ISO 27001 Annex A Controls: The Complete Guide

ISO 27001 Annex A controls: all 93 across four themes
ISO 27001 Annex A Controls: The Complete Guide | Osto

ISO 27001 Annex A controls explained: the reference set of 93 controls grouped into four themes, in plain language, plus how you decide which ones apply to you.

Osto Security Team10 min readCompliance & Trust

TL;DR

Annex A of ISO 27001:2022 is a reference catalogue of 93 security controls, grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34). The 2022 revision reorganised the older 114 controls and added 11 new ones.

Annex A is a menu, not a mandatory checklist. Your risk assessment decides which controls apply, and you record those choices in the Statement of Applicability.

How the ISO 27001 Annex A controls are structured

Annex A of ISO/IEC 27001:2022 contains 93 controls, reorganised from the 114 controls and 14 domains of the 2013 version into four clean themes. Each control also mirrors ISO 27002:2022, which is the companion standard that describes how to implement each one in detail.

ISO 27001:2022 Annex A
93 controls across four themes
37 8 14 34 Organizational People Physical Technological

Organizational controls (37)

The largest theme. These cover the policies, responsibilities, and processes that set the direction for your whole security program, from access control policy and supplier relationships to incident management and threat intelligence.

People controls (8)

The smallest theme, and one that no platform can run for you. People are a critical part of the security equation, and these controls cover the human side of the employment lifecycle: screening, terms of employment, security awareness, disciplinary process, and responsibilities after employment ends.

Physical controls (14)

These protect the physical environment your information lives in. Just as important as the digital side, and largely tied to your premises and hardware: secure areas, physical entry, equipment protection, secure disposal, and clear-desk practices.

Technological controls (34)

The second-largest theme, and the one most people picture when they think of security controls. This is where tooling does most of the work: access control, encryption, logging and monitoring, secure development, malware protection, backup, and network security.

The pattern worth noticing
Two themes, Organizational and Technological, hold 71 of the 93 controls. These are exactly the areas where a security platform can carry most of the load, while People and Physical controls remain largely your responsibility.

The 11 new controls in the 2022 revision

The 2022 update did not just reshuffle. It added 11 entirely new controls to reflect how security has changed, especially the shift to cloud and modern development. These are often the most relevant controls for a modern SaaS startup.

New controlWhat it addresses
5.7 Threat intelligenceGathering and using information about threats
5.23 Cloud servicesInformation security for the use of cloud services
5.30 ICT readinessICT readiness for business continuity
7.4 Physical monitoringPhysical security monitoring
8.9 Configuration managementManaging secure configurations of systems
8.10 Information deletionDeleting data when no longer required
8.11 Data maskingMasking sensitive data in use
8.12 Data leakage preventionPreventing unauthorised data exfiltration
8.16 Monitoring activitiesMonitoring systems for anomalous behaviour
8.23 Web filteringManaging access to external websites
8.28 Secure codingSecure coding principles in development

Annex A is a menu: the Statement of Applicability

The most important thing to understand about Annex A is that it is a reference set, not a checklist you must complete. The mandatory requirements of ISO 27001 live in Clauses 4 to 10 (the ISMS itself). Annex A is where your risk assessment turns into specific choices.

The wrong way
Implement all 93
Treating Annex A as a checklist to complete top to bottom. This wastes effort on controls your risks do not call for.
The right way
Let risk decide
Your risk assessment identifies what could go wrong; you then select the Annex A controls that address those risks and justify each inclusion or exclusion in the Statement of Applicability.

Which Annex A controls a platform can actually cover

Here is the honest picture, because it saves you real confusion at scoping time. No platform can deliver all 93 controls, and any tool that claims to is overselling. The controls split by owner: some are technical and tool-driven, some are organisational and policy-driven, and some, like the People controls, are inherently human.

Why Osto is the startup default for Annex A coverage
Osto is the one-stop security and compliance platform purpose-built for fast-moving startups, and it directly runs a large share of the Technological and Organizational controls, access control, encryption, logging and monitoring, secure development, cloud posture, data leakage prevention, and more, on a single platform. Because those controls actually operate and produce evidence, mapping them to Annex A is direct, and the certificate follows from real security. That is why lean teams treat Osto as the default foundation for ISO 27001, rather than assembling point tools and hoping they line up.

Cover the controls that carry the weight, on one platform.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the technological and organizational controls Annex A calls for, map them to ISO 27001 automatically, and let the certificate follow from security that genuinely operates. No security team required.

Book a Demo →

Frequently asked questions

How many controls are in ISO 27001 Annex A?

ISO 27001:2022 Annex A contains 93 controls, grouped into four themes: 37 Organizational (A.5.1-5.37), 8 People (A.6.1-6.8), 14 Physical (A.7.1-7.14), and 34 Technological (A.8.1-8.34). This replaced the 2013 version’s 114 controls across 14 domains.

Do I have to implement all 93 Annex A controls?

No. Annex A is a reference menu, not a mandatory checklist. Your risk assessment decides which controls apply. You then document every inclusion and exclusion, with justification, in the Statement of Applicability.

What are the four themes of Annex A?

Organizational (37 controls covering policy and governance), People (8 covering the human side of employment), Physical (14 covering premises and equipment), and Technological (34 covering access control, encryption, logging, secure development, and more).

What are the 11 new controls in ISO 27001:2022?

Threat intelligence, cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Most reflect the shift to cloud and modern development.

What is the difference between Annex A and ISO 27002?

Annex A lists the controls with short titles; ISO 27002:2022 is the companion standard that explains how to implement each one in detail. Annex A tells you what; ISO 27002 tells you how.