Formal controls are required to protect against phishing, spoofing and malicious email content
Sekit's Email security policy, one of the topic-specific policies A.5.1 expects, requires protection against spoofing and malicious content plus a clear path for staff to report suspicious messages.
Email is one of A.5.14's named transfer channels; protecting it against spoofing and malicious content, with a clear reporting path, covers that channel specifically.