ISO 27001 Annex A Controls Explained
- Jun 29
- 9 min read
ISO 27001 Annex A (sometimes referred to as ISO 27001 Appendix A) is the control reference section of ISO/IEC 27001:2022. It contains the catalogue of information security controls that organisations may select and implement as part of their Information Security Management System (ISMS). The current version of the standard includes 93 Annex A controls, organised into four themes: Organisational Controls, People Controls, Physical Controls, and Technological Controls.
Annex A should not be confused with the main requirements of ISO 27001. Certification is achieved against the mandatory ISMS requirements contained in Clauses 4 to 10, which cover areas such as organisational context, leadership, risk management, support, operation, performance evaluation, and continual improvement. Annex A provides the control framework used to address identified information security risks.
While ISO 27001 lists the controls, ISO/IEC 27002:2022 provides the accompanying guidance on their implementation and operation in practice.
For security and compliance leaders working towards ISO 27001 certification, understanding Annex A is essential because the selected controls must be justified, implemented, and documented within the Statement of Applicability (SoA) and wider ISMS.
The Four Control Themes
ISO/IEC 27001:2022 organises the 93 Annex A controls into four high-level themes that group related security measures together. This structure replaced the 14 control domains used in ISO/IEC 27001:2013, creating a simpler and more intuitive framework for implementing and managing information security controls.
The four themes are:
Organisational Controls (37 controls) – governance, policies, risk management, supplier security, incident management, business continuity, and other management-level security activities.
People Controls (8 controls) – personnel security, awareness, training, disciplinary processes, and the responsibilities individuals have for protecting information.
Physical Controls (14 controls) – protection of facilities, equipment, offices, assets, and physical environments where information is processed or stored.
Technological Controls (34 controls) – technical safeguards such as identity management, access control, encryption, logging, monitoring, vulnerability management, and secure development.
The revised structure reflects the reality that information security depends on more than technology alone. Effective security requires governance, people, physical safeguards, and technical controls working together as part of an integrated Information Security Management System.
In addition to being grouped by theme, each ISO 27001 Annex A control is assigned a set of attributes that help organisations filter and map controls more efficiently. These include categories such as control type, information security property (confidentiality, integrity, and availability), cybersecurity concepts, and operational capabilities. The attribute system makes it easier to align controls with risk assessments, regulatory requirements, and internal security objectives.
The 93 ISO 27001 Annex A Controls
The 93 Annex A controls are grouped into four themes: A.5 Organisational (37 controls), A.6 People (8 controls), A.7 Physical (14 controls), and A.8 Technological (34 controls). For implementation, organisations typically maintain a detailed controls register, Statement of Applicability (SoA), or spreadsheet that maps each control to risks, evidence, and ownership.
Control Group | Controls | Purpose |
A.5 Organisational Controls | A.5.1–A.5.37 | Policies, governance, risk management, supplier security, incident management, business continuity, legal compliance, asset management, information transfer, cloud services, threat intelligence and security assurance. |
A.6 People Controls | A.6.1–A.6.8 | Screening, employment terms, security awareness, disciplinary processes, responsibilities after termination, confidentiality obligations and remote working. |
A.7 Physical Controls | A.7.1–A.7.14 | Physical security perimeters, entry controls, office security, equipment protection, secure disposal, clear desk requirements and protection against environmental threats. |
A.8 Technological Controls | A.8.1–A.8.34 | Identity management, access control, encryption, logging, monitoring, vulnerability management, malware protection, secure development, network security and data protection. |
For most healthcare, life sciences, and NHS suppliers, a relatively small number of the following on the ISO 27001 controls list drive a large proportion of implementation effort and audit scrutiny:
High-Impact Control | Why It Matters |
A.5.7 Threat Intelligence | Demonstrates awareness of emerging threats and vulnerabilities. |
A.5.23 Information Security for Cloud Services | Critical for SaaS and health-tech suppliers. |
A.5.19 Information Security in Supplier Relationships | Supports third-party and supply-chain assurance. |
A.8.2 Privileged Access Rights | Protects high-risk administrative accounts. |
A.8.3 Information Access Restriction | Enforces least-privilege access. |
A.8.15 Logging | Creates audit trails for investigation and compliance. |
A.8.16 Monitoring Activities | Supports detection and response capabilities. |
A.8.8 Management of Technical Vulnerabilities | Ensures vulnerabilities are identified and remediated. |
A.8.24 Use of Cryptography | Protects sensitive and patient information. |
A.8.25 Secure Development Lifecycle | Essential for SaMD, AIaMD and healthcare software. |
A.8.28 Secure Coding | Reduces software security defects. |
For organisations handling healthcare or patient data, controls relating to monitoring, logging, threat detection, and incident response are increasingly supported through dedicated security operations capabilities such as a managed SOC and SIEM, helping demonstrate effective implementation of Annex A requirements while strengthening cyber resilience.
What Changed In ISO 27001:2022
The 2022 revision of ISO 27001 and ISO 27002 introduced the most significant restructuring of Annex A in almost a decade. The previous 114 controls organised across 14 domains were streamlined into 93 controls grouped under four themes: Organisational, People, Physical, and Technological Controls. The objective was not to reduce security requirements, but to modernise the control framework and improve usability.
According to ISO/IEC 27002:2022, the revision introduced 11 new controls, merged a number of overlapping controls, and updated many existing controls to reflect modern technology, cloud adoption, cyber threats, and digital operating models.
The 11 new controls are:
Threat Intelligence
Information Security for Use of Cloud Services
ICT Readiness for Business Continuity
Physical Security Monitoring
Configuration Management
Information Deletion
Data Masking
Data Leakage Prevention
Monitoring Activities
Web Filtering
Secure Coding
These additions reflect areas that have become increasingly important since the 2013 version of the standard, particularly cloud security, cyber threat awareness, resilience, software security, and the protection of sensitive data.
Many existing controls were also consolidated and updated to remove duplication and align with contemporary security practices. As a result, organisations transitioning from ISO 27001:2013 were required to review their Statement of Applicability, risk assessments, policies, and control mappings to ensure continued alignment with the revised structure.
The transition period from ISO 27001:2013 to ISO 27001:2022 formally ended on 31 October 2025. Organisations holding certification against the 2013 version were required to complete their transition before this deadline. ISO 27001:2013 certificates are now withdrawn, and accredited certification bodies assess organisations against ISO/IEC 27001:2022.
Selecting Controls And The SoA
One of the most common misconceptions about ISO 27001 is that organisations are expected to implement all 93 Annex A controls. In reality, ISO 27001 is a risk-based standard. Controls are selected based on the risks identified within the Information Security Management System (ISMS), not adopted wholesale simply because they appear in Annex A.
The process begins with risk assessment and risk treatment. Organisations identify threats, vulnerabilities, business impacts, and risk owners before determining how identified risks will be managed. Where a control is required to reduce risk to an acceptable level, it is selected and implemented. Where a control is not relevant to the organisation's scope, technology, operations, or risk profile, it may be excluded.
These decisions are documented within the Statement of Applicability (SoA), one of the most important documents in an ISO 27001-certified ISMS. The SoA records which Annex A controls have been included, which have been excluded, their implementation status, and the justification for each decision. During certification audits, auditors will expect to see a clear rationale for both inclusions and exclusions.
The relationship between Annex A and ISO 27002 is also frequently misunderstood. Annex A within ISO/IEC 27001:2022 contains the official list of 93 controls. ISO/IEC 27002:2022 provides the implementation guidance for those controls, explaining their objectives, purpose, and examples of how they may be applied in practice. Put simply, ISO 27001 Annex A tells organisations what controls are available, while ISO 27002 helps explain how they can be implemented.
A strong SoA creates traceability between risk management and control implementation. Every included control should be linked to a risk treatment decision, and every excluded control should have a documented justification. This demonstrates that the ISMS is genuinely risk-based rather than a collection of generic policies and controls. For auditors, regulators, customers, and stakeholders, the SoA is often the clearest demonstration of how an organisation has translated information security risks into practical and proportionate security measures.
ISO 27001 Annex A Controls For NHS And Healthcare
For NHS suppliers, Annex A controls are more than an ISO 27001 certification requirement. They provide a practical framework for demonstrating many of the governance, cybersecurity, and information protection measures expected across the healthcare sector.
There is significant overlap between ISO 27001 and the NHS Data Security and Protection Toolkit (DSPT). While the DSPT is a distinct NHS-specific assurance framework, many of its requirements align closely with Annex A controls covering areas such as information security policies, asset management, access control, supplier assurance, incident management, staff awareness, business continuity, logging, monitoring, and risk management. As a result, organisations with a mature ISO 27001-certified Information Security Management System often find that a substantial proportion of DSPT evidence already exists.
This does not mean that ISO 27001 replaces the DSPT. NHS organisations and suppliers must still satisfy the specific requirements of the toolkit and demonstrate ISO 27001 compliance with the National Data Guardian's Data Security Standards. However, ISO 27001 Annex A controls provide a strong foundation for building the policies, procedures, records, and governance arrangements needed to support assurance activities.
Several controls are particularly relevant to healthcare, life sciences, and medical device environments. Supplier relationship security controls help manage risks arising from outsourced services, cloud providers, software vendors, and third-party processors. Information security for cloud services is increasingly important as healthcare organisations adopt cloud-hosted platforms and Software as a Service solutions. Incident management, logging, monitoring activities, and threat intelligence controls support the detection and response capabilities expected by both NHS buyers and regulators.
For medical device manufacturers and digital health companies operating internationally, Annex A controls also support wider cybersecurity obligations. Regulatory frameworks such as the EU NIS2 Directive and the Cyber Resilience Act place increasing emphasis on governance, vulnerability management, incident handling, supply-chain security, and secure development practices. ISO 27001 controls relating to secure coding, vulnerability management, monitoring, and supplier assurance are therefore becoming increasingly important beyond ISO certification alone.
For healthcare organisations, ISO 27001 Annex A is best viewed as a practical security baseline that strengthens both NHS assurance activities and broader regulatory compliance.
For regulated healthcare, life sciences, and medical device organisations, ISO 27001 Annex A controls are rarely implemented in isolation. The challenge is demonstrating how information security controls align with wider regulatory, clinical safety, and assurance requirements. The AbedGraham Group specialises in helping healthcare organisations map ISO 27001 controls to NHS frameworks, medical device regulations, DSPT requirements, and emerging cybersecurity obligations. This enables organisations to build a single, risk-based assurance programme that supports certification, regulatory compliance, NHS procurement, and operational resilience without creating unnecessary duplication of effort.
ISO 27001 Annex A FAQs
How many controls are in ISO 27001 Annex A?
ISO/IEC 27001:2022 Annex A contains 93 information security controls. These controls provide a reference catalogue that organisations can use to treat information security risks identified through their Information Security Management System (ISMS). Not every control will apply to every organisation, which is why control selection is driven by risk assessment and documented within the Statement of Applicability.
What are the four control themes in ISO 27001?
The 93 controls are grouped into four themes: Organisational Controls (37), People Controls (8), Physical Controls (14), and Technological Controls (34). This structure was introduced in ISO 27001:2022 and replaced the 14 control domains used in the 2013 version. The revised grouping makes the controls easier to navigate and align with modern security programmes.
What is the current version of ISO 27001?
The current version is ISO/IEC 27001:2022. It introduced a revised Annex A structure, new controls covering areas such as threat intelligence, cloud security, and secure coding, and updated terminology to reflect modern security practices. The transition period from ISO 27001:2013 ended on 31 October 2025, and organisations are now certified against the 2022 version.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard that defines the requirements for an Information Security Management System. ISO 27002 is a supporting guidance standard that explains how Annex A controls can be implemented in practice. In simple terms, ISO 27001 defines what must be achieved, while ISO 27002 provides guidance on how controls may be applied.
Is every ISO 27001 Annex A control mandatory?
No. ISO 27001 is a risk-based standard, meaning controls are selected based on the organisation's risk profile rather than implemented automatically. Any ISO 27001 controls that are not relevant may be excluded, provided there is a documented justification. Auditors will expect to see clear evidence that control selection and exclusion decisions are linked to risk treatment activities.
What is the Statement of Applicability (SoA)?
The Statement of Applicability is a mandatory ISO 27001 document that records which Annex A controls have been selected, which have been excluded, their implementation status, and the justification for each decision. It acts as the bridge between risk assessment, risk treatment, and control implementation and is one of the most closely scrutinised documents during certification audits.
Next Steps With ISO 27001 Annex A
Annex A is the control framework that sits at the heart of ISO/IEC 27001:2022. Its 93 controls provide organisations with a structured set of security measures that can be selected and implemented in response to identified risks. Effective implementation is not about applying every control by default; it is about using risk assessment and risk treatment activities to determine which controls are appropriate and documenting those decisions within the Statement of Applicability (SoA).
Organisations pursuing certification should also be aware that ISO/IEC 27001:2022 is now the only current certifiable version of the standard. The transition period from ISO 27001:2013 ended on 31 October 2025, and certification bodies now assess organisations against the 2022 requirements and Annex A structure.
For healthcare providers, health-tech companies, medical device manufacturers, and NHS suppliers, implementing Annex A effectively often requires balancing ISO requirements with NHS assurance frameworks, cybersecurity obligations, and regulatory expectations. The AbedGraham Group helps regulated healthcare organisations design, implement, and maintain proportionate ISO 27001 programmes that support certification, NHS assurance, and long-term cyber resilience.
Book a discovery call to discuss your cybersecurity requirements today.


Comments