Skip to content
atlas

ISO 27001 Annex A

Also known as: Annex A, Annex A controls

The list of 93 reference controls at the back of ISO 27001 that every organisation using the standard must hold its own controls up against.

Draft - this entry has not been reviewed yet.

Formal

The annex of ISO 27001:2022 listing 93 controls in four themes (organisational, people, physical, technological); the organisation compares its risk treatment with the list and records in its Statement of Applicability which controls apply and why.

In plain English

Like planning a set dinner from a restaurant's full menu - you read every dish, pick the ones that suit your guests, and can say why the rest were left off.

In practice

A Danish software firm with 40 staff works through all 93 controls; it keeps the ones for secure coding and access, and marks the controls for server rooms as not needed, writing down why - it has no server room of its own.

Why it matters

The list stops organisations from quietly skipping whole areas, and the ISO 27002 guide explains how to carry out each item.

Technical deep dive

Annex A of ISO/IEC 27001:2022 is normative, but it is not a checklist that must be implemented in full. Its role is defined in clause 6.1.3: the organisation first determines the controls necessary to treat its assessed risks, from any source, and then compares them with Annex A (6.1.3 c) to verify that no necessary control has been omitted. The result is the Statement of Applicability (6.1.3 d), which must list the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control. The standard notes that Annex A is not exhaustive, so additional controls, for example from sector requirements or NIS2 Art. 21, can and often should be added.

The 2022 revision restructured the annex from 114 controls in 14 clauses (A.5-A.18 in the 2013 edition) into 93 controls in four themes numbered after ISO/IEC 27002:2022: 37 organisational controls (5.1-5.37), 8 people controls (6.1-6.8), 14 physical controls (7.1-7.14) and 34 technological controls (8.1-8.34). Eleven controls are new: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering and 8.28 secure coding. The rest were merged or renamed; no requirement disappeared wholesale. The certification transition period for the 2013 edition ended on 31 October 2025, so valid certificates now reference the 2022 edition. ISO/IEC 27001:2022/Amd 1:2024 added climate-change considerations to clauses 4.1 and 4.2 but did not change Annex A.

Annex A states each control in a single sentence; the implementation guidance, purpose and attribute tags are in ISO/IEC 27002:2022. The attributes (control type: preventive, detective, corrective; information security properties; cybersecurity concepts aligned with identify, protect, detect, respond, recover; operational capabilities; security domains) make it possible to filter and map the controls to other frameworks such as NIST CSF or the CIS Controls. Sector extensions such as ISO/IEC 27017 (cloud) and ISO/IEC 27701 (privacy) add further controls and guidance on top.

Common audit findings concern the SoA rather than the controls themselves: exclusions justified with "not relevant" instead of a risk-based reason, controls marked implemented without evidence, or an SoA that does not trace back to the risk treatment plan (6.1.3 e). Excluding a control such as 7.x physical controls because hosting is outsourced is acceptable only if the outsourcing itself is covered, typically through 5.19-5.23 supplier and cloud controls. Annex A should also not be confused with ISO 27002, which cannot be certified against, or with the management-system clauses 4-10, which are mandatory in full.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Security control
  9. →ISO 27001 Annex A

Relationships

Part of
ISO 27001
Used with
ISO 27002

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022, Annex A

Course material

  • Cyber Security Fast Track - Kursuskompendium, Modul 3 (ISO 27001 - appendix)

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.