ISO 27001 · 6 min read · Updated 2026-06-29

ISO 27001 Annex A Controls: The Four Themes (2022)

Annex A is the catalogue of security controls you select from when implementing ISO 27001. The 2022 revision reorganised it significantly from the older 2013 layout.

There are now 93 controls grouped into four themes. You do not implement all of them blindly, you select the relevant ones based on your risk assessment and justify the rest in your Statement of Applicability.

Organisational controls

The largest group covers policies, roles, supplier relationships, threat intelligence, information classification, and more, the governance backbone of the ISMS.

People controls

These address the human side: screening, terms of employment, awareness and training, disciplinary process, and responsibilities after employment ends.

Physical controls

Physical controls protect facilities and equipment, secure areas, clear desk and screen, equipment maintenance, and secure disposal.

Technological controls

The technical group covers access control, cryptography, logging and monitoring, secure development, vulnerability management, and data protection, the controls most often automated by tooling.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Automate ISO 27001 with Vanta

Vanta maps the controls, collects evidence automatically, and keeps you audit-ready. The market-leading compliance automation platform.

FAQ

How many Annex A controls are there in the 2022 version?
93 controls, down from 114 in 2013, reorganised into four themes.
Do I have to implement every Annex A control?
No. You select controls based on your risk assessment and justify inclusions and exclusions in the Statement of Applicability.
What are the four themes?
Organisational, people, physical, and technological.