| A.05.00 | A.5 Organisational Controls | Implemented |
| A.05.01 | Policies for information security | Implemented |
| A.05.02 | Information security roles and responsibilities | Implemented |
| A.05.03 | Segregation of duties | Implemented |
| A.05.04 | Management responsibilities | Implemented |
| A.05.05 | Contact with authorities | Implemented |
| A.05.06 | Contact with special interest groups | Implemented |
| A.05.07 | Threat intelligence | Implemented |
| A.05.08 | Information security in project management | WIP |
| A.05.09 | Inventory of information and other associated assets | Implemented |
| A.05.10 | Acceptable use of information and other associated assets | Implemented |
| A.05.11 | Return of assets | Implemented |
| A.05.12 | Classification of information | Implemented |
| A.05.13 | Labelling of information | Implemented |
| A.05.14 | Information transfer | Implemented |
| A.05.15 | Access control | Implemented |
| A.05.16 | Identity management | Implemented |
| A.05.17 | Authentication information | Implemented |
| A.05.18 | Access rights | Implemented |
| A.05.19 | Information security in supplier relationships | Implemented |
| A.05.20 | Addressing information security within supplier agreements | Implemented |
| A.05.21 | Managing information security in the information and communication technology (ICT) supply chain | Implemented |
| A.05.22 | Monitoring, review and change management of supplier services | Implemented |
| A.05.23 | Information security for use of cloud services | Implemented |
| A.05.24 | Information security incident management planning and preparation | Implemented |
| A.05.25 | Assessment and decision on information security events | Implemented |
| A.05.26 | Response to information security incidents | Implemented |
| A.05.27 | Learning from information security incidents | Implemented |
| A.05.28 | Collection of evidence | Implemented |
| A.05.29 | Information security during disruption | Implemented |
| A.05.30 | ICT readiness for business continuity | Implemented |
| A.05.31 | Legal, statutory, regulatory and contractual requirements | Implemented |
| A.05.32 | Intellectual property rights | Implemented |
| A.05.33 | Protection of records | Implemented |
| A.05.34 | Privacy and protection of personal identifiable information (PII) | Implemented |
| A.05.35 | Independent review of information security | Implemented |
| A.05.36 | Compliance with policies, rules and standards for information security | Implemented |
| A.05.37 | Documented operating procedures | Implemented |
| A.06.00 | A.6 Organisational Controls | — |
| A.06.01 | Screening | Implemented |
| A.06.02 | Terms and conditions of employment | Implemented |
| A.06.03 | Information security awareness, education and training | Implemented |
| A.06.04 | Disciplinary process | Implemented |
| A.06.05 | Responsibilities after termination or change of employment | Implemented |
| A.06.06 | Confidentiality or non-disclosure agreements | Implemented |
| A.06.07 | Remote working | Implemented |
| A.06.08 | Information security event reporting | Implemented |
| A.07.00 | A.7 Physical Controls | — |
| A.07.01 | Physical security perimeters | N/A |
| A.07.02 | Physical entry | N/A |
| A.07.03 | Securing offices, rooms and facilities | N/A |
| A.07.04 | Physical security monitoring | N/A |
| A.07.05 | Protecting against physical and environmental threats | N/A |
| A.07.06 | Working in secure areas | N/A |
| A.07.07 | Clear desk and clear screen | Implemented |
| A.07.08 | Equipment siting and protection | N/A |
| A.07.09 | Security of assets off-premises | Implemented |
| A.07.10 | Storage media | Implemented |
| A.07.11 | Supporting utilities | N/A |
| A.07.12 | Cabling security | N/A |
| A.07.13 | Equipment maintenance | Implemented |
| A.07.14 | Secure disposal or re-use of equipment | Implemented |
| A.08.00 | A.8 Technological Controls | — |
| A.08.01 | User end point devices | Implemented |
| A.08.02 | Privileged access rights | Implemented |
| A.08.03 | Information access restriction | Implemented |
| A.08.04 | Access to source code | Implemented |
| A.08.05 | Secure authentication | Implemented |
| A.08.06 | Capacity management | Implemented |
| A.08.07 | Protection against malware | Implemented |
| A.08.08 | Management of technical vulnerabilities | Implemented |
| A.08.09 | Configuration management | Implemented |
| A.08.10 | Information deletion | Implemented |
| A.08.11 | Data masking | N/A |
| A.08.12 | Data leakage prevention | Implemented |
| A.08.13 | Information backup | Implemented |
| A.08.14 | Redundancy of information processing facilities | Implemented |
| A.08.15 | Logging | Implemented |
| A.08.16 | Monitoring activities | Implemented |
| A.08.17 | Clock synchronization | Implemented |
| A.08.18 | Use of privileged utility programs | Implemented |
| A.08.19 | Installation of software on operational systems | Implemented |
| A.08.20 | Networks security | Implemented |
| A.08.21 | Security of network services | Implemented |
| A.08.22 | Segregation of networks | Implemented |
| A.08.23 | Web filtering | Implemented |
| A.08.24 | Use of cryptography | Implemented |
| A.08.25 | Secure development life cycle | Implemented |
| A.08.26 | Application security requirements | Implemented |
| A.08.27 | Secure system architecture and engineering principles | Implemented |
| A.08.28 | Secure coding | Implemented |
| A.08.29 | Security testing in development and acceptance | Implemented |
| A.08.30 | Outsourced development | N/A |
| A.08.31 | Separation of development, test and production environments | Implemented |
| A.08.32 | Change management | Implemented |
| A.08.33 | Test information | Implemented |
| A.08.34 | Protection of information systems during audit testing | Implemented |