Live 16 practitioner certifications live · First lesson free on every course Back to main site →

ISO/IEC 27001:2022 Annex A Controls

The 93 information security controls listed in Annex A of ISO/IEC 27001:2022, organised into 4 themes: Organisational, People, Physical, and Technological.

ISO/IEC 27001:2022, published in October 2022, restructured the Annex A control set from the previous 114 controls in 14 clauses (as in the 2013 edition) to 93 controls in 4 themes: Organisational controls (37), People controls (8), Physical controls (14), and Technological controls (34). Amendment 1:2024 added climate change considerations that must be integrated into risk assessment and treatment.

The 2022 revision introduced 11 new controls that did not exist in the 2013 standard: threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).

The Annex A controls interlock closely with the AICPA Trust Services Criteria for SOC 2 — the Common Criteria (Security) TSC and the ISO Annex A control set share roughly 60 percent of controls by count, which is why most Indian SaaS firms selling globally maintain a unified control set covering both. The dcomply Academy ISO/IEC 27001 Lead Implementer Certification walks all 93 controls including the 11 new ones and includes the SoA drafting workflow.

Cited authorities

  • ISO/IEC 27001:2022
  • ISO/IEC 27001:2022 Amendment 1:2024