{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/annex-a","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/annex-a/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/annex-a/"},"term":{"en":"ISO 27001 Annex A","da":"ISO 27001 Annex A (bilag A)"},"aka":{"en":["Annex A","Annex A controls"],"da":["bilag A","Annex A"]},"domain":["security"],"cluster":"compliance","layer":"governance","status":"current","era":2005,"summary":{"en":"The list of 93 reference controls at the back of ISO 27001 that every organisation using the standard must hold its own controls up against.","da":"De 93 referencekontroller bagerst i ISO 27001, som enhver organisation, der følger standarden, skal holde sine kontroller op imod."},"body":{"formal":{"en":"The annex of ISO 27001:2022 listing 93 controls in four themes (organisational, people, physical, technological); the organisation compares its risk treatment with the list and records in its Statement of Applicability which controls apply and why.","da":"Anneks A til ISO 27001:2022 rummer 93 kontroller i fire temaer (organisatoriske, menneskelige, fysiske og teknologiske); organisationen sammenholder sin risikohåndtering med listen og noterer i sin Statement of Applicability, hvilke kontroller der gælder, og hvorfor."},"plain":{"en":"Like planning a set dinner from a restaurant's full menu - you read every dish, pick the ones that suit your guests, and can say why the rest were left off.","da":"Som at sammensætte en festmiddag ud fra restaurantens fulde menukort - man læser hver ret, vælger dem, der passer til gæsterne, og kan forklare, hvorfor resten blev fravalgt."},"inPractice":{"en":"A Danish software firm with 40 staff works through all 93 controls; it keeps the ones for secure coding and access, and marks the controls for server rooms as not needed, writing down why - it has no server room of its own.","da":"Et dansk softwarefirma med 40 ansatte gennemgår alle 93 kontroller; det beholder dem om sikker udvikling og adgangsstyring og markerer kontrollerne for serverrum som ikke relevante med en skriftlig begrundelse - firmaet har intet serverrum."},"whyItMatters":{"en":"The list stops organisations from quietly skipping whole areas, and the ISO 27002 guide explains how to carry out each item.","da":"Listen forhindrer organisationer i stille og roligt at springe hele områder over, og ISO 27002 forklarer, hvordan hvert punkt gennemføres."}},"deepDive":{"en":"Annex A of ISO/IEC 27001:2022 is normative, but it is not a checklist that must be implemented in full. Its role is defined in clause 6.1.3: the organisation first determines the controls necessary to treat its assessed risks, from any source, and then compares them with Annex A (6.1.3 c) to verify that no necessary control has been omitted. The result is the Statement of Applicability (6.1.3 d), which must list the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control. The standard notes that Annex A is not exhaustive, so additional controls, for example from sector requirements or NIS2 Art. 21, can and often should be added.\n\nThe 2022 revision restructured the annex from 114 controls in 14 clauses (A.5-A.18 in the 2013 edition) into 93 controls in four themes numbered after ISO/IEC 27002:2022: 37 organisational controls (5.1-5.37), 8 people controls (6.1-6.8), 14 physical controls (7.1-7.14) and 34 technological controls (8.1-8.34). Eleven controls are new: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering and 8.28 secure coding. The rest were merged or renamed; no requirement disappeared wholesale. The certification transition period for the 2013 edition ended on 31 October 2025, so valid certificates now reference the 2022 edition. ISO/IEC 27001:2022/Amd 1:2024 added climate-change considerations to clauses 4.1 and 4.2 but did not change Annex A.\n\nAnnex A states each control in a single sentence; the implementation guidance, purpose and attribute tags are in ISO/IEC 27002:2022. The attributes (control type: preventive, detective, corrective; information security properties; cybersecurity concepts aligned with identify, protect, detect, respond, recover; operational capabilities; security domains) make it possible to filter and map the controls to other frameworks such as NIST CSF or the CIS Controls. Sector extensions such as ISO/IEC 27017 (cloud) and ISO/IEC 27701 (privacy) add further controls and guidance on top.\n\nCommon audit findings concern the SoA rather than the controls themselves: exclusions justified with \"not relevant\" instead of a risk-based reason, controls marked implemented without evidence, or an SoA that does not trace back to the risk treatment plan (6.1.3 e). Excluding a control such as 7.x physical controls because hosting is outsourced is acceptable only if the outsourcing itself is covered, typically through 5.19-5.23 supplier and cloud controls. Annex A should also not be confused with ISO 27002, which cannot be certified against, or with the management-system clauses 4-10, which are mandatory in full.","da":"Annex A i ISO/IEC 27001:2022 er normativt, men det er ikke en tjekliste, der skal gennemføres i sin helhed. Dets rolle er fastlagt i punkt 6.1.3: organisationen fastlægger først de kontroller, der er nødvendige for at håndtere de vurderede risici, uanset kilde, og sammenligner dem derefter med Annex A (6.1.3 c) for at sikre, at ingen nødvendig kontrol er udeladt. Resultatet er Statement of Applicability (6.1.3 d), som skal angive de nødvendige kontroller, begrundelsen for at medtage dem, om de er gennemført, og begrundelsen for at udelade en kontrol fra Annex A. Standarden bemærker, at Annex A ikke er udtømmende, så yderligere kontroller, fx fra sektorkrav eller NIS2 art. 21, kan og bør ofte tilføjes.\n\nRevisionen i 2022 omlagde bilaget fra 114 kontroller i 14 afsnit (A.5-A.18 i 2013-udgaven) til 93 kontroller i fire temaer nummereret som i ISO/IEC 27002:2022: 37 organisatoriske kontroller (5.1-5.37), 8 personrelaterede kontroller (6.1-6.8), 14 fysiske kontroller (7.1-7.14) og 34 teknologiske kontroller (8.1-8.34). Elleve kontroller er nye: 5.7 trusselsefterretninger, 5.23 informationssikkerhed ved brug af cloudtjenester, 5.30 IKT-parathed til forretningskontinuitet, 7.4 overvågning af fysisk sikkerhed, 8.9 konfigurationsstyring, 8.10 sletning af information, 8.11 datamaskering, 8.12 forebyggelse af datalæk, 8.16 overvågningsaktiviteter, 8.23 webfiltrering og 8.28 sikker kodning. Resten blev slået sammen eller omdøbt; intet krav forsvandt helt. Overgangsperioden for certificering efter 2013-udgaven sluttede 31. oktober 2025, så gyldige certifikater henviser nu til 2022-udgaven. ISO/IEC 27001:2022/Amd 1:2024 tilføjede klimahensyn i punkt 4.1 og 4.2, men ændrede ikke Annex A.\n\nAnnex A beskriver hver kontrol i én sætning; vejledning, formål og attributter står i ISO/IEC 27002:2022. Attributterne (kontroltype: forebyggende, detekterende, korrigerende; informationssikkerhedsegenskaber; cybersikkerhedsbegreber svarende til identify, protect, detect, respond, recover; operationelle kapabiliteter; sikkerhedsdomæner) gør det muligt at filtrere kontrollerne og mappe dem til andre rammeværker som NIST CSF eller CIS-kontrollerne. Sektorudvidelser som ISO/IEC 27017 (cloud) og ISO/IEC 27701 (privatliv) lægger yderligere kontroller og vejledning ovenpå.\n\nTypiske auditfund handler om SoA'en snarere end om selve kontrollerne: fravalg begrundet med \"ikke relevant\" i stedet for en risikobaseret begrundelse, kontroller markeret som gennemført uden dokumentation, eller en SoA, der ikke kan spores tilbage til risikohåndteringsplanen (6.1.3 e). At fravælge fx de fysiske 7.x-kontroller, fordi hostingen er outsourcet, holder kun, hvis selve outsourcingen er dækket, typisk via leverandør- og cloudkontrollerne 5.19-5.23. Annex A må heller ikke forveksles med ISO 27002, som man ikke kan certificeres efter, eller med ledelsessystemets punkt 4-10, som skal opfyldes fuldt ud."},"edges":[{"type":"requires","to":"security/control","confidence":"high","strength":"normal"},{"type":"part-of","to":"security/iso-27001","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/iso-27002","why":{"en":"Annex A names each control in one line; ISO 27002 gives the guidance for the same 93 controls.","da":"Annex A nævner hver kontrol på én linje; ISO 27002 giver vejledningen til de samme 93 kontroller."},"confidence":"high","strength":"primary"}],"depth":5,"sources":[{"title":"Cyber Security Fast Track - Kursuskompendium, Modul 3 (ISO 27001 - appendix)","tier":"course-material"},{"title":"ISO/IEC 27001:2022, Annex A","tier":"standard"}],"draft":true}