ISO 27001 Annex A Controls: The Four Themes (2022)
Annex A is the catalogue of security controls you select from when implementing ISO 27001. The 2022 revision reorganised it significantly from the older 2013 layout.
There are now 93 controls grouped into four themes. You do not implement all of them blindly, you select the relevant ones based on your risk assessment and justify the rest in your Statement of Applicability.
Organisational controls
The largest group covers policies, roles, supplier relationships, threat intelligence, information classification, and more, the governance backbone of the ISMS.
People controls
These address the human side: screening, terms of employment, awareness and training, disciplinary process, and responsibilities after employment ends.
Physical controls
Physical controls protect facilities and equipment, secure areas, clear desk and screen, equipment maintenance, and secure disposal.
Technological controls
The technical group covers access control, cryptography, logging and monitoring, secure development, vulnerability management, and data protection, the controls most often automated by tooling.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate ISO 27001 with Vanta
Vanta maps the controls, collects evidence automatically, and keeps you audit-ready. The market-leading compliance automation platform.
FAQ
- How many Annex A controls are there in the 2022 version?
- 93 controls, down from 114 in 2013, reorganised into four themes.
- Do I have to implement every Annex A control?
- No. You select controls based on your risk assessment and justify inclusions and exclusions in the Statement of Applicability.
- What are the four themes?
- Organisational, people, physical, and technological.