Annex A of ISO/IEC 27001:2022 is the standard's control catalogue — a reference list of 93 information security controls that organizations draw on when building their risk treatment plan. It is not a checklist you must implement in full. Instead, Annex A functions as a menu: you select the controls relevant to your risks, justify your selections (and exclusions) in your Statement of Applicability, and implement what applies to your context. This hub organizes every control-focused article on this site so you can navigate the full set by theme, find the specific control guidance you need, and understand how the pieces fit together.
What Is Annex A? 93 Controls, Four Themes
Annex A is structured into four themes, a change introduced in the 2022 revision that replaced the older 14-domain structure from ISO 27001:2013. The four themes are:
Organizational controls (5.1–5.37) — 37 controls covering policies, roles, asset management, access control, supplier relationships, incident management, and business continuity.
People controls (6.1–6.8) — 8 controls covering screening, employment terms, awareness training, and disciplinary and remote-working expectations.
Physical controls (7.1–7.14) — 14 controls covering perimeters, entry control, equipment security, and secure disposal.
Technological controls (8.1–8.34) — 34 controls covering endpoints, access management, malware defense, logging, networks, cryptography, and secure development.
Add those up — 37 + 8 + 14 + 34 — and you get the full 93 controls that make up Annex A in ISO/IEC 27001:2022. This is a reduction from the 114 controls in the 2013 version: several controls were merged, some were renamed, and 11 new controls were added to reflect current threats and practices. Each control in Annex A also carries a set of attributes (control type, security properties, cybersecurity concepts, operational capabilities, and security domains) that let you filter and view the same 93 controls through different lenses — but the theme structure is what drives how organizations typically read, document, and audit against the annex.
The 11 New Controls in the 2022 Revision
If you're transitioning from ISO 27001:2013, pay close attention to these controls — they didn't exist in the previous version and require new evidence in your ISMS:
5.7 Threat intelligence
5.23 Information security for use of cloud services
5.30 ICT readiness for business continuity
7.4 Physical security monitoring
8.9 Configuration management
8.10 Information deletion
8.11 Data masking
8.12 Data leakage prevention
8.16 Monitoring activities
8.23 Web filtering
8.28 Secure coding
Organizations certifying for the first time under the 2022 revision need to address all 11. Organizations transitioning from ISO 27001:2013 need a documented plan for closing the gap on each one before their transition deadline.
How to Use Annex A: The Statement of Applicability
Annex A is not implemented mechanically. The standard's Clause 6.1.3 requires you to compare the results of your risk assessment against the full Annex A list, determine which controls are necessary to treat your identified risks, and record the outcome — including justification for both inclusion and exclusion — in your Statement of Applicability (SoA). The SoA is the single document that ties your risk assessment to the 93 controls and becomes the primary reference your certification auditor works from during Stage 1 and Stage 2 audits.
In practice, most organizations end up implementing the large majority of the 93 controls in some form, because most apply broadly to any organization handling information. But the SoA still matters: it documents how each control is implemented (or why it's not applicable), which is what an auditor tests against, not the raw text of Annex A itself.
Each theme below links to its overview article first, followed by the detailed guides covering specific control clusters. Use the overview articles to understand the theme as a whole, then drill into the control-specific articles for implementation detail.
Key resources - Annex A: All 93 Controls at a Glance (Cheat Sheet) — a one-page reference listing every control number, name, and theme. - Statement of Applicability Template — a ready-to-use SoA structure covering all 93 controls with justification columns.
For the full picture of how Annex A fits into the rest of the standard — clauses, risk assessment, certification — see the master guide: ISO 27001: The Complete Guide.
Organizational Controls (5.1–5.37)
The largest theme, Organizational controls, covers the governance backbone of your ISMS: policies, roles and responsibilities, asset management, access control, supplier security, incident management, and business continuity. If your organization is early in implementation, this is usually the theme with the heaviest documentation lift, since many of these controls define the policies and processes that other controls depend on.
Article | Covers |
|---|---|
ISO 27001 Annex A Organizational Controls: Complete Overview (5.1–5.37) | Full walkthrough of all 37 organizational controls and how they group together |
Information Security Policies: ISO 27001 Control 5.1 Explained | Writing and maintaining the top-level information security policy |
Roles and Responsibilities in Information Security: ISO 27001 Controls 5.2–5.4 | Assigning security roles, segregating duties, and management responsibilities |
Threat Intelligence and ISO 27001: Control 5.7 Implementation Guide | Collecting and using threat intelligence — new in 2022 |
Information Security in Project Management: ISO 27001 Control 5.8 | Embedding security requirements into project delivery |
Asset Management Under ISO 27001: Controls 5.9–5.14 Explained | Asset inventory, acceptable use, return of assets, classification, and labeling |
Access control policy, identity management, authentication, and access rights | |
Supplier Relationship Security: ISO 27001 Controls 5.19–5.23 | Supplier security, agreements, ICT supply chain, and cloud services |
Incident response planning, assessment, response, and evidence collection | |
Business Continuity and ICT Readiness: ISO 27001 Controls 5.29–5.30 | Security during disruption and ICT readiness for business continuity |
People Controls (6.1–6.8)
People controls are the smallest theme by count but touch every employee, contractor, and third party with access to your information. They cover the employee lifecycle — from pre-hire screening through employment terms, ongoing awareness training, and what happens when someone leaves or breaks the rules.
Article | Covers |
|---|---|
ISO 27001 People Controls Overview: Controls 6.1–6.8 Explained | Full walkthrough of all 8 people controls |
Pre-employment verification proportionate to role risk | |
Contractual security responsibilities for staff | |
Security Awareness, Education, and Training: ISO 27001 Control 6.3 | Building and running an ongoing awareness program |
Disciplinary Process and Remote Working Security: ISO 27001 Controls 6.4–6.7 | Disciplinary process, post-termination duties, and remote/teleworking security |
Confidentiality and Non-Disclosure Agreements: ISO 27001 Control 6.6 | Drafting and managing NDAs and confidentiality clauses |
Enabling and encouraging staff to report security events |
Physical Controls (7.1–7.14)
Physical controls protect the tangible environments where information and equipment live: offices, data centers, secure areas, and the equipment itself. Even organizations that are fully cloud-hosted still need to address most of these controls, since they cover endpoint hardware, workstations, and physical media handling as much as buildings.
Article | Covers |
|---|---|
ISO 27001 Physical Controls Overview: Controls 7.1–7.14 Explained | Full walkthrough of all 14 physical controls |
Physical Security Perimeters and Entry Controls: ISO 27001 Controls 7.1–7.3 | Defining perimeters and controlling physical entry |
Securing Offices, Rooms, and Facilities: ISO 27001 Control 7.3 | Detailed guidance on securing specific rooms and facilities |
Continuous monitoring of premises — new in 2022 | |
Environmental threat protection and rules for working in secure areas | |
Practical clear desk and clear screen requirements | |
Equipment Security and Maintenance: ISO 27001 Controls 7.8–7.13 | Siting, utilities, cabling, maintenance, off-site equipment, and unattended equipment |
Secure Disposal or Re-use of Equipment: ISO 27001 Control 7.14 | Sanitizing and disposing of equipment securely |
Technological Controls (8.1–8.34)
The largest single theme after Organizational, Technological controls cover the security engineering side of the ISMS: endpoints, privileged access, malware defense, vulnerability management, logging, network security, cryptography, and the secure development lifecycle. This is typically where IT and engineering teams carry most of the implementation load.
Article | Covers |
|---|---|
ISO 27001 Technological Controls Overview: Controls 8.1–8.34 Explained | Full walkthrough of all 34 technological controls |
Endpoint Devices and User Authentication: ISO 27001 Controls 8.1–8.5 | User endpoint devices, access rights, information access restriction, and secure authentication |
Deep dive on managing and restricting privileged accounts | |
Outsourced Development, Environment Separation & Source Code: ISO 27001 Controls 8.4, 8.30, 8.31 | Source code access, outsourced development, and separating dev/test/production |
Redundancy and Capacity Management: ISO 27001 Controls 8.6, 8.14 | Capacity planning and redundancy of information processing facilities |
Malware detection, prevention, and recovery controls | |
Identifying, assessing, and remediating technical vulnerabilities | |
Configuration Management and Backup: ISO 27001 Controls 8.9, 8.13 | Secure baseline configuration and backup — 8.9 is new in 2022 |
Data Protection: ISO 27001 Controls 8.10–8.12 (Information Deletion, Data Masking, DLP) | Information deletion, data masking, and data leakage prevention — all new in 2022 |
Logging and Monitoring Activities: ISO 27001 Controls 8.15–8.16 | Event logging and monitoring activities — 8.16 is new in 2022 |
Clock synchronization, use of privileged utility programs, and software installation controls | |
Network security, segregation, filtering, and web filtering — 8.23 is new in 2022 | |
Cryptographic policy, key management, and encryption practices | |
Secure coding principles, security requirements, design, testing, and application security testing — includes 8.28, new in 2022 | |
Controlling changes to information processing facilities and systems |
