Control catalogue
A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.
Governance5 Sept 20263 min read
On this page
control-catalogue.xlsx · 10 kBLicensed CC BY 4.0
What this is
A register of the controls the organisation operates: one row per control, four sheets. Section 3.2 of Control ownership and the control catalogue produces it, and it answers three questions about any control. Who owns it, what record it leaves, when it was last tested. Annex A of ISO/IEC 27001:2022 is titled Information security controls reference 1 — the comparison set, not the list controls are run from.
How to use it
- Fix the unit first. A control has an operator, a cadence and an output; a framework line has none. See the playbook, section 3.1.
- Delete the nine example rows across the three working sheets.
- Write one Controls row per operation actually run, then map upward to reference controls, Subcategories and obligations. See the playbook, section 3.2.
- Fill owner, evidence producer and approver first. All three are roles. Responsibilities are defined and allocated to the organisation's needs, with authorisation levels documented 2.
- Set control type from the attribute value printed against the reference control. Organisations may disregard the other attributes or add their own 3.
- Fill Obligation(s) served from the obligations or risk register, never from a framework index. An empty cell is a retirement candidate.
- Fill the Evidence schedule sheet from the control IDs. Clause 7.5 covers documented information, and 7.5.3 is Control of documented information 4.
- Give every control a test whose tester is not its owner. Compliance with the policy set, rules and standards is reviewed regularly, and results recorded 5.
What good looks like
Six of the sixteen Controls columns, from the workbook's rows.
| ID | Control (what runs) | Owner (role) | ISO/IEC 27002:2022 control(s) | Control type | Result |
|---|---|---|---|---|---|
| CTL-001 | Quarterly restore test from backup | Platform engineering lead | 8.13 Information backup | 3. Corrective | 1. Pass |
| CTL-002 | Monthly vulnerability scan and patch cycle | Platform engineering lead | 8.8 Management of technical vulnerabilities | 1. Preventive | 2. Fail |
| CTL-003 | Quarterly access-rights review, payment platform | Payments service owner | 5.18 Access rights | 1. Preventive | 3. Not tested |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Control (what runs) | yes | The operation, with an operator and a cadence | Copying a reference control title |
| Objective | yes | What the control is for, in one sentence | Restating the control name |
| Owner, producer, approver | yes | Who answers, who records, whose decision binds | A person, or one role in all three |
| Obligation(s) served | yes | The instrument, article or risk decision behind it | A framework number, explaining nothing |
| Control type | yes | 1. Preventive, 2. Detective or 3. Corrective | A value the test was not written against |
| Evidence record, Retention | yes | The record produced, and how long it is kept | "Ticket", with no location |
| Last test, Result | yes | When last tested, and what came back | A dashboard shown as a test result |
| Status | yes | 1. Operating, 2. Planned or 3. Retired | Retired controls left as operating |
Download
- File:
control-catalogue.xlsx(xlsx, 10 KB) — sheets Read first, Controls, Evidence schedule, Test plan. - Markdown variant: the same tables as
_control-catalogue.md, beside the workbook. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names; the example rows are invented.
Related
- Playbook: Control ownership and the control catalogue.
- Playbook: Building an ISMS people actually use, source of the Statement of Applicability.
- Playbook: From regulation to controls, which fills the obligation column.
References
- ISO/IEC. Information security controls. ISO/IEC 27002:2022. Clause 4.2 and controls 5.2, 5.18, 5.36, 8.8 and 8.13 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 6
- ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles and Annex A read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 7
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC or any other standards body.
Sources
- 1ISO/IEC 27001:2022 Annex A, iso.org/obp · verified 2026-09-03
- 2ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
- 3ISO/IEC 27002:2022 clause 4.2, licensed copy · verified 2026-09-05
- 4ISO/IEC 27001:2022 clause 7.5, iso.org/obp · verified 2026-09-03
- 5ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
- 6ISO/IEC 27002:2022 clause 4.2 and controls 5.2 to 8.13, licensed copy · verified 2026-09-05
- 7ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03