Get Free Consultation

Have any Questions?

Mail us Today!

contact@qcert360.com

Click here to connect through WhatsApp – 24/7

ISO 27001:2022 Annex A Controls: All 93 Explained

ISO 27001:2022 Annex A Controls — All 93 Explained

ISO 27001:2022 Annex A lists 93 information security controls grouped into four themes: organizational (37), people (8), physical (14), and technological (34). Organizations don’t have to implement every control — they select applicable ones through a risk assessment and document the decision in a Statement of Applicability (SoA). This guide explains what each control covers, in plain language, so you know exactly what your ISMS needs to address.

What Changed in the 2022 Revision of ISO 27001 standard

ISO 27001:2022 replaced the old 114-control structure from the 2013 version with a leaner set of 93 controls. Fourteen groups of overlapping controls were merged, and 11 entirely new controls were added to address threat intelligence, cloud security, and data protection practices that didn’t exist a decade ago. The four-theme structure (organizational, people, physical, technological) replaced the old 14-domain layout, making the controls easier to map against real operational functions rather than abstract clause numbers.

Organizations certified under ISO 27001:2013 had until October 2025 to transition to the 2022 version. If your certification body hasn’t already walked you through a gap assessment against the new control set, that’s the first step before your next audit cycle.

How Annex A Controls Work With the Statement of Applicability

Annex A itself is not a checklist you tick off line by line. Clause 6.1.3 of the main ISO 27001 standard requires you to run a risk assessment, decide which controls address your identified risks, and record the outcome — including any controls you exclude and why — in a Statement of Applicability. Auditors use the SoA as the master reference during certification audits, cross-checking it against your risk treatment plan and the actual evidence in place for each selected control.

Most certified organizations end up applying the large majority of the 93 controls in some form, since the four themes map closely to standard operational areas: governance, HR, facilities, and IT. Full exclusions are less common than partial ones, where a control applies in scope but at a reduced level (for example, a fully cloud-based company implementing A.7.1 through a colocation provider’s physical controls rather than its own).

Organizational Controls (A.5.1 – A.5.37)

Organizational controls form the governance backbone of the ISMS — policy, roles, supplier management, incident response, and business continuity. This is the largest theme, with 37 controls, because it covers everything that isn’t a specific technical, physical, or people-related mechanism.

  • A.5.1 Policies for information security — Requires a top-level information security policy and supporting topic-specific policies, formally approved by management and reviewed on a set schedule.
  • A.5.2 Information security roles and responsibilities — Assigns and communicates ownership for security tasks, from executive sponsorship down to individual asset and risk owners.
  • A.5.3 Segregation of duties — Splits conflicting tasks between different people so no single individual can both execute and approve a sensitive action unchecked.
  • A.5.4 Management responsibilities — Obliges managers to actively enforce security policy within their teams, not just acknowledge it exists.
  • A.5.5 Contact with authorities — Maintains defined channels with regulators, law enforcement, and supervisory bodies for legal and incident-reporting obligations.
  • A.5.6 Contact with special interest groups — Keeps the organization connected to security communities, CERTs, and industry forums for early threat warning.
  • A.5.7 Threat intelligence (new in 2022) — Requires gathering and analyzing threat data from internal and external sources to inform security decisions before incidents occur.
  • A.5.8 Information security in project management — Embeds security requirements and risk assessment into every project, not only IT initiatives.
  • A.5.9 Inventory of information and other associated assets — Maintains an accurate, owned inventory of information and the assets that store or process it.
  • A.5.10 Acceptable use of information and other associated assets — Defines and communicates rules for handling organizational information and assets appropriately.
  • A.5.11 Return of assets — Ensures personnel and contractors return organizational property when their engagement ends or changes.
  • A.5.12 Classification of information — Classifies information by confidentiality, integrity, and availability needs so protection effort matches business value.
  • A.5.13 Labelling of information — Applies classification labels consistently across formats and systems so handling rules travel with the data.
  • A.5.14 Information transfer — Sets rules and agreements for securing information moving electronically, physically, or verbally.
  • A.5.15 Access control — Establishes the rules governing who gets logical and physical access to what, based on business need and risk.
  • A.5.16 Identity management — Manages the full lifecycle of digital identities, ensuring each maps to one accountable person or system.
  • A.5.17 Authentication information — Controls how passwords, keys, and other secrets are issued, stored, and rotated.
  • A.5.18 Access rights — Governs provisioning, periodic review, and revocation of access in line with joiner-mover-leaver events.
  • A.5.19 Information security in supplier relationships — Manages the risk of suppliers accessing organizational systems and data, across the full relationship.
  • A.5.20 Addressing information security within supplier agreements — Writes specific security obligations, SLAs, and audit rights directly into supplier contracts.
  • A.5.21 Managing information security in the ICT supply chain — Extends security requirements to sub-suppliers and third-party components, not just direct vendors.
  • A.5.22 Monitoring, review and change management of supplier services — Tracks supplier performance and manages changes to services or agreements over time.
  • A.5.23 Information security for use of cloud services (new in 2022) — Sets requirements for acquiring, operating, and exiting cloud services with a clear shared-responsibility split.
  • A.5.24 Information security incident management planning and preparation — Builds incident response capability — roles, procedures, and communication paths — before an incident happens.
  • A.5.25 Assessment and decision on information security events — Establishes criteria for triaging security events and deciding which ones qualify as incidents.
  • A.5.26 Response to information security incidents — Requires documented incident response covering containment, eradication, recovery, and escalation.
  • A.5.27 Learning from information security incidents — Converts post-incident findings into control improvements and updated risk assessments.
  • A.5.28 Collection of evidence — Governs how incident evidence is identified, preserved, and handled so it holds up for disciplinary or legal use.
  • A.5.29 Information security during disruption — Maintains an agreed level of security even when normal business operations are disrupted.
  • A.5.30 ICT readiness for business continuity (new in 2022) — Ensures IT infrastructure can recover within agreed timeframes through tested failover and recovery plans.
  • A.5.31 Legal, statutory, regulatory and contractual requirements — Requires identifying and tracking every applicable legal and contractual security obligation.
  • A.5.32 Intellectual property rights — Protects IP — the organization’s own and third parties’ — through licensing compliance and usage controls.
  • A.5.33 Protection of records — Safeguards records from loss, falsification, and unauthorized access through their full retention period.
  • A.5.34 Privacy and protection of PII — Meets applicable privacy obligations for personal data, from identification through lawful processing.
  • A.5.35 Independent review of information security — Requires the security program to be independently reviewed at planned intervals and after major change.
  • A.5.36 Compliance with policies, rules and standards for information security — Verifies, on a regular basis, that documented policies are actually being followed.
  • A.5.37 Documented operating procedures — Documents operational procedures for security-relevant activities so they survive staff turnover and stand up under audit.

People Controls (A.6.1 – A.6.8)

People controls cover the human side of the ISMS — screening, contracts, training, discipline, remote work, and incident reporting. Auditors weight this theme heavily because most breaches trace back to human error or insider risk rather than technical failure.

  • A.6.1 Screening — Requires background checks proportionate to role risk, conducted within legal and ethical limits, before granting access.
  • A.6.2 Terms and conditions of employment — Embeds information security responsibilities into employment contracts from day one.
  • A.6.3 Information security awareness, education and training — Runs a role-based training program measured for actual behavior change, not just completion rates.
  • A.6.4 Disciplinary process — Establishes a formal, consistently applied process for handling security policy violations.
  • A.6.5 Responsibilities after termination or change of employment — Defines which obligations — confidentiality, IP, asset return — survive after someone leaves or changes roles.
  • A.6.6 Confidentiality or non-disclosure agreements — Identifies and regularly reviews the NDA terms protecting organizational information.
  • A.6.7 Remote working — Secures information for people working outside the office, covering devices, networks, and the physical environment.
  • A.6.8 Information security event reporting — Gives every employee a fast, clear channel — and the culture — to report suspected security events.

Physical Controls (A.7.1 – A.7.14)

Physical controls protect information in the real world — perimeters, entry points, secure areas, equipment, and media. Even fully remote organizations need to address this theme, typically through data center and device-level controls rather than office security.

  • A.7.1 Physical security perimeters — Defines physical boundaries around areas holding information and assets, with barriers matched to the risk inside.
  • A.7.2 Physical entry — Controls who enters secure areas through entry controls, visitor logs, and protected delivery points.
  • A.7.3 Securing offices, rooms and facilities — Applies physical security measures to offices and rooms against unauthorized access or observation.
  • A.7.4 Physical security monitoring (new in 2022) — Requires continuous monitoring of premises through surveillance and intruder detection systems.
  • A.7.5 Protecting against physical and environmental threats — Designs infrastructure protection against fire, flood, power failure, and similar environmental risks.
  • A.7.6 Working in secure areas — Sets conduct rules for working inside secure areas, including supervision and device restrictions.
  • A.7.7 Clear desk and clear screen — Requires sensitive material to be removed from desks and screens when unattended.
  • A.7.8 Equipment siting and protection — Positions equipment to reduce environmental exposure and unintended observation of sensitive output.
  • A.7.9 Security of assets off-premises — Protects devices and media used outside the office through custody and tracking controls.
  • A.7.10 Storage media — Manages removable and fixed media through acquisition, use, transport, and secure disposal.
  • A.7.11 Supporting utilities — Protects operations from power, cooling, and telecom failures through redundancy such as UPS and generators.
  • A.7.12 Cabling security — Protects power and data cabling against interception, interference, and physical damage.
  • A.7.13 Equipment maintenance — Requires authorized servicing and documented maintenance records, with security checks before equipment returns to use.
  • A.7.14 Secure disposal or re-use of equipment — Verifies storage media are sanitized or destroyed before equipment leaves the organization.

Technological Controls (A.8.1 – A.8.34)

Technological controls are the largest theme after organizational, covering endpoints, access management, cryptography, secure development, and network security. This is where most of the 2022 revision’s new additions landed, reflecting how much IT risk has shifted since 2013.

  • A.8.1 User endpoint devices — Hardens and encrypts laptops, phones, and other endpoints, with clear rules for BYOD.
  • A.8.2 Privileged access rights — Restricts and closely monitors admin-level access through allocation controls and regular revalidation.
  • A.8.3 Information access restriction — Enforces need-to-know access per the access control policy, using dynamic restriction where appropriate.
  • A.8.4 Access to source code — Controls read and write access to source code, development tools, and libraries.
  • A.8.5 Secure authentication — Requires authentication strength matched to what’s being protected, including MFA and secure log-on handling.
  • A.8.6 Capacity management — Monitors and forecasts compute, storage, and network capacity so availability doesn’t fail for predictable reasons.
  • A.8.7 Protection against malware — Layers prevention, detection, and recovery controls with the user awareness needed to make them effective.
  • A.8.8 Management of technical vulnerabilities — Drives inventory-based vulnerability scanning, patching SLAs, and managed exceptions.
  • A.8.9 Configuration management (new in 2022) — Defines and enforces secure baseline configurations for hardware, software, and networks.
  • A.8.10 Information deletion (new in 2022) — Requires deleting information once it’s no longer needed, across systems, devices, and cloud services.
  • A.8.11 Data masking (new in 2022) — Masks or pseudonymizes data so non-production and limited-privilege use never exposes real values.
  • A.8.12 Data leakage prevention (new in 2022) — Detects and blocks unauthorized exfiltration of sensitive data across systems and endpoints.
  • A.8.13 Information backup — Maintains and tests backups matched to agreed scope, frequency, and recovery objectives.
  • A.8.14 Redundancy of information processing facilities — Builds component, system, and site-level redundancy to meet committed availability targets.
  • A.8.15 Logging — Produces, protects, and analyzes event logs covering user activity, exceptions, and security events.
  • A.8.16 Monitoring activities (new in 2022) — Monitors networks, systems, and applications for anomalous behavior and requires action on findings.
  • A.8.17 Clock synchronization — Synchronizes system clocks to approved time sources so logs correlate reliably across systems.
  • A.8.18 Use of privileged utility programs — Restricts utility programs capable of overriding system and application controls.
  • A.8.19 Installation of software on operational systems — Controls what gets installed on production systems, by whom, and under what approval.
  • A.8.20 Networks security — Secures networks and devices through protected management interfaces and controlled traffic flows.
  • A.8.21 Security of network services — Defines security requirements for in-house or outsourced network services, including monitoring.
  • A.8.22 Segregation of networks — Separates services, users, and systems into network domains with controlled traffic between them.
  • A.8.23 Web filtering (new in 2022) — Manages access to external websites to reduce exposure to malicious content.
  • A.8.24 Use of cryptography — Sets rules for algorithm selection and key management across data at rest and in transit.
  • A.8.25 Secure development life cycle — Builds security into the SDLC from design through deployment.
  • A.8.26 Application security requirements — Identifies and approves security requirements when applications are developed or acquired.
  • A.8.27 Secure system architecture and engineering principles — Applies secure-by-design engineering principles to every system implementation.
  • A.8.28 Secure coding (new in 2022) — Applies secure coding standards and review across in-house and third-party code.
  • A.8.29 Security testing in development and acceptance — Runs defined security test plans — SAST, DAST, pre-release checks — in the development pipeline.
  • A.8.30 Outsourced development — Directs and reviews outsourced development so external code meets internal security requirements.
  • A.8.31 Separation of development, test and production environments — Separates environments, access, and data to protect the live estate.
  • A.8.32 Change management — Puts changes to systems and processing facilities through defined, recorded change control.
  • A.8.33 Test information — Protects and manages test data so production data is never exposed unprotected.
  • A.8.34 Protection of information systems during audit testing — Plans audits and technical tests so live systems remain protected throughout.

Frequently Asked Questions

Do I need to implement all 93 Annex A controls?
No. ISO 27001 requires a risk assessment that determines which controls apply to your organization. Controls not relevant to your risk profile can be excluded, provided the exclusion is justified and documented in your Statement of Applicability.

How many Annex A controls are new in ISO 27001:2022?
Eleven controls are new: threat intelligence, cloud security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

What’s the difference between Annex A controls and the main ISO 27001 clauses?
Clauses 4–10 define the mandatory management system requirements — context, leadership, planning, support, operation, evaluation, and improvement. Annex A is a reference set of controls you draw from when your risk assessment calls for them; it doesn’t set requirements on its own.

Where do Annex A controls appear in a certification audit?
Auditors check your Statement of Applicability against your risk treatment plan, then sample evidence for the controls you’ve marked as applicable — policies, logs, records, and interviews confirming the control operates as documented.

How many controls are in each Annex A theme?
Organizational has 37 controls, people has 8, physical has 14, and technological has 34 — a total of 93 across all four themes.

What replaced the 114 controls from ISO 27001:2013?
The 2022 revision consolidated overlapping 2013 controls into 93 controls and reorganized them from 14 domains into four themes. Most 2013 controls map directly to a 2022 equivalent, with 11 genuinely new additions.

Is a Statement of Applicability mandatory for certification?
Yes. Clause 6.1.3(d) requires a documented Statement of Applicability covering every Annex A control, whether included or excluded, with justification for each decision.

Can a small business exclude most technological controls?
Only if a risk assessment genuinely supports it. Auditors expect exclusions to follow from documented risk analysis, not company size alone — most small businesses still apply the majority of technological controls in some scaled-down form.

Which Annex A controls do auditors flag most often during certification?
Access rights review (A.5.18), vulnerability management (A.8.8), logging (A.8.15), and supplier agreements (A.5.20) are common gap areas, usually due to inconsistent evidence rather than missing policy.

Do cloud-only companies still need physical controls?
Yes, but typically through their cloud provider’s controls rather than owned infrastructure. Controls like A.7.1 through A.7.14 still apply to the environment processing your data — you just rely on provider attestations and contracts as evidence.

How long does it take to implement all applicable Annex A controls?
Most first-time certifications take three to six months from gap assessment to audit-ready, depending on how many controls require new documentation, tooling, or process change versus controls already partially in place.

Does ISO 27001:2013 certification remain valid after the 2022 transition deadline?
No. Organizations certified under the 2013 version needed to transition to ISO 27001:2022 by October 2025; certificates issued against the older version are no longer valid for new audits.

Talk to a certification consultant about your Annex A scope — request a custom quote based on your systems, team size, and industry, with no fixed pricing tiers to work around.

What services does QCert360 offer?

QCert360 provides a wide range of services including ISO certification, audit support, compliance consulting, and training. They specialize in helping businesses achieve global standards and certifications like ISO 9001, ISO 27001, ISO 14001, and many others. Their team ensures a seamless experience from consultation to certification, supporting clients at every stage.

How long does it take to get certified through QCert360?

The time it takes to achieve certification can vary depending on the complexity of the standard and the readiness of your organization. On average, it takes about 3 to 6 months. QCert360 works closely with clients to streamline the process, ensuring that all requirements are met efficiently and within a reasonable timeline.

Why should I choose QCert360 for my certification needs?

QCert360 is a trusted partner with years of experience in helping businesses obtain international certifications. Their expert consultants provide tailored solutions, ensuring your organization not only meets but exceeds industry standards. With a customer-centric approach, they focus on offering end-to-end support to simplify the certification journey.

What industries does QCert360 cater to?

QCert360 serves a wide range of industries including manufacturing, healthcare, information technology, education, and services, among others. They customize their certification solutions to meet the unique requirements of each industry, ensuring relevance and compliance with global standards.

Do you offer post-certification support?

Yes, QCert360 provides ongoing support even after certification. They offer services like surveillance audits, recertification guidance, and consultancy to help maintain and improve your certification status. Their team ensures that your organization stays compliant and up-to-date with any changes in certification standards.

How do I get started with QCert360?

Getting started with QCert360 is simple. You can contact them via their website to request a consultation. Their team will assess your needs, discuss the best certification options for your business, and outline the steps involved. From there, they’ll guide you through the entire process, ensuring you’re prepared for certification.

What makes QCert360 different from other certification providers?

QCert360 stands out due to its customer-focused approach, industry expertise, and comprehensive service offerings. Their team doesn’t just help you obtain certification but works to ensure your organization thrives in compliance with international standards. They also offer personalized consultation, making the process smoother and more efficient, ensuring long-term success for your business.

How much does certification through QCert360 cost?

The cost of certification varies depending on factors such as the type of certification, the size and complexity of your organization, and the specific industry requirements. QCert360 offers competitive pricing and provides tailored quotes based on your unique needs. They ensure transparency and work with you to find the most cost-effective solution for your certification goals.

Can QCert360 help with internal audits?

Yes, QCert360 offers internal audit services to help assess and improve your organization’s processes. Their expert auditors conduct thorough reviews of your systems and operations to ensure they meet required standards. They also provide actionable recommendations to help enhance efficiency and compliance, making sure you’re fully prepared for external audits.

What happens if we fail an audit or certification assessment?

If your organization doesn’t pass an audit or certification assessment, QCert360 works with you to understand the reasons for non-compliance and provides support to rectify the issues. They offer guidance on corrective actions and help you prepare for a re-assessment. Their goal is to ensure your organization meets the necessary standards for certification, and they will be by your side to make the process as smooth as possible.

Get a quote instantly

Fill out the form to get your project cost within 1 hour

service required
Company details
Contact details