| A.5.1 | Policies for information security | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.2 | Information security roles and responsibilities | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.3 | Segregation of duties | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.4 | Management responsibilities | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.5 | Contact with authorities | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.6 | Contact with special interest groups | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.7 | Threat intelligence | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.8 | Information security in project management | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.9 | Inventory of information and other associated assets | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.10 | Acceptable use of information and other associated assets | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.11 | Return of assets | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.12 | Classification of information | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.13 | Labelling of information | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.14 | Information transfer | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.15 | Access control | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.16 | Identity management | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.17 | Authentication information | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.18 | Access rights | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.19 | Information security in supplier relationships | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.20 | Addressing information security within supplier agreements | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.21 | Managing information security in the ICT supply chain | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.22 | Monitoring, review and change management of supplier services | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.23 | Information security for use of cloud services | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.24 | Information security incident management planning and preparation | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.25 | Assessment and decision on information security events | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.26 | Response to information security incidents | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.27 | Learning from information security incidents | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.28 | Collection of evidence | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.29 | Information security during disruption | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.30 | ICT readiness for business continuity | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.32 | Intellectual property rights | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.33 | Protection of records | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.34 | Privacy and protection of personal identifiable information (PII) | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.35 | Independent review of information security | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.36 | Compliance with policies, rules and standards for information security | Yes | Applicable — treated through the organisation's ISMS policies and controls |
| A.5.37 | Documented operating procedures | Yes | Applicable — treated through the organisation's ISMS policies and controls |