Back to Columns
ISMS & Certification13 min read

Reading the 37 Organizational Controls

September 14, 2026

Reading the 37 Organizational Controls
Share this article

The organizational controls are the largest of Annex A's four themes, at 37 items — roughly 40% of the 93, and the centre of gravity of an ISMS project. They are also the set that can only be satisfied with documents and operating practice, never with a product. Leave them late and you will mass-produce procedures in the weeks before audit, ending up with a stack of paper that does not match how you work.

Equally, reading all 37 one by one and filling in a mapping table is not the way. The controls are not 37 independent tasks; they cluster, and each cluster has a fairly predictable output. Grouped, the 37 converge on about eight document sets.

This article groups A.5 into eight clusters: what each asks for, what you produce, and where it bites for a healthcare business. For the overall map see Annex A 2022: 93 Controls Across Four Themes.

Disclaimer: This article is general information. Control titles and requirement text live in the standard. We do not quote them; we describe the intent in our own words. Base decisions on ISO/IEC 27001 (JIS Q 27001) and the publications of the accreditation and certification bodies.

Eight Clusters Cover the 37

ClusterWhat it is forMain outputs
① Policy and governanceFix who decides what, and who is accountableSecurity policy, subordinate procedures, org chart, role assignments
② Assets and classificationIdentify what must be protected and how it is handled by sensitivityAsset register, classification and labelling rules, acceptable use, return of assets
③ Access policyDefine, at policy level, who may access whatAccess control policy, identity lifecycle, provisioning and review records
④ Suppliers and cloudSecure the parts you have handed to othersSupplier management procedure, assessment sheets, contract clauses, supplier list
⑤ Threat intelligence and external contactsKeep taking in what is happening outsideIntelligence collection routine, contact list, memberships
⑥ Incident managementDo not stop when something happens, and learn from itResponse plan, reporting flow, evidence handling, incident log
⑦ ContinuityKeep the business running, seen from securityBCP, ICT continuity requirements and test records, recovery objectives
⑧ Compliance and reviewIdentify external obligations and verify you meet themLegal and contractual register, records protection, independent review records

Get those eight document sets right and A.5 is substantially covered. Put differently: you do not need 37 documents for 37 controls. The relationship is many-to-many, and one procedure routinely satisfies five or six controls.

The Foundations: Policy, Assets, Access

① Policy and governance

What is required is that the organisation's security decisions exist as approved documents, and that responsibility for them is assigned. That runs through policy, the relationship to subordinate procedures, periodic review, role allocation, and segregation of duties.

In practice you build a top-level information security policy with a set of procedures beneath it. What matters is not how many documents there are but that they match reality. Take a template as-is and you end up asserting that you retain entry logs for an office you do not have.

Segregation of duties gets hard in small teams; that is covered in Reading the 8 People Controls.

② Assets and classification

This cluster converges on one artefact: the information asset register. You identify the information and facilities to protect, assign an owner to each, classify by sensitivity, and define handling rules for that classification — storage, transfer, removal, return.

For healthcare the leverage is in the classification design. Treating every patient-derived record as top secret paralyses test data use in development and over-restricts aggregated anonymised data. At minimum, separate:

  • Identifiable medical information (including special-care-required personal information)
  • Pseudonymised and anonymised medical information
  • Customer (hospital) operational and configuration data
  • Your own commercial and technical information
  • Public information

See Building the Information Asset Register.

③ Access policy

The access-related controls in A.5 are policy level. Implementation — privileged IDs, MFA, endpoint control — lives in A.8. Here the standard wants the need-to-know principle, the identity lifecycle (issue, change, revoke), management of authentication information, and periodic review of rights.

Auditors press hardest on that last point. Provisioning records exist; review records do not. Leaver accounts still active, and rights retained after an internal move, are perennial nonconformities. Quarterly is enough — but the review must leave a record, and that should be built in from the start.

See Reading the 34 Technological Controls and Access Rights Design and Privileged ID Management.

External Relationships: Suppliers, Cloud, Threat Intelligence

④ Suppliers and cloud services

The 2022 edition makes use of cloud services an explicit control — a change that lands directly on healthcare SaaS. If you deliver on cloud, your IaaS/PaaS providers are suppliers, and their selection, contracting, monitoring, and exit all fall in scope.

The flow required is roughly:

  1. Set a policy for entrusting information to suppliers
  2. Write security requirements into contracts
  3. Extend visibility into the ICT supply chain — your suppliers' suppliers
  4. Monitor and review supplier service delivery over time
  5. Define procedures for change and termination

Step 3 is where healthcare companies struggle. To a hospital, you are the supplier and your cloud is a sub-processor. Hospitals working to the three-ministry guidelines will ask about that layer, so a single diagram showing who manages what pays for itself in sales conversations.

See Shared Responsibility in AI EMR Security Design, Cloud Security for Medical Institutions, and Supplier Security Management.

⑤ Threat intelligence and external contacts

Threat intelligence was added in 2022. It does not mean buying a feed. It means taking in threat information relevant to you, continuously, and using it in decisions.

For a small organisation, this is enough to operate:

  • Subscribe to JPCERT/CC and IPA advisories; a named person reviews them weekly
  • Subscribe to advisories for the cloud services and open-source components you use
  • Record what was reviewed and whether action was required

The record is the point. "We keep an eye on it" does not survive audit. A one-page monthly "threats seen and action taken" note satisfies this control and feeds continuity and incident management at the same time.

For contact with authorities, a list of who you notify — regulator, JPCERT/CC, the Personal Information Protection Commission, your hospital customers — is sufficient. The intent is that you are not looking it up mid-incident.

When It Happens, and What You Must Comply With

⑥ Incident management

Five to six controls cluster here, making it the densest part of A.5. The required flow is plan → report → assess and classify → respond → learn → collect evidence. Assessment/classification and learning are the ones most often missing.

StageRequirementOutput
PlanRoles, escalation paths, decision criteria agreed in advanceResponse plan, contact tree
ReportStaff have a route to report eventsReporting form and procedure
Assess and classifyEvent or incident? How is severity set?Classification criteria, triage sheet
RespondContain and recover by the agreed procedureResponse records, customer and regulator notifications
LearnFeed back into preventionPost-incident review, corrective action reports
EvidencePreserve in a form that survives legal processEvidence handling procedure and records

For medical information, notification timing and content are usually fixed by contract with the hospital, so those terms belong in the plan. Committing to a first report within four hours while the internal contact tree does not function at night or on holidays is a design failure that genuinely happens.

See Building an Incident Response Procedure and Incident Response Plans for Hospitals.

⑦ Continuity

This covers business continuity seen through security, plus ICT continuity — recovery objectives, redundancy, testing. The key point: if you already have a BCP, reference it rather than writing a new one for the ISMS.

For healthcare SaaS, what gets tested is whether recovery objectives are real. Declaring a four-hour RTO while never having restored from backup is a nonconformity. Run a recovery test once a year and keep the record — it also doubles as sales evidence for hospitals. See Connecting BCP and ISMS.

⑧ Compliance and review

The final cluster: identifying legal, regulatory, and contractual requirements; intellectual property; protection of records; privacy; independent review of information security; and verifying conformance with your own policies and procedures.

A healthcare company's register of external obligations is longer than most: the personal information law and its special-care category, requirements around the Medical Care Act and Medical Practitioners Act, the Next-Generation Medical Infrastructure Act where relevant, the PMD Act for SaMD, and contractual commitments to the three-ministry guidelines. The practical work is a table mapping each obligation to the internal procedure that addresses it.

Independent review is largely satisfied by internal audit, provided auditors do not audit their own work — which is why external auditors are a realistic answer for small teams.

Conclusion

  1. The 37 controls group into eight clusters producing about eight document sets — not 37 documents
  2. The foundations are policy, asset register, access policy; everything above them wobbles if these do
  3. Do not classify all medical information as top secret — separating pseudonymised and anonymised data lightens operations
  4. The explicit cloud services control means producing a diagram that reaches your sub-processors
  5. Threat intelligence must leave a one-page monthly record, not a claim of vigilance
  6. Incident management loses "assess and classify" and "learn"; derive notification terms from your contracts
  7. Access review records, recovery test records, independent review records — a control with no record looks like a control you do not operate

Pottech supports ISMS certification with a focus on healthcare. Organizational controls carry the heaviest documentation load, but we supply templates for procedures, registers, and assessment sheets and tailor them to how your business actually works. We can also act as your internal audit manager and auditors, satisfying the independent review requirement.

See ISMS Certification Support for scope and pricing, or contact us.

See also What Is an ISMS? A Complete Guide for Healthcare Companies and Writing the Statement of Applicability.

References and Sources

Note: interpretation of controls and the acceptability of exclusions can change with revisions to the standard and the practices of certification bodies.

Share this article

Related Articles

ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
ISMS & Certification

Reading the 34 Technological Controls

The 34 technological controls of Annex A.8 in six clusters: access control and authentication, vulnerabilities and configuration, the data protection lifecycle, logging and monitoring, networks, and secure development — written in the context of building and operating healthcare SaaS.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.