ISO 27001 List of Controls: What the 93 Annex A Controls Actually Cover
By Brian Crocker · Published 23 August 2026
ISO 27001:2022 Annex A contains 93 information security controls across 4 categories. Your Statement of Applicability must address every one — either implementing it or documenting a justified exclusion. Understanding what each control actually requires is the difference between a paper ISMS and one that survives a Stage 2 audit.
This guide breaks down all 93 controls in plain English, with evidence prompts and UK SMB applicability notes for each category.
The 2022 restructure: from 114 to 93 controls
ISO 27001:2022 reduced the Annex A control list from 114 controls in 14 categories (2013 version) to 93 controls in 4 categories. The restructuring was significant:
- 58 controls were revised
- 24 controls were merged from 57 existing controls
- 11 controls were new
- 1 control was split into two
No controls were deleted — the reduction from 114 to 93 came entirely from consolidating 57 controls into 24.
The 4 new categories replace the 14 old domains:
- A.5 Organisational controls — 37 controls (was spread across multiple old domains)
- A.6 People controls — 8 controls (replaced A.7 in 2013)
- A.7 Physical controls — 14 controls (replaced A.11 in 2013)
- A.8 Technological controls — 34 controls (drawn from A.9, A.10, A.12, A.13 and A.14 in 2013)
If you built your ISMS against ISO 27001:2013, you need a gap analysis against the 2022 version — particularly for the 11 new controls which did not exist in 2013. Our ISO 27001 gap analysis template covers this.
A.5 Organisational controls (37 controls)
Organisational controls cover policies, governance, roles, and management processes.
A.5.1 Policies for information security: Establish, approve, communicate, and review a top-level information security policy and topic-specific policies. Evidence: signed policy document, distribution records, review history. See ISO 27001 Policy Templates.
A.5.2 Information security roles and responsibilities: Define and allocate information security responsibilities. Evidence: role descriptions, ISMS organisation chart, named ISMS Manager.
A.5.3 Segregation of duties: Separate conflicting duties to prevent fraud and error. Evidence: access control configuration showing no single person can initiate and approve transactions; documented role assignments.
A.5.4 Management responsibilities: Management must require staff to apply information security in accordance with established policies. Evidence: employment contracts referencing security obligations; management sign-off on ISMS.
A.5.5 Contact with authorities: Maintain contacts with relevant authorities (police, ICO, NCSC). Evidence: contacts list; procedure for when to contact each authority (e.g. data breach → ICO within 72 hours).
A.5.6 Contact with special interest groups: Maintain memberships or connections with security forums and industry groups. Evidence: NCSC Early Warning Service subscription, industry ISAC membership, or equivalent.
A.5.7 Threat intelligence: Gather and analyse information about relevant threats. Evidence: process for monitoring threat advisories (NCSC alerts, vendor bulletins); evidence of acting on intelligence.
A.5.8 Information security in project management: Integrate security into project management. Evidence: project initiation checklist including security review; risk assessment for significant new projects.
A.5.9 Inventory of information and other associated assets: Maintain an asset inventory. Evidence: documented asset register covering information, software, hardware, services, people, and premises.
A.5.10 Acceptable use of information and other associated assets: Rules for acceptable use of assets. Evidence: documented acceptable use policy; staff sign-off during induction.
A.5.11 Return of assets: Procedures for returning assets when employment or contract ends. Evidence: leaver checklist; evidence of asset return or sign-off.
A.5.12 Classification of information: Classify information based on confidentiality requirements. Evidence: classification scheme (e.g. Public / Internal / Confidential / Restricted); labelling policy; training records.
A.5.13 Labelling of information: Apply classification labels to information. Evidence: email classification rules; file naming conventions; physical document labelling procedure.
A.5.14 Information transfer: Secure transfer of information between internal and external parties. Evidence: data transfer policy; approved transfer methods; NDAs for third parties receiving confidential information.
A.5.15 Access control: Define and implement access control rules. Evidence: access control policy; user access matrix showing least-privilege; access request and approval process.
A.5.16 Identity management: Manage the full lifecycle of identities. Evidence: joiner/mover/leaver process; identity provisioning records; inactive account review.
A.5.17 Authentication information: Manage authentication credentials. Evidence: password policy (length, complexity, MFA); no shared credentials; password manager policy.
A.5.18 Access rights: Provision, review, modify, and revoke access rights. Evidence: access request records; quarterly access reviews for privileged accounts; leaver access revocation records.
A.5.19 Information security in supplier relationships: Protect organisational information accessed or processed by suppliers. Evidence: supplier assessment procedure; contractual security requirements.
A.5.20 Addressing information security within supplier agreements: Include information security requirements in supplier contracts. Evidence: data processing agreements (required for UK GDPR); security clauses in supplier contracts.
A.5.21 Managing information security in the ICT supply chain: Address security in ICT product and service supply chains. Evidence: software assurance process; evaluation of cloud providers' security certifications (ISO 27001, SOC 2).
A.5.22 Monitoring, review and change management of supplier services: Monitor, review, and manage supplier relationships. Evidence: annual supplier review records; supplier incident response procedure.
A.5.23 Information security for use of cloud services: Define and manage security for cloud service use. Evidence: approved cloud services list; data residency assessment; exit plan for critical cloud services.
A.5.24 Information security incident management planning and preparation: Plan for security incidents. Evidence: incident response plan; defined severity classifications; communication escalation.
A.5.25 Assessment and decision on information security events: Assess security events and classify as incidents. Evidence: incident log; triage process; defined incident classification criteria.
A.5.26 Response to information security incidents: Respond to security incidents. Evidence: incident response records; containment and recovery steps documented; post-incident review.
A.5.27 Learning from information security incidents: Learn from incidents to improve. Evidence: post-incident review reports; evidence that lessons resulted in control improvements.
A.5.28 Collection of evidence: Collect and preserve evidence relating to incidents. Evidence: evidence handling procedure; chain of custody documentation for serious incidents.
A.5.29 Information security during disruption: Protect information security during disruption. Evidence: business continuity plan covering information security; BCP testing records.
A.5.30 ICT readiness for business continuity: Plan, implement, and test ICT continuity measures. Evidence: ICT continuity plan; recovery time and recovery point objectives; test results.
A.5.31 Legal, statutory, regulatory, and contractual requirements: Identify and comply with relevant legal requirements. Evidence: legal compliance register (UK GDPR, Data Protection Act 2018, Computer Misuse Act, sector-specific regulations); compliance review records.
A.5.32 Intellectual property rights: Protect intellectual property. Evidence: software licence register; procedure for checking licence compliance; prohibition on unlicensed software.
A.5.33 Protection of records: Protect records from loss, destruction, and falsification. Evidence: records retention schedule; backup verification; access controls on record repositories.
A.5.34 Privacy and protection of PII: Protect personal information per applicable privacy requirements. Evidence: UK GDPR compliance programme; privacy notices; DPIAs where required; ICO registration.
A.5.35 Independent review of information security: Conduct independent reviews of ISMS implementation. Evidence: internal audit programme; external audit or assessment records. See ISO 27001 Internal Audit Guide.
A.5.36 Compliance with policies, rules and standards for information security: Review compliance with policies and standards. Evidence: compliance review records; management review inputs showing policy adherence assessment.
A.5.37 Documented operating procedures: Document operational procedures for information processing. Evidence: operational SOPs; evidence of version control and communication.
A.6 People controls (8 controls)
People controls cover security obligations related to employment.
A.6.1 Screening: Conduct background checks on candidates and contractors. Evidence: HR policy on pre-employment screening; records of checks conducted (DBS, references, right to work). Note: proportionate to role — senior IT staff with privileged access warrant more extensive screening.
A.6.2 Terms and conditions of employment: Include information security responsibilities in employment terms. Evidence: employment contracts referencing acceptable use policy and confidentiality obligations; contractor agreements.
A.6.3 Information security awareness, education and training: Provide security awareness training. Evidence: annual training programme; attendance records; evidence of tailored training for high-risk roles. Training must be repeated — one induction session does not satisfy this control.
A.6.4 Disciplinary process: Have a formal disciplinary process for policy violations. Evidence: HR disciplinary procedure referencing information security breaches; evidence it has been applied (anonymised records acceptable).
A.6.5 Responsibilities after termination or change of employment: Security obligations on termination or role change. Evidence: leaver checklist; evidence of access revocation; exit interview or security briefing records.
A.6.6 Confidentiality or non-disclosure agreements: Use NDAs where appropriate. Evidence: template NDA; records of NDAs executed with staff, contractors, and third parties receiving confidential information.
A.6.7 Remote working: Protect information when working remotely. Evidence: remote working policy; VPN configuration; device encryption enforcement; clean desk when working from home.
A.6.8 Information security event reporting: Staff should report security events promptly. Evidence: reporting procedure communicated in training; evidence channel exists (email address, helpdesk ticket, form); incident log showing reports received.
A.7 Physical controls (14 controls)
Physical controls cover the physical environment of information processing.
A.7.1 Physical security perimeters: Define and use security perimeters around facilities. Evidence: office entry controls (locked doors, entry cards); server room access restrictions; visitor log.
A.7.2 Physical entry: Control physical access to facilities. Evidence: access control system records; visitor procedure; escort policy for visitors in secure areas.
A.7.3 Securing offices, rooms and facilities: Secure physical spaces. Evidence: lock policy for offices containing sensitive information; secure storage for paper records.
A.7.4 Physical security monitoring: Monitor physical areas. Evidence: CCTV (where appropriate); intruder alarm; monitoring records.
A.7.5 Protecting against physical and environmental threats: Protect against physical threats (fire, flood, power). Evidence: fire suppression or detection in server room; UPS for critical systems; documented environmental assessment.
A.7.6 Working in secure areas: Apply rules for working in secure areas. Evidence: secure area procedures; prohibition on unauthorised devices in secure areas; clean desk enforcement.
A.7.7 Clear desk and clear screen: Maintain clear desk and screen lock policy. Evidence: documented policy; clean desk inspections; automatic screen lock configured.
A.7.8 Equipment siting and protection: Position equipment to reduce risk. Evidence: server room siting assessment; cable management records; monitor positioning (no screens visible from public areas).
A.7.9 Security of assets off-premises: Protect assets taken off-site. Evidence: laptop encryption (verified via configuration reports); mobile device management; approval process for taking assets off-site.
A.7.10 Storage media: Manage storage media across acquisition, use, and disposal. Evidence: removable media policy; USB use restrictions or prohibition; secure disposal records (certificate of destruction for hard drives).
A.7.11 Supporting utilities: Protect against power and utility failures. Evidence: UPS for servers; generator or alternative power for critical operations; environmental monitoring.
A.7.12 Cabling security: Protect communications cabling. Evidence: network cable routing records; prevention of access to cable runs; labelling of network connections.
A.7.13 Equipment maintenance: Maintain equipment to ensure availability and integrity. Evidence: maintenance schedule; vendor support contracts; patch management records.
A.7.14 Secure disposal or re-use of equipment: Dispose of equipment securely. Evidence: equipment disposal procedure; hard drive wiping records or physical destruction certificates; asset register updated on disposal.
A.8 Technological controls (34 controls)
Technological controls cover security measures implemented in systems and software.
A.8.1 User endpoint devices: Protect user endpoint devices. Evidence: endpoint protection configuration (antivirus, EDR); encryption enforcement; device management records.
A.8.2 Privileged access rights: Restrict and manage privileged access. Evidence: privileged account register; quarterly review records; no shared admin accounts; MFA on admin accounts.
A.8.3 Information access restriction: Restrict access to information per access control policy. Evidence: access control lists; role-based access configuration; audit logs of access.
A.8.4 Access to source code: Control access to source code. Evidence: version control system with access restrictions; branch protection rules; code review process. (Applicable if you develop software.)
A.8.5 Secure authentication: Implement secure authentication. Evidence: MFA enforcement on all systems handling sensitive data; password policy configuration; SSO implementation.
A.8.6 Capacity management: Monitor and manage system capacity. Evidence: capacity monitoring dashboards; alerts for storage or CPU thresholds; documented capacity review records.
A.8.7 Protection against malware: Protect against malware. Evidence: endpoint protection software installed and updated; email filtering; web filtering; staff training on phishing.
A.8.8 Management of technical vulnerabilities: Identify and manage technical vulnerabilities. Evidence: vulnerability scanning schedule and results; patch management policy and records; CVE monitoring process.
A.8.9 Configuration management: Manage security configurations. Evidence: documented baseline configurations; change control process for configuration changes; configuration audit records.
A.8.10 Information deletion: Delete information when no longer needed. Evidence: data retention schedule; records of data deletion; secure deletion method for sensitive data.
A.8.11 Data masking: Mask sensitive data where appropriate. Evidence: PII masking in non-production environments; data masking in reports and exports; applicable to SQL databases and analytics.
A.8.12 Data leakage prevention: Prevent unauthorised disclosure of sensitive information. Evidence: DLP tool configuration; USB restriction policy; email monitoring for sensitive content exfiltration.
A.8.13 Information backup: Back up information and test recovery. Evidence: backup schedule; off-site or cloud backup; tested restore procedure with documented results; RPO/RTO defined.
A.8.14 Redundancy of information processing facilities: Implement redundancy to meet availability requirements. Evidence: high availability configuration for critical systems; failover test records; documentation of single points of failure.
A.8.15 Logging: Produce, protect, and analyse event logs. Evidence: logging enabled on servers, network devices, and applications; log retention period defined; regular log review records.
A.8.16 Monitoring activities: Monitor networks and systems for anomalies. Evidence: SIEM or monitoring tool; alert thresholds defined; evidence of alerts reviewed and acted on.
A.8.17 Clock synchronisation: Synchronise clocks across systems. Evidence: NTP configuration on all systems; clock sync verification records; log timestamps consistent across systems.
A.8.18 Use of privileged utility programs: Control privileged utility programs. Evidence: approved tools list; access restriction on diagnostic and administration utilities; change records for privileged tool use.
A.8.19 Installation of software on operational systems: Control software installation. Evidence: software installation policy; change management approval for new software; software inventory.
A.8.20 Networks security: Protect networks. Evidence: network segmentation design; firewall rule review records; segregation of guest and corporate Wi-Fi.
A.8.21 Security of network services: Secure network services. Evidence: ISP/managed network service contracts with security SLAs; network service monitoring.
A.8.22 Segregation of networks: Separate networks based on trust levels. Evidence: VLAN configuration; DMZ for internet-facing systems; guest Wi-Fi isolated from internal network.
A.8.23 Web filtering: Control access to external websites. Evidence: web filtering policy; DNS filtering or proxy configuration; blocked category list.
A.8.24 Use of cryptography: Implement cryptographic controls. Evidence: cryptography policy; encryption of data at rest (disk encryption) and in transit (TLS 1.2+); key management process.
A.8.25 Secure development life cycle: Apply security in development. Evidence: secure coding standards; security testing in SDLC; SAST/DAST tools in pipeline. (Applicable to software development organisations.)
A.8.26 Application security requirements: Define and enforce application security requirements. Evidence: security requirements in functional specifications; pen test results; OWASP Top 10 assessment.
A.8.27 Secure system architecture and engineering principles: Apply secure architecture principles. Evidence: documented architecture review process; defence-in-depth design; zero trust principles where applicable.
A.8.28 Secure coding: Apply secure coding practices. Evidence: secure coding guidelines; code review for security; developer security training records.
A.8.29 Security testing in development and acceptance: Test security in development and acceptance. Evidence: security test plan; test results; vulnerabilities remediated before production deployment.
A.8.30 Outsourced development: Supervise and monitor outsourced development. Evidence: supplier contracts with security requirements; code review of outsourced deliverables; security acceptance criteria.
A.8.31 Separation of development, test and production environments: Separate environments. Evidence: separate development/test/production systems; no production data in test; change management between environments.
A.8.32 Change management: Manage changes to information processing facilities. Evidence: change request process; impact assessment; approval; testing before production deployment; rollback plan.
A.8.33 Test information: Protect test information. Evidence: prohibition on production data in test; data masking for test datasets; access restriction on test systems.
A.8.34 Protection of information systems during audit testing: Protect systems during audit and testing. Evidence: audit tool access restrictions; audit scope defined and approved; test environment used for penetration testing where possible.
Applying this to your Statement of Applicability
Your SoA must address all 93 controls. For each: applicable or not applicable, justification, and implementation status. Controls you exclude must have a justification — "we have no physical offices" or "we do not develop software" are valid if true. "We don't do this" without a risk-based reason is not.
Our ISO 27001 Annex A Controls Checklist provides an interactive applicability assessment for all 93 controls with evidence prompts and links back to your risk register.
This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO certification requirements vary by scope, sector, and certification body. Always verify requirements with your UKAS-accredited certification body or a qualified consultant before making compliance decisions.
ClauseWise is coming soon
Generate your ISO 9001 and ISO 27001 documentation without consultant fees.