ISO 27001 Controls Explained: A Simple Guide to Annex A
Annex A of ISO 27001:2022 is a reference list of 93 information security controls grouped into four themes: A.5 Organizational (37 controls), A.6 People (8), A.7 Physical (14), and A.8 Technological (34). It is not a checklist you work through and not a set of requirements you must all implement. Your risks decide which controls you need; Annex A is the cross-check you run afterwards to confirm you haven't missed anything obvious, and your Statement of Applicability records what you included, what you excluded, and why.
Annex A is the list of security controls printed at the back of ISO/IEC 27001. In the 2022 edition it contains 93 controls grouped into four themes, and it is the part of the standard people meet first — usually as a spreadsheet someone forwarded with the words "we need to do all of these."
You don't. That misunderstanding is the single most expensive one in early ISO 27001 work, and clearing it up is most of what this guide does. This is the plain-language orientation; when you want the control-by-control detail, our complete 2022 Annex A guide covers all 93.
What Annex A Actually Is
Annex A is a reference set — a catalogue of controls the standard offers you, not a list of obligations. The requirements you must meet live in Clauses 4 through 10 (context, leadership, planning, support, operation, evaluation, improvement). Annex A supports those requirements; it doesn't replace them.
The mechanism is in Clause 6.1.3. You assess your risks, decide how to treat them, and determine the controls you need. Then you compare your determined controls against Annex A to verify you haven't overlooked something necessary. That order matters: risks first, catalogue second. Teams who reverse it end up implementing controls nobody needed and can't explain why any of them exist.
The detailed guidance for each control — what it means, how to implement it — lives in a companion standard, ISO/IEC 27002:2022. ISO 27001 gives you the control titles; ISO 27002 explains them.
The Four Themes
The 2022 edition organizes all 93 controls into four themes, replacing the fourteen domains of the 2013 edition:
| Theme | Controls | What it covers |
|---|---|---|
| A.5 — Organizational | 37 | Policies, roles and responsibilities, supplier relationships, incident management, continuity, legal and contractual requirements. The largest theme by far. Deep dive. |
| A.6 — People | 8 | Screening, terms of employment, awareness and training, disciplinary process, offboarding, remote working. Deep dive. |
| A.7 — Physical | 14 | Secure areas, entry controls, equipment, clear desk and screen, physical monitoring, secure disposal. Deep dive. |
| A.8 — Technological | 34 | Access management, cryptography, logging and monitoring, network security, secure development, configuration and change management. Deep dive. |
The grouping is deliberately practical: it tends to map onto who owns the work. People controls are mostly HR's, physical controls mostly office management's, technological controls mostly engineering's, and organizational controls mostly whoever owns the ISMS.
How to Read a Control Number
Control identifiers look like A.8.24. Read them as theme, then position within that theme: A.8 is the Technological theme, and .24 is "use of cryptography" within it. Similarly A.5.19 is a supplier-relationships control inside the Organizational theme, and A.6.3 is awareness and training inside People.
One thing that trips people up: numbering in the current edition looks nothing like the 2013 edition. If a template, consultant, or blog post refers to A.9 (access control), A.10 (cryptography), A.12 (operations security), or A.14 (system acquisition and development), it is written against ISO 27001:2013, which was superseded. Those clusters still exist in substance — they were redistributed across the four new themes. Our 2013 to 2022 control mapping shows where each one landed.
Ready to Streamline Your Compliance?
Discover how AuditBadger can simplify your compliance management process.
You Do Not Implement All 93
This is the point worth internalizing. Annex A is a menu, and your risk assessment is the order.
A fully remote company with no office does not implement most of the physical theme — there are no secure areas to control entry to. A company that holds no physical media has no media-disposal control to run. Excluding those is normal, expected, and explicitly provided for by the standard.
What you cannot do is exclude something silently. Clause 6.1.3 requires a Statement of Applicability that lists which controls apply, why they apply, whether they are implemented — and, for each control you left out, the justification for excluding it. "We are fully remote and operate no offices" is a justification. "Not relevant to us" is not, and an auditor will ask you to expand it.
So the honest sequence for a small company is: build the risk register, decide treatments, determine controls, check them against Annex A, then write the SoA recording the whole set of decisions. The number of applicable controls you end up with is an output, not a target.
What Changed in 2022
Three things are worth knowing if you're reading older material:
- Fewer controls, not less coverage. The count went from 114 to 93 because overlapping controls were merged, not because requirements were dropped.
- Eleven genuinely new controls were added, covering ground the 2013 edition predated: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
- Attributes were introduced. Each control in ISO 27002:2022 carries tags — control type, which of confidentiality, integrity and availability it protects, cybersecurity concept, operational capability, security domain. They're optional, but useful if you need to view your controls through a different lens or map them to another framework.
Where to Go Next
If you're orienting yourself, the useful order is: understand what Annex A is (this page), then read the requirements that actually drive it in Clauses 4 to 10, then work through the controls themselves in the complete Annex A guide.
When you get to implementation, the two documents that carry the most weight are the risk register and the Statement of Applicability, connected by a risk treatment plan. Get those three pointing at each other and Annex A stops being a wall of 93 rows and becomes what it was designed to be: a checklist you run once, at the end, to make sure you didn't forget anything.
Frequently asked questions
How many controls are in ISO 27001 Annex A? +
ISO 27001:2022 Annex A contains 93 information security controls organized into four categories: Organizational Controls (A.5, 37 controls), People Controls (A.6, 8 controls), Physical Controls (A.7, 14 controls), and Technological Controls (A.8, 34 controls). The 2022 revision restructured the previous 114 controls from 14 domains into this cleaner four-category structure, merging 24 overlapping controls, updating 58, and introducing 11 entirely new controls. Organizations don't need to implement all 93 — they select controls based on their risk assessment and document their decisions in a Statement of Applicability.
What are the four categories of ISO 27001 Annex A controls? +
The four categories of ISO 27001:2022 Annex A controls are: A.5 Organizational Controls (37 controls covering governance, policies, roles, supplier management, and incident handling), A.6 People Controls (8 controls covering screening, training, awareness, and offboarding), A.7 Physical Controls (14 controls covering facility access, equipment security, and environmental protection), and A.8 Technological Controls (34 controls covering access management, encryption, logging, network security, and secure development). This structure replaced the 14 domains from the 2013 version, making it clearer which team or function owns each control.
Do you have to implement all 93 ISO 27001 Annex A controls? +
No. Annex A is a reference catalogue, not a list of obligations. Your risk assessment determines which controls you need; Annex A is the cross-check you run afterwards under Clause 6.1.3 to confirm nothing necessary was overlooked. A fully remote company legitimately excludes most physical controls. What you cannot do is exclude a control silently — the Statement of Applicability must record each exclusion with a justification an auditor can test.
What is the difference between ISO 27001 and ISO 27002? +
ISO/IEC 27001 is the certifiable standard: it sets the management system requirements in Clauses 4 to 10 and lists the 93 Annex A control titles. ISO/IEC 27002 is the companion guidance document that explains each of those controls in detail — what it means and how to implement it — and it carries the attribute taxonomy introduced in 2022. You get certified against 27001; you read 27002 to understand what the controls actually ask of you.
What happened to ISO 27001 controls A.9 through A.18? +
They belong to the superseded 2013 edition, which organized 114 controls into fourteen domains numbered A.5 to A.18. The 2022 edition regrouped everything into four themes — A.5 Organizational, A.6 People, A.7 Physical, A.8 Technological — so identifiers like A.9 (access control), A.10 (cryptography), A.12 (operations security), and A.14 (system acquisition and development) no longer exist. The substance survived and was redistributed; only the numbering changed. If a template or consultant still uses A.9-to-A.18 numbering, it was written against the old edition.