ISO 27001:2022 Annex A contains 93 controls organized into four themes, a significant restructuring from the 2013 version which had 114 controls across 14 domains. These controls represent the reference set of information security measures that organizations select from based on their risk assessment results. Understanding the full landscape of Annex A controls is essential for building a comprehensive Statement of Applicability and implementing an effective Information Security Management System.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
ISO 27001:2022 Annex A contains 93 controls organized into four themes: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). This is a reduction from 114 controls in 14 domains in the 2013 version, achieved through merging and reorganization.
The 2022 version introduces 11 new controls: threat intelligence (A.5.7), information security for cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.22), and secure coding (A.8.28).
No. Organizations implement controls based on their risk assessment results. However, every control must be addressed in the Statement of Applicability with a justified inclusion or exclusion. Exclusions must be based on the risk assessment demonstrating the control is not relevant, not merely on cost or convenience.
The Statement of Applicability (SoA) is a mandatory ISMS document that lists all 93 Annex A controls and states whether each is applicable, the justification for inclusion or exclusion, the implementation status, and references to supporting documentation. It links risk assessment results to control selection.
The 2022 version restructures controls from 14 domains into 4 themes, reduces the count from 114 to 93 through merging, adds 11 new controls addressing modern concerns, and introduces control attributes (threat type, cybersecurity concept, security property, operational capability, security domain) for easier filtering and classification.
Annex A in ISO 27001 lists the controls as concise reference points for the ISMS. ISO 27002 provides detailed implementation guidance for each control, including purpose, guidance, and supplementary information. Organizations use Annex A for compliance scoping and ISO 27002 for implementation details.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for ISO 27001 compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free