GlossaryISO 27001

Annex A

Short answer

Annex A is the section of ISO 27001 that lists the reference set of information security controls. The 2022 version contains 93 controls grouped into four themes, and organisations select the ones they need based on their risk assessment.

The four themes

In ISO 27001:2022, Annex A groups its 93 controls into four themes: organisational controls (37), people controls (8), physical controls (14) and technological controls (34).

What changed in 2022

The 2013 version had 114 controls in 14 domains. The 2022 revision merged many of them and added 11 new controls, including threat intelligence, information security for cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities, web filtering and secure coding.

Are all controls mandatory?

No. The organisation decides which controls apply based on its risk assessment, and records the decision in the Statement of Applicability. Excluded controls must be justified.

Annex A and ISO 27002

Annex A only lists each control in a sentence or two. ISO 27002 gives detailed guidance on how to implement each one.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub