ISO 27001 Annex A controls are the reference list of security safeguards printed at the back of the standard. Once your risk assessment is done, you turn to this list and check whether anything sensible has been left out. The 2022 edition carries 93 ISO 27001 Annex A controls, grouped into four themes instead of the 14 domains used in the older 2013 version.
Here is the point most first-time implementers miss. Annex A is not a compulsory to-do list. It is a cross-check. Your risk treatment decisions decide which controls apply to your information security management system, and the Statement of Applicability records what you included, what you left out, and the reasoning behind each call.
What Annex A Contains
Annex A is a normative annex, meaning it forms part of the certifiable requirements. It gives you the control number, the control title, and a one-line statement of what the control should achieve. It does not tell you how to implement anything.
The how sits in ISO/IEC 27002:2022, a companion guidance document that expands every Annex A control with purpose, guidance, and other information. Auditors expect to see Annex A used as the checklist and ISO 27002 used as the reference manual.
Clause 6.1.3 of the standard is what ties them together. It requires you to compare the controls you selected during risk treatment against Annex A and confirm that no necessary control was overlooked. That comparison, along with the ISO 27001 clauses that govern the management system itself, is what a certification auditor will trace during Stage 1.
How Annex A Changed in the 2022 Revision
The 2013 version listed 114 controls across 14 domains. The current ISO 27001 standard lists 93 across four. The count dropped because 24 controls were merged, not because requirements were removed. Fifty-eight controls were reworded or updated, and 11 controls were added to reflect cloud adoption, remote work, and modern attack patterns.
Organisations that certified under the 2013 version had until 31 October 2025 to migrate. Any active certificate today should already be mapped to the 2022 control set.
The Four Themes of Annex A Controls

Organizational Controls, A.5.1 to A.5.37
Thirty-seven controls, the largest group. This theme covers policies, roles, supplier and cloud service arrangements, asset inventories, classification, incident handling, legal obligations, and continuity. Most of your written evidence lives here, which is why document control discipline matters so much in this section. Controls such as A.5.19 to A.5.22 pull your whole vendor management process into audit scope.
People Controls, A.6.1 to A.6.8
Eight controls covering screening, terms of employment, awareness and training, disciplinary process, responsibilities after employment ends, confidentiality agreements, remote working, and event reporting. Small in number, but these are the controls that fail most often because they depend on HR records rather than technical settings.
Physical Controls, A.7.1 to A.7.14
Fourteen controls covering perimeters, entry, secure areas, equipment siting, cabling, maintenance, clear desk and clear screen, and secure disposal. If your team works from home or from a shared office, your physical security evidence will look different from a data centre operator's, and that is acceptable as long as the risk assessment says so.
Technological Controls, A.8.1 to A.8.34
Thirty-four controls covering endpoints, privileged access, authentication, cryptography, capacity, backup, logging, network segregation, secure development, and protection against malicious code. This is the theme where automated evidence is easiest to produce and where auditors ask for screenshots and system exports rather than signed documents.
The 11 New Annex A Controls
These are the additions in the 2022 set, and they are the ones auditors probe first because organisations have had the least time to embed them.
- A.5.7 Threat intelligence
- A.5.23 Information security for use of cloud services
- A.5.30 ICT readiness for business continuity
- A.7.4 Physical security monitoring
- A.8.9 Configuration management
- A.8.10 Information deletion
- A.8.11 Data masking
- A.8.12 Data leakage prevention
- A.8.16 Monitoring activities
- A.8.23 Web filtering
- A.8.28 Secure coding
Note that A.8.28 applies only if you build software. A.8.11 rarely applies to a services firm with no test environments. Applicability is judged against your context, not against a generic template.
Control Attributes and Why They Help
The 2022 revision tags every control with five attributes: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities, and security domains.
Attributes are optional and never audited on their own. They are useful for one practical reason: they let you filter the control set. Filtering by the detect concept, for example, quickly shows whether your monitoring coverage is thin compared with your preventive coverage. Teams that already report to a board find this filtering makes control reporting far easier to explain.
Selecting the Right Annex A Controls
The order of work matters, and getting it backwards is the most common cause of a bloated, unusable control set.

- Build your asset and information inventory first.
- Run the risk assessment for ISO 27001 and rate each risk.
- Decide treatment for each risk: modify, accept, avoid, or share.
- Identify the controls those treatment decisions require.
- Compare that list against all 93 Annex A controls and note any gaps.
- Record every inclusion and exclusion in the Statement of Applicability with justification.
Sound information security risk management is what makes step four defensible. Without it, you are copying a template and hoping the auditor agrees.
Mistakes That Show Up in Audits
Marking all 93 controls as applicable to look thorough. It creates evidence obligations you cannot meet, and gaps surface during the ISO 27001 audit.
Writing exclusion justifications that restate the control instead of explaining the business reason for excluding it.
Treating the Statement of Applicability as a one-time document. It should change whenever a new system, supplier, or location enters scope.
Leaving people controls to HR and technological controls to IT with nobody reconciling the two.
Managing Annex A Controls in Effivity
Spreadsheet-based control tracking breaks down at about the third internal audit, when nobody can tell which version of the Statement of Applicability was current at the time of a finding.
Effivity's information security management software ships with all 93 Annex A controls preloaded, links each control to the risks it treats, and auto-generates the Statement of Applicability from those links. Control owners, evidence, and review dates stay in one place, and every change carries a timestamp. Organisations using it report roughly 65 percent less effort on ISMS compliance work compared with manual methods.
Try Effivity for Free and see the full Annex A control library mapped against your own risk register.
Frequently Asked Questions
There are 93 controls in ISO/IEC 27001:2022, reduced from 114 in the 2013 version. They sit across four themes.
No. You must consider every control, but only apply the ones your risk assessment justifies. Exclusions need documented reasons.
Organizational (37 controls), People (8), Physical (14), and Technological (34). Together they make up the full set of 93.
ISO 27001 lists the controls and is certifiable. ISO 27002 explains how to implement each one and is guidance only.
Eleven were added, including threat intelligence, cloud services security, configuration management, data masking, and secure coding.
In the Statement of Applicability, which lists each control, its applicability status, the justification, and its implementation state.