- 5.01 - Policies for Information Security - OnePager
- 5.02 - Information security roles and responsibilities - OnePager
- 5.03 - Segregation of duties - OnePager
- 5.04 - Management responsibilities - OnePager
- 5.05 - Contact with authorities - OnePager
- 5.06 - Contact with special interest groups - OnePager
- 5.07 - Threat Intelligence - OnePager
- 5.08 - Information security in project management - OnePager
- 5.09 - Inventory of information and other associated assets - OnePager
- 5.10 - Acceptable use of information and other associated assets - OnePager
- 5.11 - Return of assets - OnePager
- 5.12 - Classification of information - OnePager
- 5.13 - Labelling of information - OnePager
- 5.14 - Information transfer - OnePager
- 5.15 - Access control - OnePager
- 5.16 - Identity management - OnePager
- 5.17 - Authentication information - OnePager
- 5.18 - Access rights - OnePager
- 5.19 - Information security in supplier relationships - OnePager