Annex A is the catalogue of 93 security controls published with ISO 27001. You select from it based on your risk assessment, and record every decision in the Statement of Applicability.
The short answer
Annex A of ISO/IEC 27001:2022 lists 93 controls across four groups: A.5 organisational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). Each is one line long. ISO 27002 is the companion document explaining how to implement them.
On this page
How Annex A is numbered
Controls are referenced by group and number, so A.8.8 means the eighth control in the technological group. Auditors, questionnaires and compliance tools all use these references, so it is worth knowing which range covers what.
The 11 controls added in 2022
The 2013 edition had 114 controls in 14 domains. The 2022 edition regrouped them into 93 and added eleven that did not exist when the previous version was written. If you are moving from the old edition, these are the gaps to close.
| Reference | Control | Why it was added |
|---|---|---|
| A.5.7 | Threat intelligence | Defence should reflect what attackers are currently doing |
| A.5.23 | Cloud services security | Most infrastructure is now someone else’s |
| A.5.30 | ICT readiness for continuity | Recovery objectives have to be tested, not assumed |
| A.7.4 | Physical security monitoring | Detection of physical intrusion, not just prevention |
| A.8.9 | Configuration management | Misconfiguration overtook exploits as a breach cause |
| A.8.10 | Information deletion | Privacy laws now require data to be removed on request |
| A.8.11 | Data masking | Limits exposure in non-production and analytics |
| A.8.12 | Data leakage prevention | Insider and accidental loss became a primary risk |
| A.8.16 | Monitoring activities | Logging alone is not detection |
| A.8.23 | Web filtering | Blocks a common malware delivery path |
| A.8.28 | Secure coding | Security moved earlier into development |
Which controls apply to you
Controls follow risk. You assess risks, decide how to treat each one, then check those treatments against Annex A to confirm nothing obvious was missed. Every control is then marked applicable or not in the Statement of Applicability, with a reason.
| Exclusion | Defensible when |
|---|---|
| A.7 physical controls, in part | Fully remote, no offices or data centres in the certified scope |
| A.8.28 secure coding | No software is developed in house within scope |
| A.7.12 cabling security | No owned network infrastructure, everything cloud hosted |
| A.8.8 technical vulnerability management | Almost never. Expect a challenge if you exclude this |
Applicable is not the same as implemented
The SoA has two separate columns for a reason. A control can be applicable and still be in progress. Marking everything implemented when it is not is the fastest route to a Stage 2 nonconformity.
Controls a SaaS startup always needs
Scope varies, but a cloud software company with customer data will be asked about these in almost every audit and every security questionnaire.
| Reference | Control | What the auditor looks for |
|---|---|---|
| A.5.1 | Policies for information security | Approved, dated, communicated, reviewed |
| A.5.15 | Access control | Least privilege, joiner and leaver records |
| A.5.23 | Cloud services security | How you assess and monitor your providers |
| A.5.24 | Incident management planning | A tested plan with named responders |
| A.6.3 | Awareness and training | Completion records, not just a deck |
| A.8.5 | Secure authentication | MFA enforced, exceptions documented |
| A.8.8 | Technical vulnerability management | Scanning, remediation timeframes, evidence of closure |
| A.8.13 | Information backup | Backups taken, encrypted, and restore tested |
| A.8.15 | Logging | What is logged, retained how long, reviewed by whom |
| A.8.24 | Use of cryptography | A key management policy, not just encryption switched on |
Which controls Osto covers
Most of A.8 is deployed rather than written. Osto covers secure authentication (A.8.5), malware protection (A.8.7), technical vulnerability management (A.8.8), configuration management (A.8.9), data leakage prevention (A.8.12), logging and monitoring (A.8.15 and A.8.16), cryptography in transit (A.8.24) and web filtering (A.8.23), along with cloud services security (A.5.23), with evidence mapped to each reference. The A.6 people controls and most of A.7 stay with you, because they describe how your organisation behaves rather than how your systems are configured.
Free security assessment
Most of A.8 is deployed, not written
Osto runs the technological controls directly, from secure authentication to logging, with evidence mapped to each Annex A reference.
Get a free security assessment Book a platform walkthroughControls that actually run · Mapped evidence · One platform, everything
Frequently asked questions
How many controls are in Annex A?
Ninety-three in ISO/IEC 27001:2022, split into A.5 organisational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). The 2013 edition had 114 controls across 14 domains.
Are all Annex A controls mandatory?
No. Annex A is a reference catalogue. Controls are selected according to your risk assessment, and exclusions are permitted provided each is justified in the Statement of Applicability. Excluding a control because it is inconvenient is not acceptable.
What is the difference between Annex A and ISO 27002?
Annex A lists each control in a single line. ISO 27002 is a separate guidance document explaining the purpose of each control and how to implement it. Certification is against ISO 27001; there is no certification against ISO 27002.
What are the control attributes introduced in 2022?
Five optional tags on each control: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They let large programmes filter and group the catalogue. Small teams generally do not use them.
Which Annex A controls are hardest for startups?
Usually the ones needing sustained records rather than a one-time setup: A.6.3 awareness training with completion evidence, A.8.8 vulnerability management with remediation timeframes met, and A.8.13 backup with a tested restore. Auditors ask for history on all three.

