A.5 — Organizational Controls
A.5.1
Policies for information security
Critical
▶
A set of information security policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties.
Implementation Guidance
- Define a top-level information security policy and supporting topic-specific policies
- Ensure policies are approved by top management or delegated authority
- Communicate policies to all relevant personnel and interested parties
- Review policies at planned intervals or when significant changes occur
Framework Mapping
- NIS2: Art. 21(2)(a) — Risk analysis & IS policies
- NIST CSF: GV.PO — Policy
- DORA: Art. 6 — ICT risk management framework
Security Engineer Takeaway: This is the foundation control. Without documented, approved policies, nothing else has authority. Key: policies must be living documents, not shelf-ware. Review at least annually or after significant incidents/changes.
A.5.2
Information security roles & responsibilities
Important
▶
Information security roles and responsibilities shall be defined and allocated.
Implementation Guidance
- Define roles such as CISO, security architects, risk owners, asset owners
- Document responsibilities in job descriptions and RACI matrices
- Ensure roles are allocated to specific individuals or teams
Security Engineer Takeaway: Unclear roles cause gaps. Define who owns risk decisions, who responds to incidents, who manages access. Map to your org chart.
A.5.3
Segregation of duties
Important
▶
Conflicting duties and conflicting areas of responsibility shall be segregated.
Implementation Guidance
- Identify duties that create conflicts of interest if combined
- Separate authorization, execution, and verification functions
- Where segregation is not possible, implement compensating controls (monitoring, audit trails)
A.5.4
Management responsibilities
Standard
▶
Management shall require all personnel to apply information security in accordance with the established policies and procedures.
A.5.5
Contact with authorities
Standard
▶
Appropriate contacts with relevant authorities shall be maintained.
Implementation Guidance
- Maintain contact details for law enforcement, regulators, CSIRTs
- Under NIS2: know your national CSIRT for incident reporting
A.5.6
Contact with special interest groups
Standard
▶
Appropriate contacts with special interest groups or other specialist security forums and professional associations shall be maintained.
A.5.7
Threat intelligence
Critical
NEW
▶
Information relating to information security threats shall be collected and analysed to produce threat intelligence.
Implementation Guidance
- Establish processes to collect threat information from multiple sources (ISACs, CERT feeds, vendor advisories)
- Analyse threats at strategic, tactical, and operational levels
- Feed threat intelligence into risk assessment and control selection
- Share threat information with relevant parties per TLP markings
Framework Mapping
- NIS2: Art. 29 — Information sharing arrangements
- NIST CSF: ID.RA — Risk Assessment
- MITRE ATT&CK: Threat-informed defense
Security Engineer Takeaway: New in 2022. Formalizes what mature SOCs already do. You need documented processes for CTI collection, analysis, and dissemination. Subscribe to relevant feeds (sector ISACs, CERT advisories), integrate with SIEM/SOAR, and use STIX/TAXII for structured sharing.
A.5.8
Information security in project management
Standard
▶
Information security shall be integrated into project management.
A.5.9
Inventory of information and associated assets
Critical
▶
An inventory of information and other associated assets, including owners, shall be identified and maintained.
Implementation Guidance
- Maintain a comprehensive asset inventory (hardware, software, data, services, cloud resources)
- Assign owners to each asset
- Classify assets by criticality and sensitivity
- Review and update regularly
Security Engineer Takeaway: You cannot protect what you don't know about. This feeds your risk assessment. Use your CMDB, cloud asset discovery tools, and network scans to maintain an up-to-date inventory.
A.5.10
Acceptable use of information and assets
Important
▶
Rules for the acceptable use of information and other associated assets shall be identified, documented, and implemented.
A.5.11
Return of assets
Standard
▶
Personnel and other interested parties shall return all organizational assets in their possession upon change or termination of employment, contract, or agreement.
A.5.12
Classification of information
Important
▶
Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability, and relevant interested party requirements.
A.5.13
Labelling of information
Standard
▶
An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme.
A.5.14
Information transfer
Important
▶
Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.
A.5.15
Access control
Critical
▶
Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
Implementation Guidance
- Define access control policy based on least privilege and need-to-know
- Cover both physical and logical access
- Consider role-based access control (RBAC) or attribute-based (ABAC)
- Document and review regularly
Framework Mapping
- NIS2: Art. 21(2)(i) — HR security, access control, asset management
- NIST CSF: PR.AC — Access Control
Security Engineer Takeaway: Access control is foundational. Implement least privilege, enforce MFA, and conduct quarterly access reviews. This control is the policy backbone; A.8.2-A.8.5 are the technical implementation.
A.5.16
Identity management
Important
▶
The full lifecycle of identities shall be managed.
Implementation Guidance
- Manage identities from creation through modification to deletion
- Ensure unique identifiers for all users
- Integrate with HR processes for joiner/mover/leaver workflows
A.5.17
Authentication information
Important
▶
Allocation and management of authentication information shall be controlled by a management process including advising personnel on appropriate handling.
A.5.18
Access rights
Important
▶
Access rights to information and other associated assets shall be provisioned, reviewed, modified, and removed in a timely manner.
A.5.19
Information security in supplier relationships
Critical
▶
Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier's products or services.
Implementation Guidance
- Identify and document all suppliers with access to organizational information
- Assess supplier security posture before engagement
- Define minimum security requirements for suppliers
- Maintain a supplier register with risk ratings
Framework Mapping
- NIS2: Art. 21(2)(d) — Supply chain security
- DORA: Art. 28-30 — ICT third-party risk management
Security Engineer Takeaway: Supply chain attacks are a top threat vector. This control, with A.5.20-A.5.22, forms a complete supplier security framework that maps well to NIS2 and DORA third-party requirements.
A.5.20
Addressing info sec in supplier agreements
Important
▶
Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.
A.5.21
Managing info sec in the ICT supply chain
Important
▶
Processes and procedures shall be defined and implemented for managing the information security risks associated with the ICT products and services supply chain.
A.5.22
Monitoring, review & change management of supplier services
Important
▶
The organization shall regularly monitor, review, evaluate, and manage change in supplier information security practices and service delivery.
A.5.23
Information security for use of cloud services
Critical
NEW
▶
Processes for acquisition, use, management, and exit from cloud services shall be established in accordance with the organization's information security requirements.
Implementation Guidance
- Define cloud security policy covering all service models (IaaS, PaaS, SaaS)
- Assess cloud provider security (certifications, SOC 2, shared responsibility model)
- Implement cloud-specific controls: identity federation, encryption, monitoring
- Plan for cloud exit and data portability
- Address data residency and sovereignty requirements
Framework Mapping
- ISO 27017 — Cloud security controls
- ISO 27018 — PII protection in cloud
- DORA: Art. 28-30 — Third-party ICT provider requirements
Security Engineer Takeaway: New in 2022. Finally a dedicated cloud security control. Key: understand the shared responsibility model for each provider. Ensure your SoA addresses cloud-specific risks. Map to CSA CCM or ISO 27017 for detailed cloud controls.
A.5.24
Incident management planning & preparation
Critical
▶
The organization shall plan and prepare for managing information security incidents by defining, establishing, and communicating incident management processes, roles, and responsibilities.
Framework Mapping
- NIS2: Art. 21(2)(b) — Incident handling
- DORA: Art. 17 — ICT-related incident management process
Security Engineer Takeaway: Your IR plan is only as good as your last test. Conduct tabletop exercises quarterly and live exercises annually. Ensure NIS2/DORA reporting timelines are embedded in your playbooks.
A.5.25
Assessment & decision on information security events
Important
▶
The organization shall assess information security events and decide if they are to be categorized as information security incidents.
A.5.26
Response to information security incidents
Important
▶
Information security incidents shall be responded to in accordance with the documented procedures.
A.5.27
Learning from information security incidents
Important
▶
Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls.
A.5.28
Collection of evidence
Standard
▶
The organization shall establish and implement procedures for the identification, collection, acquisition, and preservation of evidence related to information security events.
A.5.29
Information security during disruption
Important
▶
The organization shall plan how to maintain information security at an appropriate level during disruption.
A.5.30
ICT readiness for business continuity
Critical
NEW
▶
ICT readiness shall be planned, implemented, maintained, and tested based on business continuity objectives and ICT continuity requirements.
Implementation Guidance
- Conduct business impact analysis (BIA) to identify ICT dependencies
- Define RTO and RPO for critical systems
- Implement and test disaster recovery plans for ICT
- Ensure backup and restoration processes are verified
Framework Mapping
- NIS2: Art. 21(2)(c) — Business continuity & crisis management
- DORA: Art. 11-12 — Business continuity & DR
- ISO 22301 — Business continuity management
Security Engineer Takeaway: New in 2022. Goes beyond traditional BCP by specifically focusing on ICT readiness. Test your DR plans for ransomware scenarios where all primary systems are unavailable. Can you restore from backups in your defined RTO?
A.5.31
Legal, statutory, regulatory & contractual requirements
Important
▶
Legal, statutory, regulatory, and contractual requirements relevant to information security and the organization's approach to meeting these requirements shall be identified, documented, and kept up to date.
A.5.32
Intellectual property rights
Standard
▶
The organization shall implement appropriate procedures to protect intellectual property rights.
A.5.33
Protection of records
Standard
▶
Records shall be protected from loss, destruction, falsification, unauthorized access, and unauthorized release.
A.5.34
Privacy and protection of PII
Important
▶
The organization shall identify and meet the requirements regarding the preservation of privacy and protection of PII as required by applicable legislation, regulations, and contractual requirements.
Framework Mapping
- GDPR: Art. 32 — Security of processing
- ISO 27701 — Privacy information management
A.5.35
Independent review of information security
Standard
▶
The organization's approach to managing information security and its implementation shall be reviewed independently at planned intervals or when significant changes occur.
A.5.36
Compliance with policies, rules & standards
Standard
▶
Compliance with the organization's information security policy, topic-specific policies, rules, and standards shall be regularly reviewed.
A.5.37
Documented operating procedures
Standard
▶
Operating procedures for information processing facilities shall be documented and made available to personnel who need them.
A.6 — People Controls
A.6.1
Screening
Important
▶
Background verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis taking into account applicable laws, regulations, and ethics and be proportional to the business requirements, the classification of the information to be accessed, and the perceived risks.
A.6.2
Terms and conditions of employment
Important
▶
The employment contractual agreements shall state the personnel's and the organization's responsibilities for information security.
A.6.3
Information security awareness, education & training
Critical
▶
Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education, and training and regular updates of the organization's information security policy, topic-specific policies, and procedures, as relevant for their job function.
Framework Mapping
- NIS2: Art. 21(2)(g) — Cyber hygiene & training
- NIS2: Art. 20(2) — Board cybersecurity training
Security Engineer Takeaway: This maps directly to NIS2 Art. 21(2)(g). Run phishing simulations monthly, track click rates, and provide role-specific training (secure coding for developers, cloud security for ops). Document everything for audit evidence.
A.6.4
Disciplinary process
Standard
▶
A disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.
A.6.5
Responsibilities after termination or change of employment
Standard
▶
Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced, and communicated to relevant personnel and other interested parties.
A.6.6
Confidentiality or non-disclosure agreements
Standard
▶
Confidentiality or non-disclosure agreements reflecting the organization's needs for the protection of information shall be identified, documented, regularly reviewed, and signed by personnel and other relevant interested parties.
A.6.7
Remote working
Important
▶
Security measures shall be implemented when personnel are working remotely to protect information accessed, processed, or stored outside the organization's premises.
Security Engineer Takeaway: Updated in 2022 for post-pandemic reality. Ensure VPN/ZTNA, endpoint protection, encrypted storage, and clear guidelines on handling sensitive data remotely.
A.6.8
Information security event reporting
Important
▶
The organization shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.
A.7 — Physical Controls
A.7.1
Physical security perimeters
Critical
▶
Security perimeters shall be defined and used to protect areas that contain information and other associated assets.
Implementation Guidance
- Define security zones (public, restricted, secure, high-security)
- Implement physical barriers (walls, fences, doors with access control)
- Consider data centre physical security requirements
A.7.2
Physical entry
Important
▶
Secure areas shall be protected by appropriate entry controls and access points.
A.7.3
Securing offices, rooms & facilities
Standard
▶
Physical security for offices, rooms, and facilities shall be designed and implemented.
A.7.4
Physical security monitoring
Important
NEW
▶
Premises shall be continuously monitored for unauthorized physical access.
Security Engineer Takeaway: New in 2022. Requires continuous monitoring (CCTV, intrusion detection sensors, security guards). Integrate with your SIEM for physical-cyber correlation.
A.7.5
Protecting against physical & environmental threats
Important
▶
Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented.
A.7.6
Working in secure areas
Standard
▶
Security measures for working in secure areas shall be designed and implemented.
A.7.7
Clear desk and clear screen
Standard
▶
Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.
A.7.8
Equipment siting and protection
Standard
▶
Equipment shall be sited securely and protected.
A.7.9
Security of assets off-premises
Standard
▶
Off-site assets shall be protected.
A.7.10
Storage media
Important
▶
Storage media shall be managed through their lifecycle of acquisition, use, transportation, and disposal in accordance with the organization's classification scheme and handling requirements.
A.7.11
Supporting utilities
Standard
▶
Information processing facilities shall be protected from power failures and other disruptions caused by failures in supporting utilities.
A.7.12
Cabling security
Standard
▶
Cables carrying power, data, or supporting information services shall be protected from interception, interference, or damage.
A.7.13
Equipment maintenance
Standard
▶
Equipment shall be maintained correctly to ensure availability, integrity, and continued fulfilment of information security requirements.
A.7.14
Secure disposal or re-use of equipment
Standard
▶
Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
A.8 — Technological Controls
A.8.1
User endpoint devices
Important
▶
Information stored on, processed by, or accessible via user endpoint devices shall be protected.
Implementation Guidance
- Deploy endpoint protection (EDR), encryption, and remote wipe capabilities
- Implement device management (MDM/UEM)
- Enforce security baselines and patch management
A.8.2
Privileged access rights
Critical
▶
The allocation and use of privileged access rights shall be restricted and managed.
Implementation Guidance
- Implement PAM (Privileged Access Management) solutions
- Use just-in-time privilege elevation
- Enforce MFA for all privileged access
- Monitor and log all privileged sessions
- Review privileged accounts quarterly
Security Engineer Takeaway: Privileged accounts are the number one target. Implement PAM with session recording, enforce MFA, and adopt just-in-time access. Maps to NIS2 Art. 21(2)(i) and (j).
A.8.3
Information access restriction
Important
▶
Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.
A.8.4
Access to source code
Standard
▶
Read and write access to source code, development tools, and software libraries shall be appropriately managed.
A.8.5
Secure authentication
Critical
▶
Secure authentication technologies and procedures shall be established and implemented based on information access restrictions and the topic-specific policy on access control.
Framework Mapping
- NIS2: Art. 21(2)(j) — MFA & continuous authentication
Security Engineer Takeaway: Implement phishing-resistant MFA (FIDO2/WebAuthn) for all critical and admin access. Maps directly to NIS2 Art. 21(2)(j).
A.8.6
Capacity management
Standard
▶
The use of resources shall be monitored and adjusted in line with current and expected capacity requirements.
A.8.7
Protection against malware
Critical
▶
Protection against malware shall be implemented and supported by appropriate user awareness.
Security Engineer Takeaway: Deploy EDR on all endpoints and servers. Combine with email filtering, web proxies, and user awareness. Test with simulated attacks.
A.8.8
Management of technical vulnerabilities
Critical
▶
Information about technical vulnerabilities of information systems in use shall be obtained in a timely fashion, the organization's exposure to such vulnerabilities shall be evaluated, and appropriate measures shall be taken.
Framework Mapping
- NIS2: Art. 21(2)(e) — Vulnerability handling and disclosure
Security Engineer Takeaway: Establish SLAs: critical vulns patched within 7 days, high within 30 days. Scan weekly. Feed results into risk assessment. Coordinate with A.5.7 threat intelligence for prioritization.
A.8.9
Configuration management
Critical
NEW
▶
Configurations, including security configurations, of hardware, software, services, and networks shall be established, documented, implemented, monitored, and reviewed.
Security Engineer Takeaway: New in 2022. Formalize your hardening baselines using CIS Benchmarks or DISA STIGs. Monitor for configuration drift. Use IaC (Infrastructure as Code) for consistency.
A.8.10
Information deletion
Important
NEW
▶
Information stored in information systems, devices, or in any other storage media shall be deleted when no longer required.
Security Engineer Takeaway: New in 2022. Aligns with GDPR data minimization. Implement automated data lifecycle management and retention policies.
A.8.11
Data masking
Important
NEW
▶
Data masking shall be used in accordance with the organization's topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration.
Security Engineer Takeaway: New in 2022. Use dynamic data masking for non-production environments, static masking for test data, and tokenization for sensitive fields. Supports GDPR compliance.
A.8.12
Data leakage prevention
Critical
NEW
▶
Data leakage prevention measures shall be applied to systems, networks, and any other devices that process, store, or transmit sensitive information.
Security Engineer Takeaway: New in 2022. Implement DLP at endpoint, network, and cloud levels. Start with classifying sensitive data, then deploy policies to prevent unauthorized transfer. Integrates with A.5.12 (classification) and A.8.11 (masking).
A.8.13
Information backup
Important
▶
Backup copies of information, software, and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
A.8.14
Redundancy of information processing facilities
Standard
▶
Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.
A.8.15
Logging
Critical
▶
Logs that record activities, exceptions, faults, and other relevant events shall be produced, stored, protected, and analysed.
Security Engineer Takeaway: Central logging is your forensics and detection foundation. Feed all logs to SIEM. Protect log integrity. Define retention periods. This control pairs with A.8.16 (monitoring) and A.8.17 (clock sync).
A.8.16
Monitoring activities
Critical
NEW
▶
Networks, systems, and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
Framework Mapping
- NIS2: Art. 21(2)(b) — Incident handling (detection)
- DORA: Art. 10 — Detection
- NIST CSF: DE.CM — Continuous Monitoring
Security Engineer Takeaway: New in 2022. Explicitly requires continuous anomaly detection — not just logging, but active monitoring. Deploy SIEM with behavioral analytics (UEBA), network detection and response (NDR), and alerting. This maps directly to NIS2 and DORA detection requirements.
A.8.17
Clock synchronization
Standard
▶
The clocks of information processing systems used by the organization shall be synchronized to approved time sources.
A.8.18
Use of privileged utility programs
Standard
▶
The use of utility programs that might be capable of overriding system and application controls shall be restricted and tightly controlled.
A.8.19
Installation of software on operational systems
Standard
▶
Procedures and measures shall be implemented to securely manage software installation on operational systems.
A.8.20
Networks security
Critical
▶
Networks and network devices shall be secured, managed, and controlled to protect information in systems and applications.
A.8.21
Security of network services
Standard
▶
Security mechanisms, service levels, and service requirements of network services shall be identified, implemented, and monitored.
A.8.22
Segregation of networks
Important
▶
Groups of information services, users, and information systems shall be segregated in the organization's networks.
A.8.23
Web filtering
Important
NEW
▶
Access to external websites shall be managed to reduce exposure to malicious content.
Security Engineer Takeaway: New in 2022. Control outbound web access using DNS filtering, web proxies, or SASE solutions. Block known malicious categories and enforce HTTPS inspection where appropriate.
A.8.24
Use of cryptography
Critical
▶
Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.
Framework Mapping
- NIS2: Art. 21(2)(h) — Cryptography & encryption
Security Engineer Takeaway: Enforce TLS 1.2+ everywhere, encrypt data at rest and in transit, implement proper key management. Start planning for post-quantum cryptography migration.
A.8.25
Secure development life cycle
Critical
▶
Rules for the secure development of software and systems shall be established and applied.
Security Engineer Takeaway: Integrate security into CI/CD: threat modeling, SAST, DAST, SCA, container scanning. This is the process control; A.8.28 is the coding practice control.
A.8.26
Application security requirements
Standard
▶
Information security requirements shall be identified, specified, and approved when developing or acquiring applications.
A.8.27
Secure system architecture & engineering principles
Important
▶
Principles for engineering secure systems shall be established, documented, maintained, and applied to any information system development activities.
A.8.28
Secure coding
Critical
NEW
▶
Secure coding principles shall be applied to software development.
Framework Mapping
- NIS2: Art. 21(2)(e) — Security in acquisition, development & maintenance
- OWASP Top 10 / OWASP ASVS
Security Engineer Takeaway: New in 2022. Secure coding is now a standalone control. Enforce OWASP guidelines, run SAST in CI/CD pipelines, conduct code reviews, and train developers on secure coding practices.
A.8.29
Security testing in development & acceptance
Important
▶
Security testing processes shall be defined and implemented in the development life cycle.
A.8.30
Outsourced development
Standard
▶
The organization shall direct, monitor, and review the activities related to outsourced system development.
A.8.31
Separation of development, test & production environments
Standard
▶
Development, testing, and production environments shall be separated and secured.
A.8.32
Change management
Important
▶
Changes to information processing facilities and information systems shall be subject to change management procedures.
A.8.33
Test information
Standard
▶
Test information shall be appropriately selected, protected, and managed.
A.8.34
Protection of information systems during audit testing
Standard
▶
Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.