ISO 27001 Annex A Controls - All 93 Explained
Every Annex A control from the 2022 revision, with what the control requires, what good looks like in practice, the evidence an auditor will ask for, and the template that fulfils it.
Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer
Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.
Organizational controls
37 controls covering governance, risk, suppliers, incident management and compliance.
People controls
8 controls covering screening, employment terms, training, discipline and remote working.
Physical controls
14 controls covering perimeters, entry, equipment siting and environmental threats.
Technological controls
34 controls covering access control, logging, networks, cryptography and secure development.
Implement all 93 controls
Assess your organisation against every Annex A control with the free Gap Analysis tool, or get auditor-ready templates for the controls that need documented policies with the Document Pack.
