| A.5 Organisational Controls | 2026-07-05 | Director |
| A.05.01 - Policies for information security | 2026-07-05 | Director |
| A.05.02 - Information security roles and responsibilities | 2026-07-05 | Director |
| A.05.03 - Segregation of duties | 2026-07-05 | Director |
| A.05.04 - Management responsibilities | 2026-07-05 | Director |
| A.05.05 - Contact with authorities | 2026-07-05 | Business Manager |
| A.05.06 - Contact with special interest groups | 2026-07-05 | Director |
| A.05.07 - Threat intelligence | 2026-07-05 | Director |
| A.05.08 - Information security in project management | 2026-07-05 | Director |
| A.05.09 - Inventory of information and other associated assets | 2026-07-05 | Operations Manager |
| A.05.10 - Acceptable use of information and other associated assets | 2026-07-05 | Business Manager |
| A.05.11 - Return of assets | 2026-07-05 | Business Manager |
| A.05.12 - Classification of information | 2026-07-05 | Director |
| A.05.13 - Labelling of information | 2026-07-05 | Director |
| A.05.14 - Information transfer | 2026-07-05 | Director |
| A.05.15 - Access control | 2026-07-05 | Director |
| A.05.16 - Identity management | 2026-07-05 | Operations Manager |
| A.05.17 - Authentication information | 2026-07-05 | Operations Manager |
| A.05.18 - Access rights | 2026-07-05 | Operations Manager |
| A.05.19 - Information security in supplier relationships | 2026-07-05 | Business Manager |
| A.05.20 - Addressing information security within supplier agreements | 2026-07-05 | Business Manager |
| A.05.21 - Managing information security in the information and communication technology (ICT) supply chain | 2026-07-05 | Business Manager |
| A.05.22 - Monitoring, review and change management of supplier services | 2026-07-05 | Business Manager |
| A.05.23 - Information security for use of cloud services | 2026-07-05 | Operations Manager |
| A.05.24 - Information security incident management planning and preparation | 2026-07-05 | Director |
| A.05.25 - Assessment and decision on information security events | 2026-07-05 | Director |
| A.05.26 - Response to information security incidents | 2026-06-22 | Director |
| A.05.27 - Learning from information security incidents | 2026-07-05 | Director |
| A.05.28 - Collection of evidence | 2026-07-05 | Operations Manager |
| A.05.29 - Information security during disruption | 2026-07-05 | Operations Manager |
| A.05.30 - ICT readiness for business continuity | 2026-07-05 | Operations Manager |
| A.05.31 - Legal, statutory, regulatory and contractual requirements | 2026-07-05 | Business Manager |
| A.05.32 - Intellectual property rights | 2026-07-05 | Business Manager |
| A.05.33 - Protection of records | 2026-07-05 | Business Manager |
| A.05.34 - Privacy and protection of personal identifiable information (PII) | 2026-07-05 | Business Manager |
| A.05.35 - Independent review of information security | 2026-07-05 | Director |
| A.05.36 - Compliance with policies, rules and standards for information security | 2026-07-05 | Director |
| A.05.37 - Documented operating procedures | 2026-07-05 | Operations Manager |
| A.6 Organisational Controls | 2026-07-05 | Director |
| A.06.01 - Screening | 2026-07-05 | Business Manager |
| A.06.02 - Terms and conditions of employment | 2026-07-05 | Business Manager |
| A.06.03 - Information security awareness, education and training | 2026-07-05 | Director |
| A.06.04 - Disciplinary process | 2026-07-05 | Business Manager |
| A.06.05 - Responsibilities after termination or change of employment | 2026-07-05 | Business Manager |
| A.06.06 - Confidentiality or non-disclosure agreements | 2026-07-05 | Business Manager |
| A.06.07 - Remote working | 2026-07-05 | Operations Manager |
| A.06.08 - Information security event reporting | 2026-07-05 | Operations Manager |
| A.7 Physical Controls | 2026-07-05 | Director |
| A.07.01 - Physical security perimeters | 2026-07-05 | Operations Manager |
| A.07.02 - Physical entry | 2026-07-05 | Operations Manager |
| A.07.03 - Securing offices, rooms and facilities | 2026-07-05 | Operations Manager |
| A.07.04 - Physical security monitoring | 2026-07-05 | Operations Manager |
| A.07.05 - Protecting against physical and environmental threats | 2026-07-05 | Operations Manager |
| A.07.06 - Working in secure areas | 2026-07-05 | Operations Manager |
| A.07.07 - Clear desk and clear screen | 2026-07-05 | Director |
| A.07.08 - Equipment siting and protection | 2026-07-05 | Operations Manager |
| A.07.09 - Security of assets off-premises | 2026-07-05 | Operations Manager |
| A.07.10 - Storage media | 2026-07-05 | Operations Manager |
| A.07.11 - Supporting utilities | 2026-07-05 | Operations Manager |
| A.07.12 - Cabling security | 2026-07-05 | Operations Manager |
| A.07.13 - Equipment maintenance | 2026-07-05 | Operations Manager |
| A.07.14 - Secure disposal or re-use of equipment | 2026-07-05 | Operations Manager |
| A.8 Technological Controls | 2026-07-05 | Director |
| A.08.01 - User end point devices | 2026-07-05 | Operations Manager |
| A.08.02 - Privileged access rights | 2026-07-05 | Director |
| A.08.03 - Information access restriction | 2026-07-05 | Director |
| A.08.04 - Access to source code | 2026-07-05 | Solution Architect |
| A.08.05 - Secure authentication | 2026-07-05 | Solution Architect |
| A.08.06 - Capacity management | 2026-07-05 | Operations Manager |
| A.08.07 - Protection against malware | 2026-07-05 | Operations Manager |
| A.08.08 - Management of technical vulnerabilities | 2026-07-05 | Director |
| A.08.09 - Configuration management | 2026-07-05 | Operations Manager |
| A.08.10 - Information deletion | 2026-07-05 | Operations Manager |
| A.08.11 - Data masking | 2026-07-05 | Solution Architect |
| A.08.12 - Data leakage prevention | 2026-07-05 | Director |
| A.08.13 - Information backup | 2026-07-05 | Operations Manager |
| A.08.14 - Redundancy of information processing facilities | 2026-07-05 | Solution Architect |
| A.08.15 - Logging | 2026-07-05 | Operations Manager |
| A.08.16 - Monitoring activities | 2026-07-05 | Director |
| A.08.17 - Clock synchronization | 2026-07-05 | Operations Manager |
| A.08.18 - Use of privileged utility programs | 2026-07-05 | Operations Manager |
| A.08.19 - Installation of software on operational systems | 2026-07-05 | Operations Manager |
| A.08.20 - Networks security | 2026-07-05 | Solution Architect |
| A.08.21 - Security of network services | 2026-07-05 | Solution Architect |
| A.08.22 - Segregation of networks | 2026-07-05 | Solution Architect |
| A.08.23 - Web filtering | 2026-07-05 | Solution Architect |
| A.08.24 - Use of cryptography | 2026-07-05 | Solution Architect |
| A.08.25 - Secure development life cycle | 2026-07-05 | Solution Architect |
| A.08.26 - Application security requirements | 2026-07-05 | Solution Architect |
| A.08.27 - Secure system architecture and engineering principles | 2026-07-05 | Solution Architect |
| A.08.28 - Secure coding | 2026-07-05 | Solution Architect |
| A.08.29 - Security testing in development and acceptance | 2026-07-05 | Senior QA Engineer |
| A.08.30 - Outsourced development | 2026-07-05 | Business Manager |
| A.08.31 - Separation of development, test and production environments | 2026-07-05 | Solution Architect |
| A.08.32 - Change management | 2026-07-05 | Operations Manager |
| A.08.33 - Test information | 2026-07-05 | Senior QA Engineer |
| A.08.34 - Protection of information systems during audit testing | 2026-07-05 | Director |
| Controls Overiew | 2026-06-17 | Director |