All 93 ISO 27001 Annex A Controls
The ISO 27001:2022 Annex A controls, grouped into four themes. Each control below links to what it requires, how to meet it, and a practical tip. Pick the controls relevant to your risks and justify the rest in your Statement of Applicability.

Organizational controls
The 37 organizational controls cover policies, roles, supplier and cloud security, incident management, and legal obligations. They are the governance backbone of the ISMS.
A.6 · 8 controlsPeople controls
The 8 people controls cover the human side: screening, employment terms, awareness, and what happens when people join, move, or leave.
A.7 · 14 controlsPhysical controls
The 14 physical controls protect facilities, equipment, and media. They apply even to cloud-first companies (offices, laptops, disposal).
A.8 · 34 controlsTechnological controls
The 34 technological controls are where most engineering effort lands: access, cryptography, logging, secure development, networks, and backups.
Need the documents? Grab our ISO 27001 templates (Statement of Applicability, risk register, policies, and more).
ISO 27001 documents, evidence, and software path
SoA, risk register, access, supplier, incident, backup, crypto, endpoint, and secure development records.