ISO 27001:2022 Annex A Controls: Complete Guide

Every organization experiences information security differently. A software company may worry about insecure code and cloud misconfigurations. A hospital focuses on protecting patient records and ensuring system availability. A manufacturing organization prioritizes operational technology, supplier security, and business continuity. Although each organization faces different risks, they can all achieve ISO/IEC 27001 certification.
How is that possible? The answer lies in ISO 27001:2022 Annex A Controls. Unlike many security frameworks that prescribe a fixed set of safeguards, ISO 27001:2022 Annex A follows a risk-based approach. It provides a structured catalogue of security controls that organizations select based on their unique business objectives, information assets, legal obligations, and risk landscape. This flexibility allows every organization to build an Information Security Management System (ISMS) that reflects its own operating environment rather than following a one-size-fits-all security model.
For organizations across India, where rapid digital transformation, cloud adoption, and evolving cyber threats are reshaping business operations, understanding how Annex A works is essential. Selecting the right controls not only strengthens information security but also demonstrates that risks are being managed in a structured and measurable way.
In this article, we'll explain ISO 27001:2022 Annex A Controls, explore the four categories of controls introduced in the 2022 revision, and discuss how organizations can select, justify, and maintain controls as part of an effective ISO/IEC 27001-certified ISMS.
What Is ISO 27001:2022 Annex A Controls?
ISO 27001:2022 Annex A is a reference catalogue of ISO 27001 security controls used during the risk treatment process. Rather than requiring every organization to implement the same controls, it provides a structured set of security measures that organizations select based on their specific risks and business needs.
The controls are based on ISO/IEC 27002:2022, which provides implementation guidance. While ISO/IEC 27001 defines the certification requirements, Annex A helps organizations choose appropriate controls to address identified risks.
The 2022 revision reorganized the framework from 114 controls across 14 domains to 93 controls grouped into four categories, making it easier to navigate while aligning with modern cybersecurity challenges. During certification audits, auditors evaluate whether the selected controls, and any exclusions, are appropriately justified through the organization's risk assessment and Statement of Applicability (SoA), rather than expecting all 93 controls to be implemented.
Why Annex A Controls Matter?
The primary objective of ISO 27001 Annex A controls is to reduce information security risks while protecting the confidentiality, integrity, and availability of information.
Without structured security controls, organizations may struggle to manage cyber threats, human error, supplier risks, or operational disruptions. Annex A provides a consistent framework that enables organizations to establish governance, strengthen operational resilience, and protect critical business information.
For organizations operating in India, this has become increasingly important as businesses expand their digital services, adopt cloud technologies, and process larger volumes of sensitive customer and business data. A risk-based approach to security not only improves resilience but also strengthens customer confidence and supports compliance with contractual and regulatory obligations.
Instead of viewing Annex A as a compliance checklist, organizations should see it as a practical framework for managing information security risks in a structured and measurable way.
Achieve ISO/IEC 27001 Certification with INTERCERT and demonstrate a robust Information Security Management System that builds customer confidence and business resilience.
Understanding the Four Categories of ISO 27001:2022 Annex A Controls
One of the most noticeable changes in ISO 27001:2022 Annex A is the reorganization of all controls into four categories. This simplified structure makes it easier for organizations to understand how different controls contribute to the overall effectiveness of the ISMS.
Organizational Controls (37 Controls)
Organizational controls establish the governance foundation of an ISMS by defining how information security is managed, monitored, and integrated into business operations. The ISO 27001 Annex A controls list includes areas such as information security policies, roles and responsibilities, asset management, supplier relationships, threat intelligence, and cloud service governance. These controls promote accountability and ensure security becomes part of everyday business processes. During audits, assessors typically review governance documents, risk assessments, management review records, and supplier management processes to verify these controls are effectively implemented.
People Controls (8 Controls)
People controls focus on reducing human-related risks by addressing background verification, security awareness, training, remote working, disciplinary processes, and reporting security events. As hybrid work continues to grow across India, these controls help ensure employees understand their information security responsibilities. Auditors commonly evaluate training records, onboarding processes, awareness programs, and employee interviews to confirm that security responsibilities are well understood across the organization.
Physical Controls (14 Controls)
Physical controls protect facilities, equipment, and information assets from unauthorized access, theft, damage, and environmental threats. ISO 27001:2022 controls in this category include secure areas, physical entry controls, equipment protection, secure disposal, and clear desk practices. Auditors generally verify these controls through site inspections, access records, visitor logs, equipment inventories, and observations to ensure physical safeguards are operating effectively.
Technological Controls (34 Controls)
Technological controls are the largest category within ISO 27001:2022 Annex A Controls, covering areas such as access management, encryption, backups, logging, vulnerability management, malware protection, secure coding, network security, data masking, and data leakage prevention. While these controls play a critical role in protecting information systems, their effectiveness depends on strong governance and well-defined processes. During certification audits, assessors review technical configurations, system logs, monitoring records, backup evidence, and vulnerability management activities to confirm that the selected controls are consistently operating as intended.
The 11 New Controls Introduced in ISO/IEC 27001:2022
One of the most significant updates to ISO 27001:2022 Annex A was the introduction of 11 new controls that address modern information security challenges. As organizations increasingly adopt cloud services, remote work, digital platforms, and advanced technologies, the updated controls reflect the changing cybersecurity landscape.
The new controls include:
- Threat intelligence
- Information security for cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
These additions strengthen the overall ISO 27001 security controls by addressing risks that have become more prominent since the previous version of the standard. For example, cloud security governance recognizes the widespread use of cloud platforms, while secure coding and configuration management address vulnerabilities introduced during software development and system deployment.
Controls Removed, Merged, and Updated
The transition from 114 controls to 93 controls often creates the impression that organizations have fewer security responsibilities under ISO/IEC 27001:2022. In reality, many controls were consolidated, reworded, or reorganized to improve usability and eliminate overlapping requirements.
Several controls with similar objectives were merged into broader controls, making the framework easier to understand without reducing its effectiveness. At the same time, the language of many controls was updated to better reflect modern technologies, cloud environments, and current cybersecurity practices.
Organizations migrating from the 2013 version should therefore focus on understanding how existing controls map to the updated structure rather than assuming that previously implemented controls are no longer required.
How Organizations Select Applicable Annex A Controls?
ISO 27001 Annex A implementation follows a risk-based approach rather than a predefined checklist. Organizations should select controls based on their unique information security risks, business objectives, and operating environment.
A typical process includes:
- Conduct an information security risk assessment to identify potential threats and vulnerabilities.
- Evaluate the identified risks based on their likelihood and business impact.
- Determine appropriate risk treatment options for addressing each identified risk.
- Select applicable Annex A controls that effectively mitigate those risks.
- Document the selected and excluded controls in the Statement of Applicability (SoA), along with the justification for each decision.
- Integrate, monitor, and review the controls regularly to ensure they remain effective as risks and business requirements evolve.
For example, a cloud software provider may prioritize controls related to secure coding, cloud security, and configuration management, while a manufacturing organization may focus more on physical security, supplier management, and operational resilience. This flexibility enables organizations across India to tailor their ISMS to their specific risk profile.
From an auditor's perspective, the Statement of Applicability (SoA) is one of the most important documents reviewed during certification. Auditors verify that the selected controls are supported by the organization's risk assessment and that any excluded controls have been appropriately justified.
What Auditors Look for During Annex A Assessments?
A common misconception is that certification auditors verify whether all 93 Annex A controls have been implemented. In reality, audits focus on whether the selected controls are appropriate, effective, and supported by objective evidence.
Auditors typically evaluate:
Control selection – Whether the selected controls are appropriate for the organization's identified risks.
Implementation effectiveness – Whether the controls are operating as intended in day-to-day activities.
Supporting evidence – Policies, procedures, risk assessments, technical configurations, system logs, monitoring records, and management review outputs.
Personnel awareness – Interviews with relevant employees to confirm they understand and follow established security processes.
Continual review – Whether controls are regularly monitored, evaluated, and updated to address evolving risks.
Common Mistakes Organizations Make
Many organizations encounter avoidable challenges when managing ISO 27001 Annex A requirements. Some of the most common include:
Treating Annex A as a Checklist
Implementing controls simply because they appear in Annex A can lead to unnecessary complexity. Every control should be selected based on the organization's risk assessment.
Integrating Every Control
Although organizations are free to implement additional controls, applying all 93 controls without considering applicability may consume unnecessary resources while providing limited value.
Weak Risk Justification
Selecting or excluding controls without clear risk-based reasoning often results in audit findings and inconsistencies within the ISMS.
An Outdated Statement of Applicability
The Statement of Applicability should evolve as business operations, technologies, and risks change. An outdated SoA may no longer reflect the organization's current security posture.
Controls Existing Only on Paper
Well-written documentation alone does not demonstrate compliance. Organizations should be able to show objective evidence that controls are consistently operating in practice.
Take the next step toward ISO/IEC 27001 Certification with INTERCERT and showcase your organization's commitment to effective information security management and continual improvement.
Best Practices for Managing Annex A Controls
Organizations can strengthen their ISO 27001 Annex A implementation by adopting several practical best practices.
Build Controls Around Business Risks
Begin with the organization's risk assessment and select controls that directly address identified information security risks rather than attempting to implement controls indiscriminately.
Keep the Statement of Applicability Updated
Review the SoA regularly to ensure it reflects current technologies, business processes, legal requirements, and risk treatment decisions.
Integrate Controls into Daily Operations
Security controls are most effective when they become part of routine business processes, including procurement, software development, supplier management, and change management.
Monitor Control Effectiveness
Regular monitoring, management reviews, incident analysis, and performance measurement enable organizations to evaluate whether controls continue to operate effectively.
Train Process Owners
Employees responsible for implementing and maintaining controls should understand both the purpose of the controls and their individual responsibilities within the ISMS.
Review Controls as Risks Evolve
Information security risks continue to change. Organizations should periodically reassess risks and adjust selected controls to maintain an effective security posture.
Annex A Controls vs. ISO/IEC 27002
Many organizations confuse ISO 27001:2022 Annex A with ISO/IEC 27002 because both address information security controls. The difference lies in their purpose.
Annex A provides the official ISO 27001 Annex A controls list that organizations use as part of the certification process. It identifies the controls that may be selected during risk treatment but does not explain how each control should be implemented.
ISO/IEC 27002, on the other hand, serves as a guidance document. It provides detailed recommendations, implementation guidance, and practical examples for applying each Annex A control effectively.
In simple terms, Annex A identifies what controls should be considered, while ISO/IEC 27002 explains how those controls can be implemented.
Achieving Effective Information Security with ISO 27001 Annex A
Understanding ISO 27001:2022 Annex A Controls is essential for building an effective Information Security Management System. Rather than serving as a mandatory checklist, Annex A provides a structured catalogue of controls that organizations select based on their unique information security risks, business objectives, and regulatory obligations.
A successful ISO 27001 Annex A implementation begins with a thorough risk assessment, followed by the careful selection of applicable controls and ongoing monitoring of their effectiveness. Maintaining a well-supported Statement of Applicability and demonstrating that controls are operating as intended are equally important during certification.
For organizations across India, where digital transformation continues to reshape business operations, adopting a risk-based approach to ISO 27001 Annex A requirements enables stronger governance, improved resilience, and greater confidence among customers, regulators, and business partners.
As an independent certification body, INTERCERT assesses organizations against the requirements of ISO/IEC 27001. A well-designed ISMS, supported by appropriately selected Annex A controls and objective evidence of their effectiveness, enables organizations to demonstrate conformity with internationally recognized information security management requirements.
