ISO 27001 Annex A controls explained: the reference set of 93 controls grouped into four themes, in plain language, plus how you decide which ones apply to you.
TL;DR
Annex A of ISO 27001:2022 is a reference catalogue of 93 security controls, grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34). The 2022 revision reorganised the older 114 controls and added 11 new ones.
Annex A is a menu, not a mandatory checklist. Your risk assessment decides which controls apply, and you record those choices in the Statement of Applicability.
On this page
How the ISO 27001 Annex A controls are structured
Annex A of ISO/IEC 27001:2022 contains 93 controls, reorganised from the 114 controls and 14 domains of the 2013 version into four clean themes. Each control also mirrors ISO 27002:2022, which is the companion standard that describes how to implement each one in detail.
Organizational controls (37)
The largest theme. These cover the policies, responsibilities, and processes that set the direction for your whole security program, from access control policy and supplier relationships to incident management and threat intelligence.
People controls (8)
The smallest theme, and one that no platform can run for you. People are a critical part of the security equation, and these controls cover the human side of the employment lifecycle: screening, terms of employment, security awareness, disciplinary process, and responsibilities after employment ends.
Physical controls (14)
These protect the physical environment your information lives in. Just as important as the digital side, and largely tied to your premises and hardware: secure areas, physical entry, equipment protection, secure disposal, and clear-desk practices.
Technological controls (34)
The second-largest theme, and the one most people picture when they think of security controls. This is where tooling does most of the work: access control, encryption, logging and monitoring, secure development, malware protection, backup, and network security.
The 11 new controls in the 2022 revision
The 2022 update did not just reshuffle. It added 11 entirely new controls to reflect how security has changed, especially the shift to cloud and modern development. These are often the most relevant controls for a modern SaaS startup.
| New control | What it addresses |
|---|---|
| 5.7 Threat intelligence | Gathering and using information about threats |
| 5.23 Cloud services | Information security for the use of cloud services |
| 5.30 ICT readiness | ICT readiness for business continuity |
| 7.4 Physical monitoring | Physical security monitoring |
| 8.9 Configuration management | Managing secure configurations of systems |
| 8.10 Information deletion | Deleting data when no longer required |
| 8.11 Data masking | Masking sensitive data in use |
| 8.12 Data leakage prevention | Preventing unauthorised data exfiltration |
| 8.16 Monitoring activities | Monitoring systems for anomalous behaviour |
| 8.23 Web filtering | Managing access to external websites |
| 8.28 Secure coding | Secure coding principles in development |
Annex A is a menu: the Statement of Applicability
The most important thing to understand about Annex A is that it is a reference set, not a checklist you must complete. The mandatory requirements of ISO 27001 live in Clauses 4 to 10 (the ISMS itself). Annex A is where your risk assessment turns into specific choices.
Which Annex A controls a platform can actually cover
Here is the honest picture, because it saves you real confusion at scoping time. No platform can deliver all 93 controls, and any tool that claims to is overselling. The controls split by owner: some are technical and tool-driven, some are organisational and policy-driven, and some, like the People controls, are inherently human.
Cover the controls that carry the weight, on one platform.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the technological and organizational controls Annex A calls for, map them to ISO 27001 automatically, and let the certificate follow from security that genuinely operates. No security team required.
Frequently asked questions
How many controls are in ISO 27001 Annex A?
ISO 27001:2022 Annex A contains 93 controls, grouped into four themes: 37 Organizational (A.5.1-5.37), 8 People (A.6.1-6.8), 14 Physical (A.7.1-7.14), and 34 Technological (A.8.1-8.34). This replaced the 2013 version’s 114 controls across 14 domains.
Do I have to implement all 93 Annex A controls?
No. Annex A is a reference menu, not a mandatory checklist. Your risk assessment decides which controls apply. You then document every inclusion and exclusion, with justification, in the Statement of Applicability.
What are the four themes of Annex A?
Organizational (37 controls covering policy and governance), People (8 covering the human side of employment), Physical (14 covering premises and equipment), and Technological (34 covering access control, encryption, logging, secure development, and more).
What are the 11 new controls in ISO 27001:2022?
Threat intelligence, cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Most reflect the shift to cloud and modern development.
What is the difference between Annex A and ISO 27002?
Annex A lists the controls with short titles; ISO 27002:2022 is the companion standard that explains how to implement each one in detail. Annex A tells you what; ISO 27002 tells you how.

