Skip to main content

ISO 27001 Annex A controls (2022): all 93 controls explained

Written, published and substantively reviewed by Harry Sidhu, Director and Principal Consultant, Aegentra. Reviewed .

Every ISO 27001 control in plain English — the 93 controls across four themes in the 2022 revision, which eleven are new, how the Statement of Applicability decides what you actually implement, and where Annex A overlaps the Essential Eight and APRA CPS 234.

What is Annex A?

Direct definition: Annex A is the reference set of 93 information security controls in ISO/IEC 27001:2022. Organisations compare the controls they determine are necessary with this reference set so they do not overlook a needed control. Annex A is not a requirement to implement all 93 controls.

Purpose of this resource: provide a plain-English study view of the four themes, control titles and relationships so learners can understand the catalogue before working with an authorised copy of the standard. It is a study aid, not the standard or organisation-specific implementation advice.

Clause 6.1.3 is the clause that matters: it requires you to determine the controls necessary to treat your risks, then compare those against Annex A to verify no necessary control has been overlooked. The direction is important. Risks come first; Annex A is the cross-check, not the starting point. Teams who work the other way round end up with 93 half-implemented controls and no defensible rationale for any of them.

Annex A gives you the control title and a one-line statement. The implementation guidance lives in ISO 27002:2022, a separate document that expands each control into purpose, guidance and other information. You certify against 27001; you build against 27002. For costs, timelines and the certification process end to end, see the ISO 27001 certification guide for Australia.

Learning the standard rather than selecting controls for an organisation? Pair this reference with the ISO 27001 Foundation course, the free Clauses 4–10 study map and the terminology glossary.

The four themes and 93 controls

The 2013 edition had 114 controls across 14 domains. The 2022 revision reorganised them into four themes and consolidated overlapping controls, landing at 93. Nothing meaningful was dropped — 24 controls were merged, one was split, and 11 new ones were added.

ThemeClauseControlsOwned by
OrganizationalA.537Security lead, legal, procurement
PeopleA.68HR
PhysicalA.714Facilities, office manager
TechnologicalA.834IT, engineering
Total93

The split matters for planning. Only 34 of 93 controls are technical — roughly a third. The majority are governance, people and process, which is why an ISO 27001 programme run purely out of the IT team stalls at the Stage 1 audit.

The 11 new controls in ISO 27001:2022

These are the controls that did not exist in 2013. If you certified under the old edition and transitioned, these are where your gap analysis found work — and where surveillance audits now concentrate.

  • A.5.7 Threat intelligence — collect and analyse information about threats relevant to you, and act on it.
  • A.5.23 Information security for use of cloud services — acquisition, use, management and exit of cloud services.
  • A.5.30 ICT readiness for business continuity — ICT continuity planned against defined recovery objectives.
  • A.7.4 Physical security monitoring — premises continuously monitored for unauthorised physical access.
  • A.8.9 Configuration management — hardened, documented baselines, and detection of drift from them.
  • A.8.10 Information deletion — data deleted when no longer required; ties to Australian Privacy Principle 11.2.
  • A.8.11 Data masking — masking, pseudonymisation or anonymisation where full data is not required.
  • A.8.12 Data leakage prevention — detect and prevent unauthorised extraction of sensitive information.
  • A.8.16 Monitoring activities — networks and systems monitored for anomalous behaviour. Logging without monitoring no longer passes.
  • A.8.23 Web filtering — restrict access to malicious or inappropriate external websites.
  • A.8.28 Secure coding — secure coding principles applied to in-house and outsourced development.

The five control attributes

ISO 27002:2022 tags every control with five attributes so the same 93 controls can be sorted five different ways: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover — the NIST CSF functions), operational capabilities (governance, asset management and 13 more), and security domains (governance and ecosystem, protection, defence, resilience). They are an aid to planning and reporting, not a certification requirement — no auditor will ask to see them.

The Statement of Applicability

The Statement of Applicability (SoA) is the document that turns Annex A from a catalogue into your control set. It is mandatory under clause 6.1.3(d), and it is the first artefact most auditors ask for. For each of the 93 controls it records whether the control is applicable, the justification for including it (normally the risk it treats), the justification for excluding it if excluded, whether it is currently implemented, and how it is implemented.

Exclusions are legitimate, but they must follow from scope and risk. A business with no software development can exclude secure coding (A.8.28). A fully remote business with no office still cannot exclude the whole physical theme, because staff laptops and home working remain in scope. “Not applicable” with no reasoning is the single most common Stage 1 finding.

Annex A vs the Essential Eight

Australian teams routinely hold both, and they answer different questions. The Essential Eight is eight technical mitigations with maturity levels 0 to 3, published by the ACSC. Annex A is 93 controls spanning governance, people, physical and technology.

The Essential Eight maps into roughly a dozen Annex A technological controls — application control and patching land on A.8.8, A.8.19 and A.8.9; multi-factor authentication on A.8.5; restricting administrative privileges on A.8.2; backups on A.8.13. Everything else in Annex A has no Essential Eight equivalent at all: supplier management, incident response, classification, screening, and the entire management system. If you already run Essential Eight Maturity Level 2, you have a genuine head start on the technological theme and almost nothing on the other three. Our Microsoft 365 hardening service covers the technical overlap directly.

How many controls will you actually apply?

Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.

If you want the whole thing implemented rather than studied, our ISO 27001 consulting and implementation service takes an Australian SMB from gap analysis to audit-ready. For a separately scoped audit, review the independent ISO 27001 internal-audit service. If you want to run it yourself, the PECB ISO 27001 Lead Implementer course teaches the methodology behind every control decision above, and the Lead Auditor course teaches how those decisions get tested.

Worked example and adaptation steps

Preview — fictional SaaS provider: a 100-person Australian B2B SaaS provider uses Microsoft 365 and Azure. Its scope and cloud-service risks make A.5.23 applicable; possible evidence includes a cloud-service register, assigned owners, supplier security requirements, shared-responsibility records, configuration reviews and an exit plan. This is not a universal rationale or completed treatment record.

Adaptation steps: confirm scope and applicable requirements; assess risks; determine necessary controls, including custom controls; compare that set with all 93 Annex A reference controls; record decisions and justifications in the Statement of Applicability; then assign owners, evidence and review triggers.

Common mistakes

  • Starting with a 93-box checklist instead of scope and risk.
  • Assuming every Annex A control is mandatory.
  • Excluding whole themes because the organisation is cloud-only.
  • Treating a purchased tool as proof that a control operates effectively.
  • Copying a worked example instead of recording organisation-specific decisions.

Print or save this study guide

Aegentra does not provide a downloadable copy of Annex A or reproduce the licensed ISO control statements. Use the browser print command to print this Aegentra-authored plain-English page or save it as a PDF, and obtain the official text from an authorised standards source.

Version, author and review status

Resource version
1.0
First published
27 July 2026
Last updated
2 September 2026
Author and publication owner
Harry Sidhu · Director and Principal Consultant, Aegentra
Standards basis
ISO/IEC 27001:2022 incorporating Amendment 1:2024; ISO/IEC 27002:2022
Substantive reviewer
Harry Sidhu · Director and Principal Consultant, Aegentra
Substantive review date
2 September 2026

Substantively reviewed for source accuracy, control mapping, limitations and learner-facing presentation. Source links were checked when this version was prepared; standards status and source availability can change.

Limitations and use boundary

This is an Aegentra-authored study aid, not the ISO standard, official PECB course material, legal advice, implementation advice or a certification opinion. The example is fictional. All requirements in Clauses 4–10 apply; Annex A is a reference control set, and an organisation may need controls from other sources. Use authorised standards and competent organisation-specific judgement for consequential decisions.

Sources and further study

Study ISO 27001 Foundation · Explore ISO 27001 Lead Implementer · Practise Foundation in Aegentra Labs

Frequently asked questions

How many controls are in ISO 27001:2022 Annex A?

There are 93 controls, grouped into four themes: Organizational (37 controls, A.5.1–A.5.37), People (8 controls, A.6.1–A.6.8), Physical (14 controls, A.7.1–A.7.14), and Technological (34 controls, A.8.1–A.8.34). The 2013 version had 114 controls across 14 domains — the 2022 revision consolidated overlapping controls and added 11 genuinely new ones, so the drop from 114 to 93 is mostly merging, not removal.

Do I have to implement all 93 Annex A controls?

No. Annex A is a reference set, not a universal implementation checklist. The risk assessment determines necessary controls, and the Statement of Applicability records whether each Annex A control is applicable, the rationale and implementation status. Risks come first; Annex A is the cross-check, not the starting point.

What is the difference between Annex A and the main clauses?

Clauses 4 to 10 are the mandatory management-system requirements — context, leadership, planning, support, operation, performance evaluation and improvement. Annex A is the reference set of security controls used to cross-check the controls necessary to treat risk. The clauses establish how the management system operates; the Statement of Applicability records the organisation’s position on each Annex A control.

Which controls were added in ISO 27001:2022?

Eleven: threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28). They reflect changes in practice between 2013 and 2022, including cloud, remote work and detection-led security.

What are the Annex A control attributes?

ISO 27002:2022 tags every control with five attributes so the catalogue can be viewed in different ways: control type; information-security properties; cybersecurity concepts; operational capabilities; and security domains. The attributes are an organising aid and are not themselves a mandatory ISO 27001 certification deliverable unless the organisation makes them part of its own process.

Is Annex A the same as ISO 27002?

They are two views of the same 93 controls. Annex A in ISO 27001 gives the control titles and one-line statements. ISO 27002:2022 is the separate implementation guidance document that expands each of those into purpose, guidance and other information. You certify against ISO 27001; ISO 27002 provides implementation guidance for the controls.

When did the 2013 controls stop being accepted?

The transition window for ISO 27001:2013 certificates closed on 31 October 2025. New certification and surveillance activity now use the 2022 control set. A 114-control checklist or 14-domain structure refers to the superseded edition.

How does Annex A relate to APRA CPS 234 and the Essential Eight?

They overlap but serve different purposes. The Essential Eight is a focused set of technical mitigations with maturity levels; APRA CPS 234 is a prudential standard for regulated entities; and Annex A is a broader reference set spanning organisational, people, physical and technological controls. Mapping must be assessed against the organisation’s actual scope, obligations and implementation evidence. ISO 27001 certification does not by itself prove compliance with either framework.