ISO 27001 Annex A Controls: Complete Guide
ISO 27001 Annex A contains 93 controls organised across four domains that organisations must consider when implementing an Information Security Management System (ISMS). These controls are not mandatory checkboxes but rather a catalogue of safeguards you should evaluate based on your specific risk profile. Understanding Annex A is essential for achieving ISO 27001 certification and building a defensible security posture.
What Is ISO 27001 Annex A?
The ISO 27001 standard has two main parts: the requirements clauses (clauses 4 through 10) and Annex A. Clauses 4–10 define what an ISMS must do – things like leadership commitment, planning, operation, performance evaluation, and improvement. Annex A provides the “how” – a reference list of 93 controls grouped into four thematic domains.
Organisations typically use the ISO 27001 Annex A controls as a starting point for their risk treatment process. You do not need to implement every control. Instead, you assess which ones apply, document your rationale, and include them in your Statement of Applicability (SoA).
The Four Domains of Annex A (ISO 27001:2022)
The 2022 revision restructured Annex A from 14 domains down to four broader themes. This change makes the standard easier to navigate and aligns it with modern security thinking.
1. Organisational Controls (37 controls)
These address policies, roles, responsibilities, and governance. Key controls include information security policy, assignment of responsibilities, segregation of duties, project management security, and supplier relationships.
2. People Controls (8 controls)
Focused on human factors – screening, awareness training, disciplinary processes, and responsibilities after termination or change of employment. People remain the weakest link in most security programmes.
3. Physical Controls (14 controls)
Covering physical security perimeters, entry controls, equipment security, clear desk policy, and secure disposal. These protect your tangible assets against theft, damage, or unauthorised access.
4. Technological Controls (34 controls)
The largest domain covering endpoint protection, network security, access control, cryptography, logging, backup, and vulnerability management. Technology controls often require the most investment to implement.
Annex A Controls Table by Domain
The table below provides a high-level reference of controls within each domain. This is a condensed view; the full standard describes each control in detail including its purpose and implementation guidance.
| Domain | Control Area | Number of Controls | Key Controls |
|---|---|---|---|
| Organisational | Information security policies | 37 | Policy management, roles and responsibilities, project security, supplier management, threat intelligence |
| People | Human resource security | 8 | Screening, awareness training, disciplinary process, confidentiality agreements |
| Physical | Physical and environmental security | 14 | Physical perimeter, entry control, equipment security, clear desk, secure disposal |
| Technological | Technical security controls | 34 | Access control, cryptography, network security, backup, logging, vulnerability management |
Statement of Applicability Explained
The Statement of Applicability (SoA) is a mandatory document required for ISO 27001 certification. It lists every control from Annex A and states whether it is applicable to your organisation, along with justification for inclusion or exclusion.
A well-prepared SoA includes:
- Control reference (e.g. A.5.1, A.8.12)
- Control name and description
- Applicability status (Applicable or Excluded)
- Justification for the decision
- Reference to the risk assessment or policy that supports the decision
- Implementation status (if applicable)
Control Selection Process
Selecting the right controls follows a clear sequence within the ISMS framework:
- Establish the ISMS context (clause 4) – understand your organisation, stakeholders, and scope.
- Conduct a risk assessment (clause 6.1) – identify and analyse risks to information security.
- Determine risk treatment options – accept, mitigate, transfer, or avoid each risk.
- Select Annex A controls – choose controls that address the identified risks.
- Document the SoA – record which controls are selected and why.
- Implement controls – deploy the chosen safeguards and document procedures.
- Monitor and review – continuously assess effectiveness as part of the ISMS.
Common Controls by Industry
Different industries prioritise different controls based on their risk landscape. The table below shows typical focus areas.
| Industry | Top Priority Controls | Rationale |
|---|---|---|
| Financial services | Access control, cryptography, logging, supplier management | Regulatory compliance, customer data protection, audit trails |
| Healthcare | Access control, backup, incident management, asset management | Patient data confidentiality, availability of critical systems |
| Technology / SaaS | Vulnerability management, network security, change management | Cloud infrastructure security, rapid development cycles |
| Government | Physical security, segregation of duties, business continuity | National security, public trust, service continuity |
| Manufacturing | Physical security, asset management, supplier management | Operational technology protection, supply chain integrity |
Implementing Annex A Controls: A Practical Approach
Organisations often struggle with where to start. A phased approach reduces overwhelm and builds momentum:
- Phase 1 – Governance: Implement organisational controls first – policy framework, roles, risk assessment process. These form the foundation.
- Phase 2 – People and Physical: Address awareness training, physical security, and asset management. These are typically lower cost but high impact.
- Phase 3 – Technological: Deploy technical controls such as access control, backup, and monitoring. These require coordination with IT teams.
- Phase 4 – Review and Optimise: Conduct internal audits, management reviews, and update the SoA based on lessons learned.
Common Pitfalls and How to Avoid Them
Organisations pursuing ISO 27001 certification often make the same mistakes when handling Annex A controls. Awareness of these pitfalls can save time and cost.
| Pitfall | Why It Happens | Solution |
|---|---|---|
| Implementing all 93 controls | Misunderstanding that certification requires every control | Conduct a proper risk assessment and only implement controls that address identified risks |
| Treating the SoA as a tick-box | Lack of understanding of the purpose of SoA | Document genuine justifications; the auditor will challenge weak exclusions |
| Ignoring organisational context | Not investing time in clause 4 requirements | Thoroughly document your context, stakeholders, and scope before control selection |
| Overlooking supplier controls | Focusing only on internal operations | Include third-party risk management and supplier agreements in your scope |
| No continuous improvement | Treating certification as the finish line | Build review cycles and corrective actions into your ISMS processes |
Frequently Asked Questions
Do I need to implement all Annex A controls?
No. You only need to implement controls that address the risks identified in your risk assessment. Controls that are not applicable can be excluded, but you must justify the exclusion in your Statement of Applicability.
What is the difference between Clause 4–10 and Annex A?
Clauses 4–10 contain the mandatory requirements for the ISMS itself – the system of policies, processes, and reviews. Annex A provides a reference catalogue of controls that you select from to treat the risks identified during risk assessment.
How often should the Statement of Applicability be reviewed?
The SoA should be reviewed at least annually during the management review process, or whenever significant changes occur – such as new systems, regulatory changes, or major organisational restructuring.
Can I add controls not listed in Annex A?
Yes. Annex A is a reference list, not an exhaustive catalogue. If your risk assessment identifies a risk that is not addressed by existing Annex A controls, you can implement additional controls and document them in your SoA.
What changed in Annex A between the 2013 and 2022 versions?
The 2022 revision reduced the number of controls from 114 to 93 and restructured them from 14 domains into 4 themes. Many controls were merged, and new controls were added for threat intelligence, cloud security, and data masking.
How do Annex A controls map to other frameworks like NIST?
ISO 27001 Annex A and NIST CSF have significant overlap. Many organisations use cross-reference mappings to demonstrate alignment with both frameworks. The ISO provides a mapping guide, and several consultancies publish comparison tables.
Getting Started with ISO 27001 Annex A
Understanding and implementing Annex A controls is a substantial but manageable undertaking. Start with your risk assessment, build your SoA methodically, and focus on controls that genuinely reduce risk rather than trying to do everything at once.
If you need expert guidance with your ISMS implementation or ISO 27001 certification journey, our team can help you select, implement, and audit Annex A controls tailored to your organisation. Contact Bitrixme today or reach out on WhatsApp to discuss your requirements.