All 93 ISO 27001 Annex A Controls

The ISO 27001:2022 Annex A controls, grouped into four themes. Each control below links to what it requires, how to meet it, and a practical tip. Pick the controls relevant to your risks and justify the rest in your Statement of Applicability.

ISO 27001 Annex A control map showing organisational, people, physical and technological control groups.
ISO Annex A map / 12 KB WebP

Need the documents? Grab our ISO 27001 templates (Statement of Applicability, risk register, policies, and more).

Audit-ready next steps

ISO 27001 documents, evidence, and software path

SoA, risk register, access, supplier, incident, backup, crypto, endpoint, and secure development records.