ISO 27001:2022
ISO 27001 Annex A Controls - All 93 Explained
Every Annex A control from the 2022 revision, with what the control requires, what good looks like in practice, the evidence an auditor will ask for, and the template that fulfils it.
Organizational controls
37 controls covering governance, risk, suppliers, incident management and compliance.
Annex A 5.1
Policies for information securityTemplate
Annex A 5.2
Information security roles and responsibilitiesAnnex A 5.3
Segregation of dutiesAnnex A 5.4
Management responsibilitiesAnnex A 5.5
Contact with authoritiesAnnex A 5.6
Contact with special interest groupsAnnex A 5.7
Threat intelligenceAnnex A 5.8
Information security in project managementAnnex A 5.9
Inventory of information and other associated assetsTemplate
Annex A 5.10
Acceptable use of information and other associated assetsTemplate
Annex A 5.11
Return of assetsAnnex A 5.12
Classification of informationTemplate
Annex A 5.13
Labelling of informationTemplate
Annex A 5.14
Information transferAnnex A 5.15
Access controlTemplate
Annex A 5.16
Identity managementTemplate
Annex A 5.17
Authentication informationTemplate
Annex A 5.18
Access rightsTemplate
Annex A 5.19
Information security in supplier relationshipsTemplate
Annex A 5.20
Addressing information security within supplier agreementsTemplate
Annex A 5.21
Managing information security in the ICT supply chainTemplate
Annex A 5.22
Monitoring, review and change management of supplier servicesTemplate
Annex A 5.23
Information security for use of cloud servicesTemplate
Annex A 5.24
Information security incident management planning and preparationTemplate
Annex A 5.25
Assessment and decision on information security eventsTemplate
Annex A 5.26
Response to information security incidentsTemplate
Annex A 5.27
Learning from information security incidentsTemplate
Annex A 5.28
Collection of evidenceAnnex A 5.29
Information security during disruptionTemplate
Annex A 5.30
ICT readiness for business continuityTemplate
Annex A 5.31
Legal, statutory, regulatory and contractual requirementsTemplate
Annex A 5.32
Intellectual property rightsAnnex A 5.33
Protection of recordsAnnex A 5.34
Privacy and protection of PIITemplate
Annex A 5.35
Independent review of information securityTemplate
Annex A 5.36
Compliance with policies, rules and standards for information securityTemplate
Annex A 5.37
Documented operating proceduresTemplate
People controls
8 controls covering screening, employment terms, training, discipline and remote working.
Annex A 6.1
ScreeningTemplate
Annex A 6.2
Terms and conditions of employmentTemplate
Annex A 6.3
Information security awareness, education and trainingTemplate
Annex A 6.4
Disciplinary processTemplate
Annex A 6.5
Responsibilities after termination or change of employmentTemplate
Annex A 6.6
Confidentiality or non-disclosure agreementsTemplate
Annex A 6.7
Remote workingTemplate
Annex A 6.8
Information security event reportingPhysical controls
14 controls covering perimeters, entry, equipment siting and environmental threats.
Annex A 7.1
Physical security perimetersTemplate
Annex A 7.2
Physical entryTemplate
Annex A 7.3
Securing offices, rooms and facilitiesTemplate
Annex A 7.4
Physical security monitoringTemplate
Annex A 7.5
Protecting against physical and environmental threatsTemplate
Annex A 7.6
Working in secure areasAnnex A 7.7
Clear desk and clear screenTemplate
Annex A 7.8
Equipment siting and protectionAnnex A 7.9
Security of assets off-premisesAnnex A 7.10
Storage mediaAnnex A 7.11
Supporting utilitiesAnnex A 7.12
Cabling securityAnnex A 7.13
Equipment maintenanceAnnex A 7.14
Secure disposal or re-use of equipmentTechnological controls
34 controls covering access control, logging, networks, cryptography and secure development.
Annex A 8.1
User endpoint devicesTemplate
Annex A 8.2
Privileged access rightsAnnex A 8.3
Information access restrictionAnnex A 8.4
Access to source codeAnnex A 8.5
Secure authenticationAnnex A 8.6
Capacity managementAnnex A 8.7
Protection against malwareAnnex A 8.8
Management of technical vulnerabilitiesTemplate
Annex A 8.9
Configuration managementAnnex A 8.10
Information deletionAnnex A 8.11
Data maskingAnnex A 8.12
Data leakage preventionAnnex A 8.13
Information backupTemplate
Annex A 8.14
Redundancy of information processing facilitiesAnnex A 8.15
LoggingTemplate
Annex A 8.16
Monitoring activitiesTemplate
Annex A 8.17
Clock synchronizationAnnex A 8.18
Use of privileged utility programsAnnex A 8.19
Installation of software on operational systemsAnnex A 8.20
Networks securityTemplate
Annex A 8.21
Security of network servicesTemplate
Annex A 8.22
Segregation of networksTemplate
Annex A 8.23
Web filteringAnnex A 8.24
Use of cryptographyTemplate
Annex A 8.25
Secure development life cycleTemplate
Annex A 8.26
Application security requirementsTemplate
Annex A 8.27
Secure system architecture and engineering principlesTemplate
Annex A 8.28
Secure codingTemplate
Annex A 8.29
Security testing in development and acceptanceTemplate
Annex A 8.30
Outsourced developmentTemplate
Annex A 8.31
Separation of development, test and production environmentsAnnex A 8.32
Change managementTemplate
Annex A 8.33
Test informationAnnex A 8.34
Protection of information systems during audit testingImplement all 93 controls
Assess your organisation against every Annex A control with the free Gap Analysis tool, or get auditor-ready templates for the controls that need documented policies with the Document Pack.
