{"id":672,"date":"2026-08-13T09:37:49","date_gmt":"2026-08-13T09:37:49","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=672"},"modified":"2026-08-13T09:37:49","modified_gmt":"2026-08-13T09:37:49","slug":"annex-a-controls","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/","title":{"rendered":"ISO 27001 Annex A Controls Explained"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: ANNEX A CONTROLS\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Annex A is the catalogue of 93 security controls published with ISO 27001. You select from it based on your risk assessment, and record every decision in the Statement of Applicability.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Annex A of ISO\/IEC 27001:2022 lists 93 controls across four groups: A.5 organisational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). Each is one line long. ISO 27002 is the companion document explaining how to implement them.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#organised\">How Annex A is numbered<\/a><\/li>\n    <li><a href=\"#new\">The 11 controls added in 2022<\/a><\/li>\n    <li><a href=\"#select\">Which controls apply to you<\/a><\/li>\n    <li><a href=\"#startup\">Controls a SaaS startup always needs<\/a><\/li>\n    <li><a href=\"#osto\">Which controls Osto covers<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"organised\">How Annex A is numbered<\/h2>\n\n<p>Controls are referenced by group and number, so A.8.8 means the eighth control in the technological group. Auditors, questionnaires and compliance tools all use these references, so it is worth knowing which range covers what.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Annex A groups and control counts: A.5 organisational 37, A.8 technological 34, A.7 physical 14, A.6 people 8.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">93 CONTROLS IN FOUR NUMBERED GROUPS<\/text>\n\n  <text x=\"176\" y=\"66\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#0f1538\">A.5 Organisational<\/text>\n  <text x=\"176\" y=\"82\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">A.5.1 to A.5.37<\/text>\n  <rect x=\"190\" y=\"52\" width=\"420\" height=\"32\" rx=\"8\" fill=\"#1c267a\"\/>\n  <text x=\"596\" y=\"73\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">37<\/text>\n  <text x=\"626\" y=\"73\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">policies, suppliers<\/text>\n\n  <text x=\"176\" y=\"120\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#0f1538\">A.8 Technological<\/text>\n  <text x=\"176\" y=\"136\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">A.8.1 to A.8.34<\/text>\n  <rect x=\"190\" y=\"106\" width=\"386\" height=\"32\" rx=\"8\" fill=\"#4a52a8\"\/>\n  <text x=\"562\" y=\"127\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">34<\/text>\n  <text x=\"592\" y=\"127\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">access, crypto, logging<\/text>\n\n  <text x=\"176\" y=\"174\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#0f1538\">A.7 Physical<\/text>\n  <text x=\"176\" y=\"190\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">A.7.1 to A.7.14<\/text>\n  <rect x=\"190\" y=\"160\" width=\"159\" height=\"32\" rx=\"8\" fill=\"#7b9dc9\"\/>\n  <text x=\"335\" y=\"181\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">14<\/text>\n  <text x=\"365\" y=\"181\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">facilities, equipment, disposal<\/text>\n\n  <text x=\"176\" y=\"228\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#0f1538\">A.6 People<\/text>\n  <text x=\"176\" y=\"244\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">A.6.1 to A.6.8<\/text>\n  <rect x=\"190\" y=\"214\" width=\"91\" height=\"32\" rx=\"8\" fill=\"#c2d9ec\"\/>\n  <text x=\"267\" y=\"235\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">8<\/text>\n  <text x=\"297\" y=\"235\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">screening, training, offboarding<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full chart. <\/span>A.5 and A.8 hold three quarters of Annex A between them, which is where most implementation effort goes.<\/figcaption>\n<\/figure>\n\n<h2 id=\"new\" class=\"c-sage\">The 11 controls added in 2022<\/h2>\n\n<p>The 2013 edition had 114 controls in 14 domains. The 2022 edition regrouped them into 93 and added eleven that did not exist when the previous version was written. If you are moving from the old edition, these are the gaps to close.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Reference<\/th><th>Control<\/th><th>Why it was added<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>A.5.7<\/strong><\/td><td>Threat intelligence<\/td><td>Defence should reflect what attackers are currently doing<\/td><\/tr>\n    <tr><td><strong>A.5.23<\/strong><\/td><td>Cloud services security<\/td><td>Most infrastructure is now someone else&#8217;s<\/td><\/tr>\n    <tr><td><strong>A.5.30<\/strong><\/td><td>ICT readiness for continuity<\/td><td>Recovery objectives have to be tested, not assumed<\/td><\/tr>\n    <tr><td><strong>A.7.4<\/strong><\/td><td>Physical security monitoring<\/td><td>Detection of physical intrusion, not just prevention<\/td><\/tr>\n    <tr><td><strong>A.8.9<\/strong><\/td><td>Configuration management<\/td><td>Misconfiguration overtook exploits as a breach cause<\/td><\/tr>\n    <tr><td><strong>A.8.10<\/strong><\/td><td>Information deletion<\/td><td>Privacy laws now require data to be removed on request<\/td><\/tr>\n    <tr><td><strong>A.8.11<\/strong><\/td><td>Data masking<\/td><td>Limits exposure in non-production and analytics<\/td><\/tr>\n    <tr><td><strong>A.8.12<\/strong><\/td><td>Data leakage prevention<\/td><td>Insider and accidental loss became a primary risk<\/td><\/tr>\n    <tr><td><strong>A.8.16<\/strong><\/td><td>Monitoring activities<\/td><td>Logging alone is not detection<\/td><\/tr>\n    <tr><td><strong>A.8.23<\/strong><\/td><td>Web filtering<\/td><td>Blocks a common malware delivery path<\/td><\/tr>\n    <tr><td><strong>A.8.28<\/strong><\/td><td>Secure coding<\/td><td>Security moved earlier into development<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"select\" class=\"c-apri\">Which controls apply to you<\/h2>\n\n<p>Controls follow risk. You assess risks, decide how to treat each one, then check those treatments against Annex A to confirm nothing obvious was missed. Every control is then marked applicable or not in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a>, with a reason.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Exclusion<\/th><th>Defensible when<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>A.7 physical controls, in part<\/td><td>Fully remote, no offices or data centres in the certified scope<\/td><\/tr>\n    <tr><td>A.8.28 secure coding<\/td><td>No software is developed in house within scope<\/td><\/tr>\n    <tr><td>A.7.12 cabling security<\/td><td>No owned network infrastructure, everything cloud hosted<\/td><\/tr>\n    <tr><td>A.8.8 technical <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">vulnerability management<\/a><\/td><td>Almost never. Expect a challenge if you exclude this<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Applicable is not the same as implemented<\/p>\n  <p>The SoA has two separate columns for a reason. A control can be applicable and still be in progress. Marking everything implemented when it is not is the fastest route to a Stage 2 nonconformity.<\/p>\n<\/div>\n\n<h2 id=\"startup\" class=\"c-plum\">Controls a SaaS startup always needs<\/h2>\n\n<p>Scope varies, but a cloud software company with customer data will be asked about these in almost every audit and every security questionnaire.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Reference<\/th><th>Control<\/th><th>What the auditor looks for<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>A.5.1<\/strong><\/td><td>Policies for information security<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-policies-documentation\/\">Approved, dated, communicated, reviewed<\/a><\/td><\/tr>\n    <tr><td><strong>A.5.15<\/strong><\/td><td>Access control<\/td><td>Least privilege, joiner and leaver records<\/td><\/tr>\n    <tr><td><strong>A.5.23<\/strong><\/td><td>Cloud services security<\/td><td>How you assess and monitor your providers<\/td><\/tr>\n    <tr><td><strong>A.5.24<\/strong><\/td><td>Incident management planning<\/td><td>A tested plan with named responders<\/td><\/tr>\n    <tr><td><strong>A.6.3<\/strong><\/td><td>Awareness and training<\/td><td>Completion records, not just a deck<\/td><\/tr>\n    <tr><td><strong>A.8.5<\/strong><\/td><td>Secure authentication<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> enforced, exceptions documented<\/td><\/tr>\n    <tr><td><strong>A.8.8<\/strong><\/td><td>Technical vulnerability management<\/td><td>Scanning, remediation timeframes, evidence of closure<\/td><\/tr>\n    <tr><td><strong>A.8.13<\/strong><\/td><td>Information backup<\/td><td>Backups taken, encrypted, and restore tested<\/td><\/tr>\n    <tr><td><strong>A.8.15<\/strong><\/td><td>Logging<\/td><td>What is logged, retained how long, reviewed by whom<\/td><\/tr>\n    <tr><td><strong>A.8.24<\/strong><\/td><td>Use of cryptography<\/td><td>A key management policy, not just encryption switched on<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">Which controls Osto covers<\/h2>\n\n<p>Most of A.8 is deployed rather than written. Osto covers secure authentication (A.8.5), malware protection (A.8.7), technical vulnerability management (A.8.8), configuration management (A.8.9), data leakage prevention (A.8.12), logging and monitoring (A.8.15 and A.8.16), cryptography in transit (A.8.24) and web filtering (A.8.23), along with cloud services security (A.5.23), with evidence mapped to each reference. The A.6 people controls and most of A.7 stay with you, because they describe how your organisation behaves rather than how your systems are configured.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Most of A.8 is deployed, not written<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto runs the technological controls directly, from secure authentication to logging, with evidence mapped to each Annex A reference.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Controls that actually run &middot; Mapped evidence &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>How many controls are in Annex A?<\/summary>\n  <p>Ninety-three in ISO\/IEC 27001:2022, split into A.5 organisational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). The 2013 edition had 114 controls across 14 domains.<\/p>\n<\/details>\n\n<details>\n  <summary>Are all Annex A controls mandatory?<\/summary>\n  <p>No. Annex A is a reference catalogue. Controls are selected according to your risk assessment, and exclusions are permitted provided each is justified in the Statement of Applicability. Excluding a control because it is inconvenient is not acceptable.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between Annex A and ISO 27002?<\/summary>\n  <p>Annex A lists each control in a single line. ISO 27002 is a separate guidance document explaining the purpose of each control and how to implement it. Certification is against ISO 27001; there is no certification against ISO 27002.<\/p>\n<\/details>\n\n<details>\n  <summary>What are the control attributes introduced in 2022?<\/summary>\n  <p>Five optional tags on each control: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They let large programmes filter and group the catalogue. Small teams generally do not use them.<\/p>\n<\/details>\n\n<details>\n  <summary>Which Annex A controls are hardest for startups?<\/summary>\n  <p>Usually the ones needing sustained records rather than a one-time setup: A.6.3 awareness training with completion evidence, A.8.8 vulnerability management with remediation timeframes met, and A.8.13 backup with a tested restore. Auditors ask for history on all three.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-treatment-plan\/\">Risk Treatment Plan<\/a> &middot; ISO 27002<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Annex A is the catalogue of 93 security controls published with ISO 27001. You select from it based on your\u2026<\/p>\n","protected":false},"author":8,"featured_media":673,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[254,251,252,253],"class_list":["post-672","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-93-controls-iso-27001","tag-annex-a-controls","tag-iso-27001-annex-a","tag-iso-27001-controls-list"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/672","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=672"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/672\/revisions"}],"predecessor-version":[{"id":674,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/672\/revisions\/674"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/673"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}