The four themes
In ISO 27001:2022, Annex A groups its 93 controls into four themes: organisational controls (37), people controls (8), physical controls (14) and technological controls (34).
What changed in 2022
The 2013 version had 114 controls in 14 domains. The 2022 revision merged many of them and added 11 new controls, including threat intelligence, information security for cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities, web filtering and secure coding.
Are all controls mandatory?
No. The organisation decides which controls apply based on its risk assessment, and records the decision in the Statement of Applicability. Excluded controls must be justified.
Annex A and ISO 27002
Annex A only lists each control in a sentence or two. ISO 27002 gives detailed guidance on how to implement each one.




