Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026
Every ISO 27001 control in plain English — the 93 controls across four themes in the 2022 revision, which eleven are new, how the Statement of Applicability decides what you actually implement, and where Annex A overlaps the Essential Eight and APRA CPS 234.
Annex A is the control catalogue attached to ISO/IEC 27001:2022 — 93 controls you draw on to treat the risks your risk assessment identifies. It is normative, meaning you must compare your control set against it, but it is not a checklist you implement top to bottom.
Clause 6.1.3 is the clause that matters: it requires you to determine the controls necessary to treat your risks, then compare those against Annex A to verify no necessary control has been overlooked. The direction is important. Risks come first; Annex A is the cross-check, not the starting point. Teams who work the other way round end up with 93 half-implemented controls and no defensible rationale for any of them.
Annex A gives you the control title and a one-line statement. The implementation guidance lives in ISO 27002:2022, a separate document that expands each control into purpose, guidance and other information. You certify against 27001; you build against 27002. For costs, timelines and the certification process end to end, see the ISO 27001 certification guide for Australia.
The 2013 edition had 114 controls across 14 domains. The 2022 revision reorganised them into four themes and consolidated overlapping controls, landing at 93. Nothing meaningful was dropped — 24 controls were merged, one was split, and 11 new ones were added.
| Theme | Clause | Controls | Owned by |
|---|---|---|---|
| Organizational | A.5 | 37 | Security lead, legal, procurement |
| People | A.6 | 8 | HR |
| Physical | A.7 | 14 | Facilities, office manager |
| Technological | A.8 | 34 | IT, engineering |
| Total | 93 |
The split matters for planning. Only 34 of 93 controls are technical — roughly a third. The majority are governance, people and process, which is why an ISO 27001 programme run purely out of the IT team stalls at the Stage 1 audit.
These are the controls that did not exist in 2013. If you certified under the old edition and transitioned, these are where your gap analysis found work — and where surveillance audits now concentrate.
ISO 27002:2022 tags every control with five attributes so the same 93 controls can be sorted five different ways: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover — the NIST CSF functions), operational capabilities (governance, asset management and 13 more), and security domains (governance and ecosystem, protection, defence, resilience). They are an aid to planning and reporting, not a certification requirement — no auditor will ask to see them.
The Statement of Applicability (SoA) is the document that turns Annex A from a catalogue into your control set. It is mandatory under clause 6.1.3(d), and it is the first artefact most auditors ask for. For each of the 93 controls it records whether the control is applicable, the justification for including it (normally the risk it treats), the justification for excluding it if excluded, whether it is currently implemented, and how it is implemented.
Exclusions are legitimate, but they must follow from scope and risk. A business with no software development can exclude secure coding (A.8.28). A fully remote business with no office still cannot exclude the whole physical theme, because staff laptops and home working remain in scope. “Not applicable” with no reasoning is the single most common Stage 1 finding.
Australian teams routinely hold both, and they answer different questions. The Essential Eight is eight technical mitigations with maturity levels 0 to 3, published by the ACSC. Annex A is 93 controls spanning governance, people, physical and technology.
The Essential Eight maps into roughly a dozen Annex A technological controls — application control and patching land on A.8.8, A.8.19 and A.8.9; multi-factor authentication on A.8.5; restricting administrative privileges on A.8.2; backups on A.8.13. Everything else in Annex A has no Essential Eight equivalent at all: supplier management, incident response, classification, screening, and the entire management system. If you already run Essential Eight Maturity Level 2, you have a genuine head start on the technological theme and almost nothing on the other three. Our Microsoft 365 hardening service covers the technical overlap directly.
For a typical Australian SMB of 10 to 50 staff, expect 70 to 90 of the 93 to be applicable. Cloud-native businesses exclude a handful of physical and cabling controls; organisations with no in-house development exclude the secure development cluster in A.8.25 to A.8.31. Very few legitimately exclude more than 20.
Applicable is not the same as expensive. A large share of Annex A is documentation and process you can write once — acceptable use, classification, supplier clauses, incident procedure. The controls that consume real budget are logging and monitoring (A.8.15, A.8.16), vulnerability management (A.8.8), and data leakage prevention (A.8.12).
If you want the whole thing implemented rather than studied, our ISO 27001 consulting and implementation service takes an Australian SMB from gap analysis to audit-ready. If you want to run it yourself, the PECB ISO 27001 Lead Implementer course teaches the methodology behind every control decision above, and the Lead Auditor course teaches how those decisions get tested.