Guide

ISO 27001 Annex A Controls, Explained (93 Controls, Four Themes)

What Annex A is, how the 2022 revision reorganized the controls into four themes, and how to approach them without treating the list as a checklist.

8 min read

Annex A is the catalogue of security controls that comes with ISO 27001. It is where most people first feel the weight of the standard, because it is a long list. The 2022 revision reorganized it into 93 controls across four themes, and understanding those themes is the fastest way to make the list feel manageable.

What Annex A Is (and Is Not)

Annex A is a reference set of controls you choose from, not a mandatory checklist you must implement in full. Your job is to decide, through your risk assessment, which controls apply to you, then justify your choices in the Statement of Applicability. A control you exclude with a documented reason is a legitimate answer; an unexplained gap is not.

The Four Themes (2022 Revision)

The 2022 revision consolidated the older list of 114 controls into 93, grouped into four themes:

  • Organizational (37 controls): policies, roles, supplier relationships, threat intelligence, and how security is governed.
  • People (8 controls): screening, awareness and training, and the responsibilities of the people who handle information.
  • Physical (14 controls): secure areas, equipment, and the physical protection of information.
  • Technological (34 controls): access control, cryptography, logging, secure development, and the technical measures most engineers think of first.

The regrouping did not change the substance so much as make it easier to navigate, and it added a handful of newer controls, such as threat intelligence and secure coding.

How to Approach Them

Do not start at control number one and work down. Start from your risk assessment: for each risk, choose the Annex A controls that treat it, and record which controls you are applying and why in the Statement of Applicability. That order keeps the list tied to your actual risks instead of turning it into a hundred separate projects.

How Concord Fits

Concord Trust's control library lets you adopt the controls that apply to you, assign owners, and track coverage, so Annex A becomes a set of controls you maintain rather than a document you write once. When you adopt the ISO 27001 framework, your controls map onto its requirements so you can see where you are covered.

Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.