ISO 27001 ANNEX A
ISO 27001 Annex A Controls Explained: All 93 by Theme
The 93 Annex A controls of ISO/IEC 27001:2022 described by theme and number in plain words: what changed from 2013, the 11 new controls, the 27002 attributes, why Annex A is a cross-check, and three worked SoA numbers.

ISO 27001 Annex A is the reference list of 93 information security controls in ISO/IEC 27001:2022, grouped into four themes: 37 organisational controls (5.1 to 5.37), 8 people controls (6.1 to 6.8), 14 physical controls (7.1 to 7.14) and 34 technological controls (8.1 to 8.34). It is not a checklist to implement in full. You choose controls from your risk assessment, then compare your choice with Annex A so that nothing necessary is missed, and record every decision, including exclusions with reasons, in the Statement of Applicability (SoA). Detailed guidance on each control is in the companion standard ISO/IEC 27002:2022.
Facts about the standards were checked on iso.org in October 2026. This guide describes Annex A by theme, number and short topic in its own words; it does not reproduce the text of ISO/IEC 27001 or 27002, which ISO sells. Anyone implementing them should hold a licensed copy.
Which edition this covers
ISO's ISO/IEC 27001 page lists the third edition, published in October 2022, with one amendment, Amendment 1:2024 on climate action changes, which touches clauses 4.1 and 4.2 rather than Annex A. The 2013 edition is withdrawn, and the transition period for 2013 certificates ended on 31 October 2025. ISO's ISO/IEC 27002 page lists the 2022 edition of the guidance standard, published in February 2022, whose control numbering Annex A follows.
The four themes
| Theme | Controls | Count | Typical topics (paraphrased) |
|---|---|---|---|
| Organisational | 5.1 to 5.37 | 37 | Policies and roles, threat intelligence, asset inventory and classification, access control and identities, suppliers and cloud services, incident management, continuity, legal and privacy duties, independent review |
| People | 6.1 to 6.8 | 8 | Screening, employment terms, awareness and training, disciplinary process, duties after leaving, confidentiality agreements, remote working, reporting security events |
| Physical | 7.1 to 7.14 | 14 | Perimeters and entry, secure areas, physical monitoring, environmental threats, clear desk and screen, equipment siting, off-site assets, storage media, utilities, cabling, maintenance, secure disposal |
| Technological | 8.1 to 8.34 | 34 | Endpoints, privileged access, authentication, malware, vulnerabilities, configuration, deletion and masking, leakage prevention, backup, logging and monitoring, networks, cryptography, secure development, change and testing |
The check: 37 + 8 + 14 + 34 = 93. The themes group controls by who or what they mainly concern, not by technology domain as the 2013 edition's 14 domains did.

What changed from the 2013 edition
The 2013 Annex A had 114 controls in 14 domains. The 2022 edition has 93 in four themes: many old controls were merged (for example, several access policy and network access controls now sit together under 5.15), some were reworded, and 11 are new. ISO/IEC 27002:2022 includes a correspondence table so an existing control set can be mapped forward.
| New control | Theme | Short topic |
|---|---|---|
| 5.7 | Organisational | Threat intelligence |
| 5.23 | Organisational | Security when using cloud services |
| 5.30 | Organisational | IT readiness to keep the business running |
| 7.4 | Physical | Watching premises for intrusion |
| 8.9 | Technological | Managing secure configurations |
| 8.10 | Technological | Deleting data no longer needed |
| 8.11 | Technological | Masking sensitive data |
| 8.12 | Technological | Stopping data leaks |
| 8.16 | Technological | Watching for anomalous activity |
| 8.23 | Technological | Filtering web access |
| 8.28 | Technological | Writing code securely |
Three of the eleven are organisational, one physical and seven technological. In most implementations these need fresh work, especially threat intelligence, configuration management and secure coding.
The technological theme, grouped by job
The 34 technological controls are easier to manage grouped by what they do:
- Identities and endpoints: 8.1 user endpoint devices, 8.2 privileged access, 8.3 access restriction, 8.5 secure authentication.
- Harden and patch: 8.7 malware, 8.8 technical vulnerabilities, 8.9 configuration, 8.19 software installation.
- Protect data: 8.10 deletion, 8.11 masking, 8.12 leakage prevention, 8.13 backup, 8.24 cryptography.
- Watch and record: 8.15 logging, 8.16 monitoring, 8.17 clock synchronisation.
- Networks: 8.20 network security, 8.21 network services, 8.22 segregation, 8.23 web filtering.
- Build securely: 8.25 secure development life cycle through 8.33 test information, including 8.28 secure coding, 8.31 separate environments and 8.32 change management.
Attributes: five ways to sort the same controls
ISO/IEC 27002:2022 gives each control five attribute types, written as hashtags: control type (preventive, detective, corrective), security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities (15 values such as governance or identity and access management) and security domains (governance and ecosystem, protection, defence, resilience). They are a filtering aid, for example "show every detective control" for a SOC review. They are not requirements and are not audited.
Annex A is a cross-check, not a checklist
Clause 6.1.3 asks you to determine the controls your risk treatment needs, then compare them with Annex A to verify no necessary control was omitted. The standard notes that Annex A is not exhaustive, so you may add controls of your own. The right order is: risk assessment, your control choices, the Annex A comparison, then the SoA. Implementing all 93 "because they are there" wastes effort and hides the controls that matter.
Each SoA row gives the control, whether it applies, the justification and its status. "Required by ISO" is not a justification: point to a risk, a law, a contract or a business need. A remote-first company with no premises may justify 7.4 (watching premises) as not applicable, while 5.23 cloud services applies because the platform runs on a public cloud.

Worked example: three Annex A numbers an auditor will check
The SoA status. An SoA has 93 Annex A rows; 6 controls are justified as not applicable, 70 are implemented and 12 are partly implemented. Applicable controls: 93 - 6 = 87. Planned: 87 - 70 - 12 = 5. Fully implemented share: 70 / 87 = 0.805, about 80%. The 12 partial and 5 planned controls each need an owner and a date in the risk treatment plan.
Privileged access (8.2). An access review finds 52 of 400 accounts with administrator rights, against an objective of no more than 5%. Allowed: 0.05 x 400 = 20. To remove: 52 - 20 = 32. The share falls from 52 / 400 = 13% to 5%. Close the action with the signed review, the change tickets and a re-run of the report a month later.
ICT readiness (5.30). A billing service has a recovery time objective (RTO) of 8 hours and a recovery point objective (RPO) of 4 hours, with backups every 4 hours. It fails at 14:30; the last good backup was 12:00; restore starts at 15:00, takes 3 hours and checks take 1 hour. Data lost: 14:30 - 12:00 = 2.5 hours, inside the RPO. Downtime: 19:00 - 14:30 = 4.5 hours, inside the RTO. But if the 12:00 backup had failed, the loss from 08:00 would be 6.5 hours and break the RPO, so monitor backup success or back up more often.
Mapping Annex A to other frameworks
Few organisations answer to ISO/IEC 27001 alone. Build one control library and map each control to every framework it supports: NIST CSF 2.0 (whose resource centre publishes informative references), SOC 2's Trust Services Criteria, NIS2's risk management measures and data protection law. Mark each mapping as direct, partial or none, because laws add deadlines, recipients and content that a control does not state. Incident controls 5.24 to 5.28, for example, map only partially to legal breach-reporting duties. Our post on Cyber Resilience Act reporting obligations shows how much detail a regulation adds on top of a control.
Learn the whole ISMS free
Annex A makes sense only inside an ISMS: context and scope, risk assessment and treatment, the SoA, internal audit, management review and certification. The free ISO 27001:2022 Implementation: Build an ISMS course works through all of it in fourteen modules, with worked problems and an ISMS starter-pack project. You do not need to buy the standard to follow it.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page; our guide on how to verify a training certificate explains what to look for. It is not a lead implementer or lead auditor credential, it does not certify any organisation, and EDWartens is not affiliated with ISO or IEC. Start the ISO 27001 implementation course.
Take the free course
Questions
How many controls are in ISO 27001 Annex A?
ISO/IEC 27001:2022 Annex A has 93 controls in four themes: 37 organisational (5.1 to 5.37), 8 people (6.1 to 6.8), 14 physical (7.1 to 7.14) and 34 technological (8.1 to 8.34). The 2013 edition had 114 controls in 14 domains.
Which Annex A controls are new in 2022?
Eleven: 5.7 threat intelligence, 5.23 cloud services, 5.30 IT readiness for continuity, 7.4 monitoring of premises, and 8.9 configuration, 8.10 deletion, 8.11 masking, 8.12 leakage prevention, 8.16 monitoring, 8.23 web filtering and 8.28 secure coding.
Do I have to implement all 93 Annex A controls?
No. You choose controls from your risk assessment and compare them with Annex A to make sure nothing necessary is missed. Controls you exclude stay in the Statement of Applicability with a justification, and you may add controls that Annex A does not list.
What is the difference between ISO 27001 Annex A and ISO 27002?
Annex A of ISO/IEC 27001 lists the 93 controls in brief as a reference for risk treatment. ISO/IEC 27002:2022 is a separate guidance standard that explains each control's purpose and implementation and adds five attribute types for sorting them. Organisations are certified against 27001, not 27002.
What are the ISO 27002 control attributes?
Five attribute types: control type (preventive, detective, corrective), security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities and security domains. They help you filter controls and are not audited requirements.
Is there a free ISO 27001 course with a certificate?
Yes. ISO 27001:2022 Implementation: Build an ISMS on EDWartens is a free course with a verifiable certificate of completion, covering scope, risk, Annex A, the SoA, internal audit and certification. It is not a lead implementer or lead auditor credential.
Sources
- ISO: ISO/IEC 27001:2022, Information security management systems, with Amendment 1:2024 (read 11 October 2026)
- ISO: ISO/IEC 27002:2022, Information security controls (read 11 October 2026)
- NIST: Cybersecurity Framework 2.0 resource centre (read 11 October 2026)
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

Is ISC2 CC Worth It in 2026, Now the Free Exam Has Ended?

Wazuh vs Splunk: Which SIEM to Learn and Run in 2026

Arc Flash PPE Categories 1 to 4: Chart and Methods

ATEX vs IECEx vs CompEx: What Each One Means

Building Automation Cybersecurity: Risks and Standards

CompactLogix vs ControlLogix: Key Differences


