ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.1: Policies for information security

An overarching information security policy and a set of topic-specific policies are to be written, signed off by management, made available, brought to the attention of the staff and outside parties they concern, confirmed as received by those people, and revisited on a schedule and whenever something significant changes. Purpose: keep management's direction on information security fit, sufficient and working, in line with business, legal, regulatory and contractual needs. Guidance: top management approves the top-level policy, which states how the organization runs information security and draws on business strategy, laws and contracts, and present and expected risks and threats. It should cover what information security means for the organization, its objectives or how they are set, guiding principles, a commitment to meet applicable requirements and to keep improving the ISMS, which roles hold which responsibilities, and how exemptions and exceptions are handled; top management signs off any change to it. Beneath it sit topic-specific policies aimed at particular audiences or areas (for example access control, physical security, assets, information transfer, endpoint configuration, networks, incident management, backup, cryptography and keys, classification, technical vulnerabilities and secure development), consistent with the top policy and owned by people with the right authority and expertise. Reviews look for improvement and respond to shifts in strategy, technology, law and contracts, risks, the threat landscape and incident lessons, using management review and audit results, and check related policies for consistency. Policies should be understandable to their readers, acknowledged where appropriate, and screened for confidential content before being shared externally. The top policy is general and approved by top management; topic policies are detailed and approved at a suitable management level.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 157 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 17 controls

  • AC-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CP-1 Policy and Procedures
  • IA-1 Policy and Procedures
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • PS-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SC-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 17 controls

  • AC-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CP-1 Policy and Procedures
  • IA-1 Policy and Procedures
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • PS-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SC-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)

PCI DSS 4.0 · 15 controls

  • 1.1.1 1.1.1 Requirement 1 policies and procedures governed
  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

NIST SP 800-53 Rev 5 · 13 controls

ISO/IEC 42001:2023 · 9 controls

  • 5.2 AI policy
  • 6.1 Actions to address risks and opportunities
  • 7.5 Documented information
  • A.2 Policies related to AI
  • A.2.2 AI policy
  • A.2.3 Alignment with other organizational policies
  • A.2.4 Review of the AI policy
  • A.6.2.2 AI system requirements and specification
  • A.9.3 Objectives for responsible use of AI system

ISO 27701:2019 · 7 controls

  • 5.2.4 Information security management system
  • 5.3.1 Leadership and commitment
  • 5.3.2 Policy
  • 5.4 Planning
  • 5.6.3 Information security risk treatment
  • 6.2 Information security policies
  • 6.2.1 Management direction for information security

SOC 2 · 6 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

HIPAA Security Rule · 5 controls

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated

APRA CPS 234 · 4 controls

  • CPS234-13 Board Responsibility for Information Security
  • CPS234-15 Information Security Capability
  • CPS234-19 Information Security Policy Framework
  • CPS234-P19 Policy Direction to All Responsible Parties

C5 (Germany) · 4 controls

  • C5-OIS-01 Information Security Management System (ISMS)
  • C5-OIS-02 Information Security Policy
  • C5-SP-01 Documentation, communication and provision of policies and instructions
  • C5-SP-02 Review and Approval of Policies and Instructions

ISO 22301:2019 · 4 controls

  • 5.2 Policy
  • 5.2.1 Establishing the business continuity policy
  • 5.2.2 Communicating the business continuity policy
  • 6.2 Business continuity objectives and planning to achieve them
  • 16.7.45.C.01 16.7.45.C.01 Integrate MFA with security, PAM and password policies
  • 5.1.15.C.01 5.1.15.C.01 Security documents consistent with each other and SecPol
  • 5.1.7.C.01 5.1.7.C.01 Agency information security policy (SecPol) in place
  • 5.2.3.C.02 5.2.3.C.02 Topics to be covered in the SecPol
  • ISM-0047 CISO and authorising officer document approvals
  • ISM-0888 Annual review and currency statements
  • ISM-1602 Communication of cyber security documentation
  • ASBv3-GS-3 Define and implement data protection strategy
  • ASBv3-GS-4 Define and implement network security strategy
  • ASBv3-GS-6 Define and implement identity and privileged access strategy

NIS2 Directive · 3 controls

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-66 Rev 2 · 3 controls

  • CPS230-37 Service Provider Management Policy
  • CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers
  • MYHR-REG-3 Conditions of registration and participation
  • MYHR-SEC-1 Written security and access policy

DORA · 2 controls

ISO 27018:2019 · 2 controls

  • 5.1.1 Policies for information security
  • 5.1.2 Review of the policies for information security

MTCS (Singapore) · 2 controls

  • 6.5 Information security policy
  • 6.6 Review of information security policy

TSA Pipeline Security · 2 controls

  • TSA-PSG-01 Corporate security programme
  • TSA-PSG-02 Security plan documentation
  • 5.2 5.2 A physical asset protection policy meeting eleven conditions
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • CFTC-SS-1 Program of Risk Analysis and Oversight

CIS Controls v8 · 1 control

  • CIS-3.1 Establish and Maintain a Data Management Process

CMMC 2.0 · 1 control

IEC 62443 · 1 control

  • 62443-2-1-CSMS Cyber Security Management System (CSMS) for IACS

ISO 27001:2022 · 1 control

  • 5.1 Policies for information security

ISO/IEC 27011:2024 · 1 control

  • 27011-5.1 Policies for Information Security in Telecoms

NIST SP 800-218 · 1 control

NY DFS 23 NYCRR 500 · 1 control

  • P1-1.1.4 P1-1.1.4 Management approval of the security policy
  • TSA-SD-03 Cybersecurity Implementation Plan approval
  • MTSA-105.405 Facility Security Plan with Cybersecurity Annex

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 157 it maps to, and the evidence behind each claim, over MCP and REST.