What Annex A is for
Annex A of ISO/IEC 27001:2022 is a reference list of information security controls. It is normative, which means certification auditors will check how it was used. It isn't a full checklist. Clause 6.1.3 asks the organization to pick the controls its risk treatment needs, from any source, and then compare that selection with Annex A so that nothing necessary is missed by accident.
The result is the Statement of Applicability. It lists each Annex A control, says whether it applies, explains why it was included or left out, and states whether it's in place. Auditors treat this document as a map of the ISMS. A weak Statement of Applicability is one of the most common audit findings.
The 4 themes
The 2022 edition groups 93 controls into 4 themes. Each control has a short title and a 1-sentence control statement in ISO/IEC 27001, while ISO/IEC 27002:2022 gives the purpose, implementation guidance, and attributes for each one.
- Organizational controls, 37 controls numbered 5.1 to 5.37, covering policy, roles, assets, access, suppliers, incidents, continuity, and compliance
- People controls, 8 controls numbered 6.1 to 6.8, covering screening, employment terms, training, discipline, confidentiality, remote work, and event reporting
- Physical controls, 14 controls numbered 7.1 to 7.14, covering perimeters, entry, facilities, monitoring, environmental threats, equipment, and media
- Technological controls, 34 controls numbered 8.1 to 8.34, covering endpoints, privileged access, authentication, malware, vulnerabilities, logging, networks, cryptography, and development
The 11 new controls
According to the IAF transition document for the 2022 edition, 11 controls are new, 24 were formed by merging older controls, and 58 were updated. The new ones reflect how organizations work today, with more cloud services, more remote access, and more attention to data handling.
- 5.7 Threat intelligence
- 5.23 Information security for use of cloud services
- 5.30 ICT readiness for business continuity
- 7.4 Physical security monitoring
- 8.9 Configuration management
- 8.10 Information deletion
- 8.11 Data masking
- 8.12 Data leakage prevention
- 8.16 Monitoring activities
- 8.23 Web filtering
- 8.28 Secure coding
What changed from the 2013 list
The 2013 edition had 114 controls in 14 clauses, each clause with a control objective. The 2022 edition drops the objectives, cuts the count to 93, and sorts controls by theme rather than by topic area. Many familiar controls survive with new numbers. Several older controls on topics such as malware, logging, and access rights were folded together, which is why the total fell even though new controls were added.
ISO/IEC 27002:2022 also gives every control a set of attributes, such as control type and cybersecurity concept. They're optional. Organizations can use them to filter controls, build views for different audiences, or map the list to other frameworks such as the NIST Cybersecurity Framework.
Using the controls in practice
Most organizations start with a risk assessment, decide how each risk will be treated, and then match the needed controls against Annex A. Controls that are excluded need a clear reason tied to the scope or the risk assessment, such as having no physical office within the scope. Auditors test those reasons.
Some controls come from outside Annex A. ISO/IEC 27017 adds cloud-specific guidance and controls, and ISO/IEC 27018 adds controls for public cloud providers that process personal information for customers. These can be included in the Statement of Applicability and reviewed during the same certification audit, which keeps the evidence in one place.
Resources
- ISO/IEC 27001:2022 Information security management systems, ISO
- Information security management systems accreditation, Standards Council of Canada
- IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
- IAF CertSearch, International Accreditation Forum
- ISO Online Browsing Platform, ISO
References
- ISO/IEC 27001:2022 Information security management systems, ISO
- IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
- ISO/IEC 27002:2022 Information security controls, ISO
General information, reviewed 2026-10-11. Not legal advice.