ZF/blog/iso-27001-annex-a-controls
ISO 270018 min readMay 8, 2025

ISO 27001 Annex A Controls

Annex A in ISO 27001:2022 contains 93 controls organized into four themes. Here is what each theme covers and which controls drive the most implementation work.


Annex A Structure

The 2022 revision of ISO 27001 reorganized Annex A from 114 controls in 14 categories down to 93 controls in 4 themes. The reduction came from consolidation, not elimination. The four themes are:

  • A.5 Organizational controls (37 controls): Policies, governance, supplier relationships, business continuity
  • A.6 People controls (8 controls): Screening, training, agreements, disciplinary processes
  • A.7 Physical controls (14 controls): Facility security, equipment protection, secure disposal
  • A.8 Technological controls (34 controls): Access control, cryptography, monitoring, vulnerability management

Each control has a name, control statement, purpose, and guidance. Annex A is informative; the formal requirements are in clauses 4-10. But because the certification audit verifies your SoA against Annex A, the controls function as the de facto reference set.

The full ISO 27001 framework reference lists each control with implementation guidance.

A.5 Organizational Controls

Organizational controls cover the management system structure: policies, governance, supplier relationships, business continuity, and threat intelligence. These are typically the easiest controls to implement (mostly documentation) and the most often missed during operation (because documentation goes stale).

High-effort controls in this theme:

  • A.5.1 Policies for information security: Top-level information security policy plus topic-specific policies
  • A.5.7 Threat intelligence: Process for collecting, analyzing, and acting on threat intelligence
  • A.5.19-21 Supplier relationships: Three controls covering supplier security, supply chain, and ICT supply chain
  • A.5.23 Information security in cloud services: New control for cloud-specific risks
  • A.5.30 ICT readiness for business continuity: Continuity testing and recovery for ICT services

Document policies, then operate them. A policy that is never reviewed, never trained on, and never enforced provides no protection.

A.6 People Controls

People controls (8 controls) cover the human element of information security: hiring, training, ongoing awareness, and termination. The theme is small but high-impact because most security incidents involve human factors.

The eight controls:

  • A.6.1 Screening: Background checks for new hires
  • A.6.2 Terms and conditions of employment: Confidentiality and acceptable use clauses in employment contracts
  • A.6.3 Information security awareness, education, and training: Annual training, role-specific training, ongoing awareness
  • A.6.4 Disciplinary process: Formal process for security policy violations
  • A.6.5 Responsibilities after termination or change of employment: Confidentiality continues post-employment
  • A.6.6 Confidentiality or non-disclosure agreements: NDAs for employees, contractors, vendors
  • A.6.7 Remote working: Security for remote and hybrid workers
  • A.6.8 Information security event reporting: Process for employees to report incidents

The controls are all process-based. Document the processes, train people on them, and capture evidence of operation.

A.7 Physical Controls

Physical controls (14 controls) cover facility security, equipment protection, and secure disposal. For fully remote organizations, many of these controls are not applicable and can be excluded in the SoA with justification. For organizations with offices or data centers, all 14 typically apply.

Key controls:

  • A.7.1 Physical security perimeters: Building entry controls
  • A.7.2 Physical entry: Access controls (badges, biometrics, escort policies)
  • A.7.4 Physical security monitoring: CCTV, alarm systems, security personnel
  • A.7.5 Protecting against physical and environmental threats: Fire, flood, power, climate
  • A.7.10 Storage media: Encryption and physical protection of storage media
  • A.7.14 Secure disposal or re-use of equipment: Sanitization before disposal or reuse

For cloud-only operations, most physical controls inherit from the cloud provider. Document the inheritance in the SoA. Reference cloud provider audit reports as evidence.

A.8 Technological Controls

Technological controls (34 controls) is the largest theme and where most implementation work happens. Coverage spans access control, cryptography, system security, network security, application security, monitoring, and vulnerability management.

Highest-effort controls:

  • A.8.2 Privileged access rights: Privileged access management with MFA, JIT, and recording
  • A.8.5 Secure authentication: MFA, password policy, session management
  • A.8.7 Protection against malware: EDR, email filtering, sandboxing
  • A.8.8 Management of technical vulnerabilities: Vulnerability scanning, patch management, dependency tracking
  • A.8.9 Configuration management: Hardening baselines, configuration drift detection
  • A.8.16 Monitoring activities: SIEM, log analysis, alerting, on-call
  • A.8.24 Use of cryptography: Cryptographic policy, key management, algorithm selection
  • A.8.28 Secure coding: Application security, secure development practices

These eight controls account for the bulk of technical implementation work. They overlap heavily with SOC 2, CMMC, and other frameworks, so the work is reusable.

Frequently Asked Questions

ISO 27001Annex AControlsISMS

Related Articles