ISO27001

ISO 27001 Annex A Controls: The Complete Guide to All 93 Controls

ISO 27001 Annex A Controls: The Complete Guide to All 93 Controls
Loading advertisement...
1

Annex A of ISO/IEC 27001:2022 is the standard's control catalogue — a reference list of 93 information security controls that organizations draw on when building their risk treatment plan. It is not a checklist you must implement in full. Instead, Annex A functions as a menu: you select the controls relevant to your risks, justify your selections (and exclusions) in your Statement of Applicability, and implement what applies to your context. This hub organizes every control-focused article on this site so you can navigate the full set by theme, find the specific control guidance you need, and understand how the pieces fit together.

What Is Annex A? 93 Controls, Four Themes

Annex A is structured into four themes, a change introduced in the 2022 revision that replaced the older 14-domain structure from ISO 27001:2013. The four themes are:

  • Organizational controls (5.1–5.37) — 37 controls covering policies, roles, asset management, access control, supplier relationships, incident management, and business continuity.

  • People controls (6.1–6.8) — 8 controls covering screening, employment terms, awareness training, and disciplinary and remote-working expectations.

  • Physical controls (7.1–7.14) — 14 controls covering perimeters, entry control, equipment security, and secure disposal.

  • Technological controls (8.1–8.34) — 34 controls covering endpoints, access management, malware defense, logging, networks, cryptography, and secure development.

Add those up — 37 + 8 + 14 + 34 — and you get the full 93 controls that make up Annex A in ISO/IEC 27001:2022. This is a reduction from the 114 controls in the 2013 version: several controls were merged, some were renamed, and 11 new controls were added to reflect current threats and practices. Each control in Annex A also carries a set of attributes (control type, security properties, cybersecurity concepts, operational capabilities, and security domains) that let you filter and view the same 93 controls through different lenses — but the theme structure is what drives how organizations typically read, document, and audit against the annex.

The 11 New Controls in the 2022 Revision

If you're transitioning from ISO 27001:2013, pay close attention to these controls — they didn't exist in the previous version and require new evidence in your ISMS:

  • 5.7 Threat intelligence

  • 5.23 Information security for use of cloud services

  • 5.30 ICT readiness for business continuity

  • 7.4 Physical security monitoring

  • 8.9 Configuration management

  • 8.10 Information deletion

  • 8.11 Data masking

  • 8.12 Data leakage prevention

  • 8.16 Monitoring activities

  • 8.23 Web filtering

  • 8.28 Secure coding

Organizations certifying for the first time under the 2022 revision need to address all 11. Organizations transitioning from ISO 27001:2013 need a documented plan for closing the gap on each one before their transition deadline.

How to Use Annex A: The Statement of Applicability

Annex A is not implemented mechanically. The standard's Clause 6.1.3 requires you to compare the results of your risk assessment against the full Annex A list, determine which controls are necessary to treat your identified risks, and record the outcome — including justification for both inclusion and exclusion — in your Statement of Applicability (SoA). The SoA is the single document that ties your risk assessment to the 93 controls and becomes the primary reference your certification auditor works from during Stage 1 and Stage 2 audits.

In practice, most organizations end up implementing the large majority of the 93 controls in some form, because most apply broadly to any organization handling information. But the SoA still matters: it documents how each control is implemented (or why it's not applicable), which is what an auditor tests against, not the raw text of Annex A itself.

Each theme below links to its overview article first, followed by the detailed guides covering specific control clusters. Use the overview articles to understand the theme as a whole, then drill into the control-specific articles for implementation detail.

Key resources - Annex A: All 93 Controls at a Glance (Cheat Sheet) — a one-page reference listing every control number, name, and theme. - Statement of Applicability Template — a ready-to-use SoA structure covering all 93 controls with justification columns.

For the full picture of how Annex A fits into the rest of the standard — clauses, risk assessment, certification — see the master guide: ISO 27001: The Complete Guide.


Organizational Controls (5.1–5.37)

The largest theme, Organizational controls, covers the governance backbone of your ISMS: policies, roles and responsibilities, asset management, access control, supplier security, incident management, and business continuity. If your organization is early in implementation, this is usually the theme with the heaviest documentation lift, since many of these controls define the policies and processes that other controls depend on.

Article

Covers

ISO 27001 Annex A Organizational Controls: Complete Overview (5.1–5.37)

Full walkthrough of all 37 organizational controls and how they group together

Information Security Policies: ISO 27001 Control 5.1 Explained

Writing and maintaining the top-level information security policy

Roles and Responsibilities in Information Security: ISO 27001 Controls 5.2–5.4

Assigning security roles, segregating duties, and management responsibilities

Threat Intelligence and ISO 27001: Control 5.7 Implementation Guide

Collecting and using threat intelligence — new in 2022

Information Security in Project Management: ISO 27001 Control 5.8

Embedding security requirements into project delivery

Asset Management Under ISO 27001: Controls 5.9–5.14 Explained

Asset inventory, acceptable use, return of assets, classification, and labeling

Access Control Policy: ISO 27001 Controls 5.15–5.18

Access control policy, identity management, authentication, and access rights

Supplier Relationship Security: ISO 27001 Controls 5.19–5.23

Supplier security, agreements, ICT supply chain, and cloud services

Incident Management Under ISO 27001: Controls 5.24–5.28

Incident response planning, assessment, response, and evidence collection

Business Continuity and ICT Readiness: ISO 27001 Controls 5.29–5.30

Security during disruption and ICT readiness for business continuity

People Controls (6.1–6.8)

People controls are the smallest theme by count but touch every employee, contractor, and third party with access to your information. They cover the employee lifecycle — from pre-hire screening through employment terms, ongoing awareness training, and what happens when someone leaves or breaks the rules.

Article

Covers

ISO 27001 People Controls Overview: Controls 6.1–6.8 Explained

Full walkthrough of all 8 people controls

Screening and Background Checks: ISO 27001 Control 6.1

Pre-employment verification proportionate to role risk

Terms and Conditions of Employment: ISO 27001 Control 6.2

Contractual security responsibilities for staff

Security Awareness, Education, and Training: ISO 27001 Control 6.3

Building and running an ongoing awareness program

Disciplinary Process and Remote Working Security: ISO 27001 Controls 6.4–6.7

Disciplinary process, post-termination duties, and remote/teleworking security

Confidentiality and Non-Disclosure Agreements: ISO 27001 Control 6.6

Drafting and managing NDAs and confidentiality clauses

Information Security Event Reporting: ISO 27001 Control 6.8

Enabling and encouraging staff to report security events

Physical Controls (7.1–7.14)

Physical controls protect the tangible environments where information and equipment live: offices, data centers, secure areas, and the equipment itself. Even organizations that are fully cloud-hosted still need to address most of these controls, since they cover endpoint hardware, workstations, and physical media handling as much as buildings.

Article

Covers

ISO 27001 Physical Controls Overview: Controls 7.1–7.14 Explained

Full walkthrough of all 14 physical controls

Physical Security Perimeters and Entry Controls: ISO 27001 Controls 7.1–7.3

Defining perimeters and controlling physical entry

Securing Offices, Rooms, and Facilities: ISO 27001 Control 7.3

Detailed guidance on securing specific rooms and facilities

Physical Security Monitoring: ISO 27001 Control 7.4

Continuous monitoring of premises — new in 2022

Protecting Against Physical & Environmental Threats and Working in Secure Areas: ISO 27001 Controls 7.5, 7.6

Environmental threat protection and rules for working in secure areas

Clear Desk and Clear Screen Policy: ISO 27001 Control 7.7

Practical clear desk and clear screen requirements

Equipment Security and Maintenance: ISO 27001 Controls 7.8–7.13

Siting, utilities, cabling, maintenance, off-site equipment, and unattended equipment

Secure Disposal or Re-use of Equipment: ISO 27001 Control 7.14

Sanitizing and disposing of equipment securely

Technological Controls (8.1–8.34)

The largest single theme after Organizational, Technological controls cover the security engineering side of the ISMS: endpoints, privileged access, malware defense, vulnerability management, logging, network security, cryptography, and the secure development lifecycle. This is typically where IT and engineering teams carry most of the implementation load.

Article

Covers

ISO 27001 Technological Controls Overview: Controls 8.1–8.34 Explained

Full walkthrough of all 34 technological controls

Endpoint Devices and User Authentication: ISO 27001 Controls 8.1–8.5

User endpoint devices, access rights, information access restriction, and secure authentication

Privileged Access Rights Management: ISO 27001 Control 8.2

Deep dive on managing and restricting privileged accounts

Outsourced Development, Environment Separation & Source Code: ISO 27001 Controls 8.4, 8.30, 8.31

Source code access, outsourced development, and separating dev/test/production

Redundancy and Capacity Management: ISO 27001 Controls 8.6, 8.14

Capacity planning and redundancy of information processing facilities

Protection Against Malware: ISO 27001 Control 8.7

Malware detection, prevention, and recovery controls

Technical Vulnerability Management: ISO 27001 Control 8.8

Identifying, assessing, and remediating technical vulnerabilities

Configuration Management and Backup: ISO 27001 Controls 8.9, 8.13

Secure baseline configuration and backup — 8.9 is new in 2022

Data Protection: ISO 27001 Controls 8.10–8.12 (Information Deletion, Data Masking, DLP)

Information deletion, data masking, and data leakage prevention — all new in 2022

Logging and Monitoring Activities: ISO 27001 Controls 8.15–8.16

Event logging and monitoring activities — 8.16 is new in 2022

Operational Hygiene: ISO 27001 Controls 8.17–8.19 (Clock Sync, Privileged Utilities, Software Installation)

Clock synchronization, use of privileged utility programs, and software installation controls

Network Security Controls: ISO 27001 Controls 8.20–8.23

Network security, segregation, filtering, and web filtering — 8.23 is new in 2022

Use of Cryptography: ISO 27001 Control 8.24

Cryptographic policy, key management, and encryption practices

Secure Development Life Cycle: ISO 27001 Controls 8.25–8.29

Secure coding principles, security requirements, design, testing, and application security testing — includes 8.28, new in 2022

Change Management: ISO 27001 Control 8.32

Controlling changes to information processing facilities and systems

Frequently asked questions

How many controls are in ISO 27001 Annex A?

There are 93 controls in Annex A of ISO/IEC 27001:2022, organized into four themes: Organizational (37), People (8), Physical (14), and Technological (34). This replaced the 114-control, 14-domain structure used in ISO 27001:2013.

Are all 93 Annex A controls mandatory?

No. Annex A is a reference list, not a mandatory checklist. Clause 6.1.3 requires you to select controls based on your risk assessment and document your decisions — including justified exclusions — in your Statement of Applicability. What is mandatory is the process of considering every control against Annex A and recording the outcome, not implementing all 93 regardless of relevance.

What's new in Annex A for ISO 27001:2022?

Eleven controls were added that didn't exist in the 2013 version: 5.7 (threat intelligence), 5.23 (cloud services security), 5.30 (ICT readiness for business continuity), 7.4 (physical security monitoring), 8.9 (configuration management), 8.10 (information deletion), 8.11 (data masking), 8.12 (data leakage prevention), 8.16 (monitoring activities), 8.23 (web filtering), and 8.28 (secure coding). The overall control count also dropped from 114 to 93 through consolidation of overlapping controls.

What's the difference between Annex A controls and the main clauses (4–10)?

Clauses 4–10 define the mandatory requirements for building, running, and improving your ISMS — context, leadership, planning, support, operation, evaluation, and improvement. Annex A is a separate, referenced catalogue of security controls you draw from when treating the risks identified under Clause 6. You cannot pass certification by implementing Annex A controls alone; you also need to satisfy Clauses 4–10, and vice versa.

Do I need to implement controls in the exact order Annex A lists them?

No. Annex A's numbering is a reference structure, not an implementation sequence. Most organizations tackle organizational controls first (since policies and roles underpin everything else), then layer in people, physical, and technological controls based on which risks their risk assessment ranks highest.

1

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!