, secure operations

Information Security During Disruption vs. ICT Continuity (A.5.29 & A.5.30)

Lead Implementers must distinguish business continuity / disaster recovery concepts tested in PECB Domain 4:

  • Business continuity focuses on continuing critical business operations at an acceptable level during disruption.
  • Disaster recovery focuses on restoring ICT systems and data after a disaster or major outage.
  • A.5.29 Information security during disruption requires that information security is adapted and continues during disruption—failover sites still enforce access control, logging, and encryption; emergency accounts are controlled; backups remain protected.
  • A.5.30 ICT readiness for business continuity (new in 2022) requires planning, implementing, maintaining, and testing ICT continuity based on business continuity objectives and continuity requirements.

Implementation pattern:

  1. Identify priority activities and supporting ICT services (business impact analysis inputs).
  2. Define RTO/RPO targets with business owners.
  3. Design redundancy (A.8.14), backup (A.8.13), and alternate processing arrangements.
  4. Test continuity plans (tabletops and technical failover tests) and record results.
  5. Ensure security requirements travel with workloads to alternate sites (A.5.29).

Exam trap: a DR plan that restores systems to an unsecured alternate data center without access control or monitoring fails A.5.29 even if availability is restored.


Legal, IP, Records, and Privacy (A.5.31 – A.5.34)

Control A.5.31 requires identification and documentation of legal, statutory, regulatory, and contractual requirements related to information security, and the organization’s approach to meet them. This is the operationalization of Clause 4.2 interested-party requirements into a compliance register with owners and evidence.

Control A.5.32 Intellectual property rights covers proprietary software, licensed products, and organizational IP—license compliance, code ownership, and protection of trade secrets.

Control A.5.33 Protection of records requires records to be protected from loss, destruction, falsification, unauthorized access, and unauthorized release—overlapping Clause 7.5 retention and integrity controls.

Control A.5.34 Privacy and protection of PII requires the organization to identify and meet privacy and PII protection requirements relative to applicable legislation and contractual obligations. Lead Implementers coordinate ISMS controls with privacy programs (DPIAs, data-subject rights processes, retention schedules) rather than treating privacy as a separate silo ignored by the SoA.


Independent Review and Ongoing Compliance (A.5.35 & A.5.36)

Control A.5.35 Independent review of information security requires the organization’s approach to managing information security and its implementation to be reviewed independently at planned intervals or when significant changes occur. Independence means reviewers are free from bias about the areas reviewed—internal audit (Clause 9.2), external specialists, or corporate audit functions may satisfy this when objectively positioned.

Control A.5.36 Compliance with policies, rules and standards for information security requires regular review of compliance with the organization’s information security policies, topic-specific policies, rules, and standards. Managers verify that procedures in their areas are followed; findings feed corrective action and management review.

Together, A.5.35/A.5.36 complement—but do not replace—Clause 9.2 internal audit and Clause 9.3 management review.


Documented Operating Procedures (A.5.37)

Control A.5.37 requires operating procedures for information processing facilities to be documented and made available to personnel who need them. Procedures should be prepared for system activities associated with information processing and communication facilities, such as:

  • Computer start-up and shut-down
  • Backup and restore
  • Equipment maintenance
  • Media handling
  • Mail handling and physical management rooms
  • Safety and security anomaly handling

A.5.37 pairs with Clause 7.5: procedures must be controlled documents, versioned, and accessible at point of use. Missing runbooks for privileged operations are a common Stage 2 finding.


Practical Implementation Scenario

Scenario: A healthcare SaaS fails over to a secondary region during a regional outage. Availability recovers, but security groups in the DR region allow unrestricted SSH, logging is disabled to “save cost,” and privacy impact assessments never evaluated cross-border transfer implications.

Lead Implementer guidance: Remediate under A.5.29 by enforcing equivalent security controls in DR; update A.5.30 continuity tests to include security control verification; update A.5.31/A.5.34 compliance and privacy registers for data-residency obligations; document secure failover operating procedures under A.5.37; and schedule an A.5.35 independent review of continuity security posture.

Test Your Knowledge

A disaster-recovery exercise restores applications to an alternate site but disables MFA and centralized logging to speed recovery. Which control is most directly violated?

A
B
C
D
Test Your Knowledge

Which control specifically requires planning, implementing, maintaining, and testing ICT continuity based on business continuity objectives?

A
B
C
D
Test Your Knowledge

An organization maintains a register of GDPR, contractual customer security clauses, and sector regulations with assigned owners and evidence links. Which control is primarily implemented?

A
B
C
D