Back to templates
    Template

    Control catalogue

    A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.

    Governance5 Sept 20263 min read

    ISO/IEC 27001:2022ISO/IEC 27002:2022
    On this page
    Download the template

    control-catalogue.xlsx · 10 kBLicensed CC BY 4.0

    What this is

    A register of the controls the organisation operates: one row per control, four sheets. Section 3.2 of Control ownership and the control catalogue produces it, and it answers three questions about any control. Who owns it, what record it leaves, when it was last tested. Annex A of ISO/IEC 27001:2022 is titled Information security controls reference 1 — the comparison set, not the list controls are run from.

    How to use it

    1. Fix the unit first. A control has an operator, a cadence and an output; a framework line has none. See the playbook, section 3.1.
    2. Delete the nine example rows across the three working sheets.
    3. Write one Controls row per operation actually run, then map upward to reference controls, Subcategories and obligations. See the playbook, section 3.2.
    4. Fill owner, evidence producer and approver first. All three are roles. Responsibilities are defined and allocated to the organisation's needs, with authorisation levels documented 2.
    5. Set control type from the attribute value printed against the reference control. Organisations may disregard the other attributes or add their own 3.
    6. Fill Obligation(s) served from the obligations or risk register, never from a framework index. An empty cell is a retirement candidate.
    7. Fill the Evidence schedule sheet from the control IDs. Clause 7.5 covers documented information, and 7.5.3 is Control of documented information 4.
    8. Give every control a test whose tester is not its owner. Compliance with the policy set, rules and standards is reviewed regularly, and results recorded 5.

    What good looks like

    Six of the sixteen Controls columns, from the workbook's rows.

    IDControl (what runs)Owner (role)ISO/IEC 27002:2022 control(s)Control typeResult
    CTL-001Quarterly restore test from backupPlatform engineering lead8.13 Information backup3. Corrective1. Pass
    CTL-002Monthly vulnerability scan and patch cyclePlatform engineering lead8.8 Management of technical vulnerabilities1. Preventive2. Fail
    CTL-003Quarterly access-rights review, payment platformPayments service owner5.18 Access rights1. Preventive3. Not tested

    Fields

    FieldRequiredMeaningCommon mistake
    Control (what runs)yesThe operation, with an operator and a cadenceCopying a reference control title
    ObjectiveyesWhat the control is for, in one sentenceRestating the control name
    Owner, producer, approveryesWho answers, who records, whose decision bindsA person, or one role in all three
    Obligation(s) servedyesThe instrument, article or risk decision behind itA framework number, explaining nothing
    Control typeyes1. Preventive, 2. Detective or 3. CorrectiveA value the test was not written against
    Evidence record, RetentionyesThe record produced, and how long it is kept"Ticket", with no location
    Last test, ResultyesWhen last tested, and what came backA dashboard shown as a test result
    Statusyes1. Operating, 2. Planned or 3. RetiredRetired controls left as operating

    Download

    • File: control-catalogue.xlsx (xlsx, 10 KB) — sheets Read first, Controls, Evidence schedule, Test plan.
    • Markdown variant: the same tables as _control-catalogue.md, beside the workbook.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names; the example rows are invented.

    References

    1. ISO/IEC. Information security controls. ISO/IEC 27002:2022. Clause 4.2 and controls 5.2, 5.18, 5.36, 8.8 and 8.13 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 6
    2. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles and Annex A read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 7

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC or any other standards body.

    Sources

    1. 1ISO/IEC 27001:2022 Annex A, iso.org/obp · verified 2026-09-03
    2. 2ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
    3. 3ISO/IEC 27002:2022 clause 4.2, licensed copy · verified 2026-09-05
    4. 4ISO/IEC 27001:2022 clause 7.5, iso.org/obp · verified 2026-09-03
    5. 5ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
    6. 6ISO/IEC 27002:2022 clause 4.2 and controls 5.2 to 8.13, licensed copy · verified 2026-09-05
    7. 7ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03