ISO 27001:2022

    ISO 27001 Annex A Controls - All 93 Explained

    Every Annex A control from the 2022 revision, with what the control requires, what good looks like in practice, the evidence an auditor will ask for, and the template that fulfils it.

    Organizational controls

    37 controls covering governance, risk, suppliers, incident management and compliance.

    Annex A 5.1
    Template
    Policies for information security
    Annex A 5.2
    Information security roles and responsibilities
    Annex A 5.3
    Segregation of duties
    Annex A 5.4
    Management responsibilities
    Annex A 5.5
    Contact with authorities
    Annex A 5.6
    Contact with special interest groups
    Annex A 5.7
    Threat intelligence
    Annex A 5.8
    Information security in project management
    Annex A 5.9
    Template
    Inventory of information and other associated assets
    Annex A 5.10
    Template
    Acceptable use of information and other associated assets
    Annex A 5.11
    Return of assets
    Annex A 5.12
    Template
    Classification of information
    Annex A 5.13
    Template
    Labelling of information
    Annex A 5.14
    Information transfer
    Annex A 5.15
    Template
    Access control
    Annex A 5.16
    Template
    Identity management
    Annex A 5.17
    Template
    Authentication information
    Annex A 5.18
    Template
    Access rights
    Annex A 5.19
    Template
    Information security in supplier relationships
    Annex A 5.20
    Template
    Addressing information security within supplier agreements
    Annex A 5.21
    Template
    Managing information security in the ICT supply chain
    Annex A 5.22
    Template
    Monitoring, review and change management of supplier services
    Annex A 5.23
    Template
    Information security for use of cloud services
    Annex A 5.24
    Template
    Information security incident management planning and preparation
    Annex A 5.25
    Template
    Assessment and decision on information security events
    Annex A 5.26
    Template
    Response to information security incidents
    Annex A 5.27
    Template
    Learning from information security incidents
    Annex A 5.28
    Collection of evidence
    Annex A 5.29
    Template
    Information security during disruption
    Annex A 5.30
    Template
    ICT readiness for business continuity
    Annex A 5.31
    Template
    Legal, statutory, regulatory and contractual requirements
    Annex A 5.32
    Intellectual property rights
    Annex A 5.33
    Protection of records
    Annex A 5.34
    Template
    Privacy and protection of PII
    Annex A 5.35
    Template
    Independent review of information security
    Annex A 5.36
    Template
    Compliance with policies, rules and standards for information security
    Annex A 5.37
    Template
    Documented operating procedures

    People controls

    8 controls covering screening, employment terms, training, discipline and remote working.

    Physical controls

    14 controls covering perimeters, entry, equipment siting and environmental threats.

    Technological controls

    34 controls covering access control, logging, networks, cryptography and secure development.

    Implement all 93 controls

    Assess your organisation against every Annex A control with the free Gap Analysis tool, or get auditor-ready templates for the controls that need documented policies with the Document Pack.