ISO 27001 Annex A Controls: Complete Guide

By July 25th, 2026ISO Audit And Certificate7 min read

ISO 27001 Annex A Controls: Complete Guide

ISO 27001 Annex A contains 93 controls organised across four domains that organisations must consider when implementing an Information Security Management System (ISMS). These controls are not mandatory checkboxes but rather a catalogue of safeguards you should evaluate based on your specific risk profile. Understanding Annex A is essential for achieving ISO 27001 certification and building a defensible security posture.

What Is ISO 27001 Annex A?

The ISO 27001 standard has two main parts: the requirements clauses (clauses 4 through 10) and Annex A. Clauses 4–10 define what an ISMS must do – things like leadership commitment, planning, operation, performance evaluation, and improvement. Annex A provides the “how” – a reference list of 93 controls grouped into four thematic domains.

Organisations typically use the ISO 27001 Annex A controls as a starting point for their risk treatment process. You do not need to implement every control. Instead, you assess which ones apply, document your rationale, and include them in your Statement of Applicability (SoA).

The Four Domains of Annex A (ISO 27001:2022)

The 2022 revision restructured Annex A from 14 domains down to four broader themes. This change makes the standard easier to navigate and aligns it with modern security thinking.

1. Organisational Controls (37 controls)

These address policies, roles, responsibilities, and governance. Key controls include information security policy, assignment of responsibilities, segregation of duties, project management security, and supplier relationships.

2. People Controls (8 controls)

Focused on human factors – screening, awareness training, disciplinary processes, and responsibilities after termination or change of employment. People remain the weakest link in most security programmes.

3. Physical Controls (14 controls)

Covering physical security perimeters, entry controls, equipment security, clear desk policy, and secure disposal. These protect your tangible assets against theft, damage, or unauthorised access.

4. Technological Controls (34 controls)

The largest domain covering endpoint protection, network security, access control, cryptography, logging, backup, and vulnerability management. Technology controls often require the most investment to implement.

Annex A Controls Table by Domain

The table below provides a high-level reference of controls within each domain. This is a condensed view; the full standard describes each control in detail including its purpose and implementation guidance.

DomainControl AreaNumber of ControlsKey Controls
OrganisationalInformation security policies37Policy management, roles and responsibilities, project security, supplier management, threat intelligence
PeopleHuman resource security8Screening, awareness training, disciplinary process, confidentiality agreements
PhysicalPhysical and environmental security14Physical perimeter, entry control, equipment security, clear desk, secure disposal
TechnologicalTechnical security controls34Access control, cryptography, network security, backup, logging, vulnerability management

Statement of Applicability Explained

The Statement of Applicability (SoA) is a mandatory document required for ISO 27001 certification. It lists every control from Annex A and states whether it is applicable to your organisation, along with justification for inclusion or exclusion.

A well-prepared SoA includes:

  • Control reference (e.g. A.5.1, A.8.12)
  • Control name and description
  • Applicability status (Applicable or Excluded)
  • Justification for the decision
  • Reference to the risk assessment or policy that supports the decision
  • Implementation status (if applicable)

Control Selection Process

Selecting the right controls follows a clear sequence within the ISMS framework:

  1. Establish the ISMS context (clause 4) – understand your organisation, stakeholders, and scope.
  2. Conduct a risk assessment (clause 6.1) – identify and analyse risks to information security.
  3. Determine risk treatment options – accept, mitigate, transfer, or avoid each risk.
  4. Select Annex A controls – choose controls that address the identified risks.
  5. Document the SoA – record which controls are selected and why.
  6. Implement controls – deploy the chosen safeguards and document procedures.
  7. Monitor and review – continuously assess effectiveness as part of the ISMS.

Common Controls by Industry

Different industries prioritise different controls based on their risk landscape. The table below shows typical focus areas.

IndustryTop Priority ControlsRationale
Financial servicesAccess control, cryptography, logging, supplier managementRegulatory compliance, customer data protection, audit trails
HealthcareAccess control, backup, incident management, asset managementPatient data confidentiality, availability of critical systems
Technology / SaaSVulnerability management, network security, change managementCloud infrastructure security, rapid development cycles
GovernmentPhysical security, segregation of duties, business continuityNational security, public trust, service continuity
ManufacturingPhysical security, asset management, supplier managementOperational technology protection, supply chain integrity

Implementing Annex A Controls: A Practical Approach

Organisations often struggle with where to start. A phased approach reduces overwhelm and builds momentum:

  • Phase 1 – Governance: Implement organisational controls first – policy framework, roles, risk assessment process. These form the foundation.
  • Phase 2 – People and Physical: Address awareness training, physical security, and asset management. These are typically lower cost but high impact.
  • Phase 3 – Technological: Deploy technical controls such as access control, backup, and monitoring. These require coordination with IT teams.
  • Phase 4 – Review and Optimise: Conduct internal audits, management reviews, and update the SoA based on lessons learned.

Common Pitfalls and How to Avoid Them

Organisations pursuing ISO 27001 certification often make the same mistakes when handling Annex A controls. Awareness of these pitfalls can save time and cost.

PitfallWhy It HappensSolution
Implementing all 93 controlsMisunderstanding that certification requires every controlConduct a proper risk assessment and only implement controls that address identified risks
Treating the SoA as a tick-boxLack of understanding of the purpose of SoADocument genuine justifications; the auditor will challenge weak exclusions
Ignoring organisational contextNot investing time in clause 4 requirementsThoroughly document your context, stakeholders, and scope before control selection
Overlooking supplier controlsFocusing only on internal operationsInclude third-party risk management and supplier agreements in your scope
No continuous improvementTreating certification as the finish lineBuild review cycles and corrective actions into your ISMS processes

Frequently Asked Questions

Do I need to implement all Annex A controls?

No. You only need to implement controls that address the risks identified in your risk assessment. Controls that are not applicable can be excluded, but you must justify the exclusion in your Statement of Applicability.

What is the difference between Clause 4–10 and Annex A?

Clauses 4–10 contain the mandatory requirements for the ISMS itself – the system of policies, processes, and reviews. Annex A provides a reference catalogue of controls that you select from to treat the risks identified during risk assessment.

How often should the Statement of Applicability be reviewed?

The SoA should be reviewed at least annually during the management review process, or whenever significant changes occur – such as new systems, regulatory changes, or major organisational restructuring.

Can I add controls not listed in Annex A?

Yes. Annex A is a reference list, not an exhaustive catalogue. If your risk assessment identifies a risk that is not addressed by existing Annex A controls, you can implement additional controls and document them in your SoA.

What changed in Annex A between the 2013 and 2022 versions?

The 2022 revision reduced the number of controls from 114 to 93 and restructured them from 14 domains into 4 themes. Many controls were merged, and new controls were added for threat intelligence, cloud security, and data masking.

How do Annex A controls map to other frameworks like NIST?

ISO 27001 Annex A and NIST CSF have significant overlap. Many organisations use cross-reference mappings to demonstrate alignment with both frameworks. The ISO provides a mapping guide, and several consultancies publish comparison tables.

Getting Started with ISO 27001 Annex A

Understanding and implementing Annex A controls is a substantial but manageable undertaking. Start with your risk assessment, build your SoA methodically, and focus on controls that genuinely reduce risk rather than trying to do everything at once.

If you need expert guidance with your ISMS implementation or ISO 27001 certification journey, our team can help you select, implement, and audit Annex A controls tailored to your organisation. Contact Bitrixme today or reach out on WhatsApp to discuss your requirements.