A.5.1Policies for information security
You have security rules written down, signed off by whoever runs the business, and your team has actually seen them.
A set of security policies exists in writing, is owned and approved at the top of the organisation, reaches the people expected to follow it, and is revisited on a schedule rather than left to age.
A.5.2Information security roles and responsibilities
Every part of security has a name against it, so nothing sits in the gap between two people who each assumed the other had it.
Each part of the security effort is allocated to a role, so that asset ownership, risk work, incident leadership and policy upkeep each have somebody accountable rather than falling between people.
A.5.3Segregation of duties
No one person can start and finish a sensitive job alone, so a mistake or a misuse is seen by somebody else along the way.
Duties that conflict with one another are held by different people, so that no individual can both carry out a damaging action and conceal it.
A.5.4Management responsibilities
Whoever leads the business expects the security rules to be followed and makes that clear, rather than leaving it to good intentions.
Management actively expects everyone to work to the security rules and says so, rather than publishing the rules and hoping. Without this the whole policy set is advisory in practice.
A.5.5Contact with authorities
You know who to call at the regulator or the police if something serious happens, and you worked that out before you needed it.
The organisation works out in advance which outside authorities it might need - a regulator, law enforcement, a national cyber body - and keeps a route to them that works under pressure.
A.5.6Contact with special interest groups
You have a way of hearing what others in your line of work are seeing, rather than only finding out when it happens to you.
Links are kept with security forums, industry bodies or professional groups, so the organisation hears about threats and practice from outside its own four walls.
A.5.7Threat intelligence
You gather information about the attacks hitting businesses like yours, and you change something because of it rather than just reading it.
Information about who is attacking organisations like this one, and how, is collected, judged for relevance and turned into a decision. Intelligence nobody acts on does not satisfy this.
A.5.8Information security in project management
Security gets considered at the start of a project, not in the week before launch when changing anything is expensive.
Security questions are asked inside projects of every kind from the start, at the point when the answers are still cheap to act on.
A.5.9Inventory of information and other associated assets
You have a list of the information you hold and the kit and services it sits on, and each entry has an owner's name against it.
A maintained record of the information the organisation holds and the things that carry it - hardware, software, services, facilities - with an owner recorded against each entry.
A.5.10Acceptable use of information and other associated assets
Your team knows what they may and may not do with company information, devices and accounts, because you put it in writing.
Rules say what people may and may not do with the organisation's information, devices and accounts, and everyone who handles them has been told what those rules are.
A.5.11Return of assets
When someone leaves or moves on, the laptop, phone, keys and documents come back, and you can say what is still out there.
Everything issued to a person comes back when their employment, contract or arrangement ends or changes - devices, media, credentials, documents, keys.
A.5.12Classification of information
You sort your information by how sensitive it is, so the things that would really hurt you get more protection than the rest.
Information is graded by what it would cost the organisation if it leaked, was altered, or became unavailable, so that protection can be matched to value instead of applied evenly.
A.5.13Labelling of information
Sensitive files, emails and printouts carry a marking, so nobody has to guess how carefully to treat what is in front of them.
The grading travels with the information as a visible marking, so that anyone who receives a file, an email or a printout can see how careful to be with it.
A.5.14Information transfer
You have rules for sending information out, whether by email, chat, post or a USB stick, and for what may be discussed where.
Rules and, where another organisation is involved, agreements govern how information moves - electronically, on physical media, on paper, and in conversation.
A.5.15Access control
You have decided who may reach what, based on what their job needs, and your systems apply that decision rather than trusting habit.
Rules decide who may reach which information and services, physically and in software, based on what the work genuinely needs and how sensitive the thing being reached is.
A.5.16Identity management
Every person, service and device using your systems has its own identity, set up on purpose and removed when it is finished with.
Identities - for people, and for the services and devices that act on their own - are created deliberately, kept accurate while they are in use, and removed once they are no longer needed.
A.5.17Authentication information
Passwords and keys are handed out, stored and changed carefully, and your team knows not to share or reuse them.
The secrets that prove identity - passwords, keys, tokens - are issued, stored, handed over and replaced under control, and the people holding them have been told how to look after them.
A.5.18Access rights
Access is granted on approval, looked over from time to time, and taken away promptly when a job changes or somebody leaves.
Access is granted, reviewed, adjusted and withdrawn across the whole time a person holds it, following the organisation's own access rules rather than case by case.
A.5.19Information security in supplier relationships
You have a way of judging the security risk each supplier brings, because giving them the work does not give them the responsibility.
There is a defined way of identifying and managing the security risk that comes with using a supplier's products or services, because handing out the work does not hand out the risk.
A.5.20Addressing information security within supplier agreements
What you expect a supplier to do about security is written into the contract, so you could point at it if they fell short.
What the organisation expects of a supplier on security is written into the agreement with them, which is what makes it enforceable rather than assumed.
A.5.21Managing information security in the ICT supply chain
You have thought about who supplies your suppliers, because a weakness several steps back still arrives on your systems.
The security risk carried by the chain behind a technology product or service is managed, including the suppliers and components your own suppliers depend on.
A.5.22Monitoring, review and change management of supplier services
You check suppliers are doing what they promised, and when one changes how their service works you look at what that changes for you.
Supplier delivery is checked against what was agreed, and a change the supplier makes to how their service works is treated as a change to yours rather than quietly absorbed.
A.5.23Information security for use of cloud services
You know which parts of security your cloud providers handle and which stay with you, and you know how you would get your data back out.
Cloud services are chosen, used and eventually left under rules the organisation has set, with a clear understanding of which security duties the provider takes and which stay behind.
A.5.24Information security incident management planning and preparation
You decided in advance who does what during a security incident, so the first ten minutes are not spent working out who to call.
Before anything happens, the organisation settles how incidents will be handled - the process, who plays which part, and how decisions get made - and tells the people involved.
A.5.25Assessment and decision on information security events
Somebody looks at each reported problem and decides whether it counts as a real incident, rather than leaving it an open question.
Each reported event is assessed and a recorded decision is made about whether it counts as a security incident, so nothing stays permanently ambiguous.
A.5.26Response to information security incidents
When something is confirmed as an incident you follow the plan you wrote, and you write down what you actually did.
Confirmed incidents are handled by following the procedures the organisation wrote, and what was actually done is recorded as it happens.
A.5.27Learning from information security incidents
After an incident you change something, so the same gap does not let the same thing happen again next quarter.
What an incident revealed is fed back into the controls, so that the same weakness does not produce the same incident again.
A.5.28Collection of evidence
You know how to preserve logs and devices after an incident, because the normal rush to clean up destroys what an investigation needs.
There is a way of identifying, gathering and preserving evidence about an incident in a form that would still be worth something to an investigator, an insurer or a court later on.
A.5.29Information security during disruption
Your security does not fall away during a crisis. You planned how to keep it up while running on backup arrangements.
Security is held at a planned level while the organisation is disrupted, instead of being the first thing dropped in the effort to keep trading.
A.5.30ICT readiness for business continuity
You worked out how fast each system has to come back, and you have tested that your technology can really meet that.
Technology recovery is planned, built and tested against recovery times the business has actually agreed, rather than against whatever the technology happens to manage.
A.5.31Legal, statutory, regulatory and contractual requirements
You know which laws and contract terms apply to the information you hold, and you can say how you meet each one.
The legal, regulatory and contractual obligations bearing on information security are identified, kept current, and matched to how each one is met.
A.5.32Intellectual property rights
You use software you are actually licensed for, and you protect your own material from being taken.
Intellectual property is protected in both directions: the organisation's own material, and other people's - software licensing being where this most often bites.
A.5.33Protection of records
Records you have to keep are protected from being lost, altered or seen by the wrong people for the whole time you keep them.
Records are protected from loss, destruction, falsification and unauthorised access or release, for the whole period the organisation is required to keep them.
A.5.34Privacy and protection of PII
You know what personal information you hold about people, and what the law where you operate requires you to do with it.
The organisation identifies what it owes to the people whose personal information it holds under the law and contracts that apply to it, and meets those obligations.
A.5.35Independent review of information security
Somebody who does not run your security looks it over now and then, because it is hard to spot the gaps in your own arrangements.
The organisation's security arrangements are reviewed by someone independent of the work being reviewed, on a planned schedule and after significant change.
A.5.36Compliance with policies, rules and standards for information security
You check that your written rules are the ones people really follow, rather than assuming the policy and the practice still match.
The organisation regularly checks that its own written rules are the rules being followed in practice, rather than assuming policy and behaviour still match.
A.5.37Documented operating procedures
The routine tasks that keep your systems running are written down, so they do not live only in one person's head.
The procedures for running the systems that process information are written down and available to the people who have to run them.