Skip to content
atlas

Organisational control

Also known as: organizational control, administrative control

A safeguard made of rules, roles and routines - who decides, who does what, and how work must be done.

Draft - this entry has not been reviewed yet.

Formal

A security control carried out through policies, processes, responsibilities and agreements - such as supplier management, access approval or an incident process - one of the four control themes in ISO 27002.

In plain English

Like the plan for a school trip - the teacher counts heads at every stop, children walk in pairs, and nobody leaves the group without telling an adult. No fence is needed.

In practice

A housing association writes down that a new user account needs the head of department's approval and that HR tells the IT department the same day someone leaves.

Why it matters

It is the largest group of controls in ISO 27002, and without clear rules and owners even good technology is set up and used at random.

Technical deep dive

ISO/IEC 27002:2022 restructured its control set into four themes: organisational (clause 5, 37 controls), people (clause 6, 8 controls), physical (clause 7, 14 controls) and technological (clause 8, 34 controls), 93 in total, mirrored one-to-one in Annex A of ISO/IEC 27001:2022. The organisational theme is a residual category in the sense that it holds every control that is not primarily about individuals, premises or technology: information security policies (5.1), roles and responsibilities (5.2), segregation of duties (5.3), management responsibilities (5.4), threat intelligence (5.7, new in 2022), asset inventory and acceptable use (5.9-5.11), classification and labelling (5.12-5.13), access control and identity management (5.15-5.18), the supplier and cloud chain (5.19-5.23), incident management (5.24-5.28), security during disruption and ICT readiness for business continuity (5.29-5.30), legal, privacy and policy compliance with independent review (5.31-5.36) and documented operating procedures (5.37).

The theme describes where a control is implemented, not how it acts. ISO 27002:2022 adds attributes as a separate axis - control type (preventive, detective, corrective), information security properties, cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities and security domains - so an organisational control can be detective (an access review) or corrective (an incident process). The older triad of administrative, technical and physical controls, still common in US literature and in the HIPAA Security Rule's administrative, physical and technical safeguards, maps roughly but not exactly: "administrative" covers both ISO's organisational and people themes.

In European law the same idea appears as "technical and organisational measures" (TOMs), required by GDPR Art. 32 and Art. 25 and by NIS2 Art. 21(1), which speaks of "appropriate and proportionate technical, operational and organisational measures". Data processing agreements (databehandleraftaler) under GDPR Art. 28 usually include an annex listing the processor's TOMs, which the controller must be able to show are adequate if Datatilsynet or another supervisory authority asks.

The characteristic weakness of organisational controls is the gap between design and operation. A policy that exists but is not followed, a supplier-assessment procedure that is never triggered, or an approval workflow that is routinely bypassed looks compliant on paper. Auditors therefore test both design effectiveness (would the control address the risk if followed?) and operating effectiveness over a period, for example in ISAE 3402 type 2 or SOC 2 type II reports, by sampling evidence such as signed approvals, review records and meeting minutes. Organisational controls are strongest when they are backed by technical enforcement - an access request workflow that is the only way to obtain a role, for example - rather than relying on people remembering the rule.

What to learn first

Everything this builds on, foundations first.

  1. Governance
  2. →Organisational control

Relationships

Requires
Governance

Sources & further reading

Standards & official texts

  • ISO/IEC 27002:2022 (clause 5 - Organizational controls)

Course material

  • Cyber Security Fast Track - Kursuskompendium, Modul 1 og Ordliste (Kontrol)

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.