4 Categories of ISO 27001:2022 Controls Explained

A strong security program must account for governance, employees, physical environments, technology, suppliers, business processes, and the risks that connect them. That is one reason the 4 category areas of ISO 27001 are important to understand.
The ISO/IEC 27001:2022 framework organizes its Annex A reference controls into four themes: Organizational, People, Physical, and Technological. The 2022 edition contains 93 controls, compared with 114 in the previous edition. The restructuring also introduced 11 new controls and reduced duplication across the control set.
For organizations in the USA preparing for ISO 27001 certification, understanding these categories can make it easier to connect security controls with business risks and determine what evidence an auditor may expect.
But there is an important point to remember: ISO 27001 is not simply a checklist of 93 controls. So, what are the 4 categories of ISO 27001, what does each category cover, and how should organizations use them when developing an Information Security Management System (ISMS)?
The New ISO 27001:2022 Control Categories Explained
Before looking at the individual categories, it helps to understand what changed in the 2022 edition. The previous ISO/IEC 27001:2013 structure contained 114 Annex A controls distributed across 14 domains. In the 2022 revision, the reference control set was reorganized into four broader themes, making up to 93 controls in the 2022 reference set:
- Organizational controls – 37 controls
- People controls – 8 controls
- Physical controls – 14 controls
- Technological controls – 34 controls
The change was not simply a renumbering exercise. ISO/IEC 27002:2022 revised the control set to remove redundancies and address changes in technology and business practices. New controls include areas such as threat intelligence, information security for use of cloud services, and data leakage prevention.
This is particularly relevant for organizations in the USA that operate cloud-based infrastructure, support remote workforces, process sensitive customer information, or rely heavily on third-party service providers.
ISO 27001 vs. ISO 27002: Why the distinction matters?
When discussing ISO 27001 categories and controls, it is important to distinguish between ISO/IEC 27001 and ISO/IEC 27002. ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS. And ISO/IEC 27002 provides guidance on information security controls and their implementation. Annex A of ISO/IEC 27001 provides a reference set of controls. Organizations determine which controls are necessary based on their information security risks and treatment decisions rather than automatically implementing every control. This makes the Statement of Applicability (SoA) an important part of the certification process.
Strengthen your information security framework with ISO/IEC 27001 Certification.Choose INTERCERT for an independent assessment of your ISMS against ISO/IEC 27001 requirements.
Understanding the Four Themes of ISO 27001 Controls
The ISO 27001 four categories can be viewed as four complementary dimensions of information security: Organizational → People → Physical → Technological. Each addresses a different source or aspect of information security risk. Organizational controls establish governance and responsibilities. People controls address workforce-related risks. Physical controls protect facilities and physical assets. Technological controls address security mechanisms implemented through technology.
The categories are therefore not intended to operate as isolated security silos. ISO/IEC 27002's 2022 structure was specifically designed to make it easier to understand how controls relate to different risks, resources, and organizational responsibilities.
Consider privileged access as an example. An organization may need:
- An organizational policy defining access responsibilities
- Personnel processes governing changes in employment
- Physical protection for administrative workstations
- Technical controls for authentication and privileged access
Looking at the ISO 27001 control areas together gives a more realistic picture of how the risk is actually managed.
Annex A Controls Are Grouped Into Four Categories
The four categories provide a structured view of how information security risks are addressed across governance, people, physical environments, and technology.
Organizational Controls (37 controls)
Organizational controls form the governance layer of the ISO 27001 control structure.
They address how an organization establishes security responsibilities, policies, processes, relationships, and governance mechanisms. Examples include controls related to:
- Information security policies
- Information security roles and responsibilities
- Segregation of duties
- Threat intelligence
- Information security in project management
- Asset inventories
- Acceptable use of information and associated assets
- Access control
- Supplier relationships
- Cloud services
- Incident management
- Business continuity
- Legal, statutory, regulatory, and contractual requirements
These controls are particularly relevant to GRC teams because they connect information security with organizational decision-making. For example, deploying a security technology does not establish who is responsible for reviewing it, what risks it addresses, how exceptions are handled, or how its effectiveness is monitored. Organizational controls provide that broader governance structure. For a U.S. organization, this can also mean aligning information security responsibilities with contractual commitments, regulatory obligations, customer requirements, and internal risk management practices.
People Controls (8 controls)
People remain a significant component of information security, even in highly automated environments. The People category addresses security considerations throughout the employee and personnel lifecycle. The controls include areas such as:
- Screening
- Terms and conditions of employment
- Information security awareness, education, and training
- Disciplinary processes
- Responsibilities after termination or change of employment
- Confidentiality or non-disclosure agreements
- Remote working
- Information security event reporting
ISO/IEC JTC 1/SC 27 specifically identifies these controls as mechanisms for addressing risks associated with human behavior and workforce lifecycle events. Consider an employee moving from one department to another. The security risk is not solved simply because the organization has an identity management platform. The organization also needs processes to ensure that: Role changes → Responsibilities change → Access changes → Security requirements are communicated. The same principle applies when someone leaves the organization. This is why the People category should not be reduced to annual security awareness training. It connects security requirements with recruitment, employment, role changes, remote working, confidentiality, and termination.
Physical Controls (14 controls)
Cloud computing has changed where organizations store and process information, but it has not eliminated physical security risks. The Physical category addresses the protection of facilities, equipment, and physical information assets. Examples include controls covering:
- Physical security perimeters
- Physical entry controls
- Securing offices, rooms, and facilities
- Physical security monitoring
- Protection against physical and environmental threats
- Working in secure areas
- Clear desk and clear screen practices
- Equipment protection
- Secure disposal or reuse of equipment
For a U.S. organization operating a hybrid workforce, physical controls may apply to corporate offices, employee workspaces, laptops, networking equipment, storage areas, backup media, and other physical assets. They also become important when organizations depend on third-party facilities such as data centers. The key question is not simply, “Where is our data stored?” It is: What physical risks could affect the confidentiality, integrity, or availability of information within our ISMS scope? That distinction becomes increasingly important as organizations rely on cloud and outsourced infrastructure.
Technological Controls (34 controls)
Technological controls represent the technical security mechanisms used to protect information and technology resources. They cover a wide range of areas, including:
- Endpoint security
- Privileged access rights
- Authentication
- Capacity management
- Malware protection
- Vulnerability management
- Configuration management
- Data deletion
- Data masking
- Data leakage prevention
- Backup
- Logging
- Monitoring
- Network security
- Cryptography
- Secure development
- Application security
- Change management
This category contains the second-largest number of controls, but organizations should avoid making the mistake of treating technological controls as the entire ISO 27001 program. For example, an organization may deploy multi-factor authentication across critical systems. That is an important technical safeguard. But effective information security management also requires appropriate governance around access, defined responsibilities, personnel processes, monitoring, and evidence that the control continues to operate effectively..png)
How the Four ISO 27001 Control Areas Work Together?
Imagine a U.S. software company protecting sensitive customer information. Its information security risks could require controls across all four categories.
Organizational - The company establishes information security policies, assigns responsibilities, evaluates suppliers, manages incidents, and defines requirements for handling sensitive information.
People - Employees receive appropriate security training, confidentiality obligations are established, and access responsibilities are addressed when personnel join, change roles, or leave.
Physical - Corporate facilities, employee devices, physical documents, and relevant equipment are protected against unauthorized access, damage, or loss.
Technological - Authentication, access controls, encryption, logging, monitoring, vulnerability management, backup, and other technical safeguards are implemented.
This illustrates why understanding ISO 27001 categories and controls is more useful than simply memorizing control numbers.
Step-by-Step: How to Apply the ISO 27001 Control Categories
Organizations preparing for certification shouldn’t begin by asking how they can implement all 93 controls. Instead, they should first identify and understand their organizational risks, then determine which controls are necessary to address them.
Step 1: Define the ISMS Scope
Start by clearly defining what the Information Security Management System (ISMS) covers. Establish the relevant business units, locations, processes, systems, information assets, technologies, and third-party relationships that fall within the scope. A well-defined scope provides the foundation for the risk assessment and ensures that the organization understands exactly which information, activities, and environments are subject to the ISMS.
Step 2: Identify and Assess Information Security Risks
Once the scope is established, identify the information security risks that could affect the organization. Assess how threats and vulnerabilities could impact the confidentiality, integrity, and availability of information. The assessment should also consider business impact, regulatory and contractual requirements, customer expectations, third-party dependencies, and the organization's overall risk appetite.
Step 3: Determine Risk Treatment
After assessing the risks, determine how each significant risk should be addressed. Organizations may choose to reduce, avoid, transfer, or accept a risk based on its likelihood, impact, and business context. This step establishes which security measures are necessary and creates a clear connection between identified risks and the controls selected to address them.
Step 4: Evaluate the Annex A Controls
With risk treatment decisions established, evaluate the Annex A controls to determine which ones are relevant to the organization's identified risks. Annex A should be used as a reference set rather than treated as a mandatory checklist. The objective is to determine whether the necessary controls have been identified and whether additional controls from other sources are required to effectively manage the organization's risks.
Step 5: Develop the Statement of Applicability
Document the results in the Statement of Applicability (SoA). The SoA identifies the controls that are applicable to the ISMS, provides the justification for including or excluding controls, and records their implementation status. It creates a clear link between the organization's risk treatment decisions and the controls selected to address those risks.
Step 6: Implement and Maintain the Controls
Once the necessary controls have been determined, put them into operation and establish processes to maintain their effectiveness. Implementation should be supported by objective evidence demonstrating that controls are not only documented but operating as intended. Depending on the control, this evidence may include access review records, employee training records, vulnerability management reports, supplier assessments, incident records, backup records, physical access logs, and risk treatment documentation.
Step 7: Monitor, Audit, and Continually Improve
ISO 27001 is not a one-time compliance exercise. Organizations must continuously monitor the effectiveness of their ISMS and use the results to drive improvement. This includes conducting internal audits, performing management reviews, addressing nonconformities and corrective actions, reassessing risks when circumstances change, and identifying opportunities for continual improvement. This ongoing cycle helps ensure that the ISMS remains aligned with evolving business requirements, threats, technologies, and regulatory expectations.
Common Mistakes When Using ISO 27001 Control Categories
Understanding the ISO 27001 categories is important, but simply knowing what each category covers does not guarantee an effective ISMS. Organizations can still create gaps by treating the controls as a checklist, focusing too heavily on technology, or failing to connect controls with actual business risks. Here are some common mistakes to avoid.
Treating Annex A as a Checklist
One of the most common mistakes is approaching Annex A as a list of 93 controls that must simply be checked off. ISO 27001 takes a risk-based approach, meaning organizations should determine which controls are necessary based on their specific information security risks and treatment decisions. Implementing controls without establishing this connection can lead to unnecessary controls, weak justification for exclusions, and difficulty demonstrating how the ISMS addresses organizational risks.
Focusing Only on Technological Controls
Security technologies such as firewalls, encryption, endpoint protection, vulnerability scanners, and identity management systems are important, but technology represents only one part of the ISO 27001 control structure. Effective information security also depends on governance, employee responsibilities, physical safeguards, policies, and operational processes. A technically secure environment can still be exposed to significant risk if responsibilities are unclear, processes are inconsistent, or security requirements are not properly governed.
Overlooking People and Physical Security Risks
Cloud adoption, automation, and remote working have changed how organizations operate, but they have not eliminated people-related or physical security risks. Employees can still mishandle sensitive information, lose devices, or fall victim to social engineering, while offices, equipment, and physical records remain exposed to unauthorized access, damage, or theft. A balanced approach to the four ISO 27001 control areas ensures these risks are considered alongside technical threats.
Confusing ISO 27001 Requirements With Annex A Controls
Another common mistake is assuming that certification is primarily about implementing Annex A. ISO/IEC 27001 specifies requirements for establishing, maintaining, and continually improving an Information Security Management System, while Annex A provides a reference set of information security controls. An organization can therefore have controls in place and still have weaknesses in areas such as risk management, internal audits, management review, corrective action, or continual improvement. Certification evaluates the effectiveness of the broader ISMS, not simply whether Annex A controls have been implemented.
Failing to Maintain Objective Evidence
Having a policy or documented procedure does not necessarily demonstrate that a control is operating effectively. For example, a policy may require periodic access reviews, but an organization should also be able to demonstrate that those reviews were actually performed, documented, and followed up when issues were identified. Maintaining appropriate objective evidence helps demonstrate that controls are not merely documented requirements but functioning parts of the organization's ISMS.
Demonstrate a structured approach to information security with ISO/IEC 27001 Certification.Connect with INTERCERT for an independent evaluation of your ISMS against ISO/IEC 27001 requirements.
The Four Categories Are Parts of One ISMS
The 4 category areas of ISO 27001 provide a practical way to understand the broad range of information security controls organizations may need to consider. Organizational controls establish governance and accountability. People controls address workforce-related security risks. Physical controls protect facilities, equipment, and physical information assets. Technological controls provide technical safeguards for systems, networks, applications, and information. But the real value of the ISO 27001 four areas comes from seeing how they work together.
For organizations in the USA pursuing certification, the objective should not be to create four disconnected control programs or simply check off 93 controls. The objective is to establish an ISMS in which security risks are identified, treated, monitored, reviewed, and continually improved. INTERCERT provides ISO 27001 certification services through an independent, impartial, and internationally recognized certification process, with competent auditors evaluating the ISMS against applicable ISO 27001 requirements. For organizations seeking to demonstrate a credible and structured approach to information security, ISO 27001 certification through INTERCERT can provide an independent validation of their ISMS and its effectiveness.