Annex A Controls and Their Themes
Annex A of ISO/IEC 27001:2022 is a normative reference list of information security controls. Organizations use it during risk treatment under Clause 6.1.3. Annex A is not a mandatory checklist. Organizations first determine the controls they need to treat identified risks, then compare those contr… Annex A of ISO/IEC 27001:2022 is a normative reference list of information security controls. Organizations use it during risk treatment under Clause 6.1.3. Annex A is not a mandatory checklist. Organizations first determine the controls they need to treat identified risks, then compare those controls against Annex A to ensure no necessary control has been overlooked. The result is documented in the Statement of Applicability (SoA). The SoA lists each necessary control, states whether it is implemented, and justifies its inclusion or exclusion. The 2022 revision reduced the controls from 114 (in 14 domains) to 93, grouped into four themes. 1) Organizational controls (A.5, 37 controls) cover governance and management topics. Examples include information security policies, roles and responsibilities, asset inventory, access control, supplier relationships, incident management, business continuity, legal compliance and threat intelligence. 2) People controls (A.6, 8 controls) address the human factor. They cover screening, terms of employment, awareness and training, the disciplinary process, responsibilities after termination, confidentiality agreements, remote working and event reporting. 3) Physical controls (A.7, 14 controls) protect premises and equipment. They include security perimeters, entry controls, physical security monitoring, clear desk and clear screen, equipment siting, storage media handling and secure disposal. 4) Technological controls (A.8, 34 controls) cover technical safeguards. Examples include endpoint devices, privileged access, malware protection, vulnerability management, configuration management, backup, logging, monitoring, network security, cryptography, secure development and data leakage prevention. The revision introduced 11 new controls, including cloud services security, data masking, information deletion, web filtering and secure coding. ISO/IEC 27002 supports these controls with implementation guidance and optional attributes, such as control type (preventive, detective, corrective) and the confidentiality, integrity and availability properties each control supports. For a Lead Auditor, the focus is on the following points. Verify that control selection is traceable to the risk assessment. Confirm that exclusions in the SoA are justified. Gather objective evidence that the selected controls are implemented and operating effectively, through interviews, observation and records review. Always keep in mind that the controls serve the overall ISMS requirements in Clauses 4 to 10.
Annex A Controls and Their Themes in ISO/IEC 27001:2022: A Lead Auditor's Guide
Introduction
Annex A of ISO/IEC 27001:2022 is one of the most heavily examined topics in any ISO 27001 Lead Auditor course. It is a normative reference list of information security controls. Every organization implementing an Information Security Management System (ISMS) must compare its chosen controls against it. As a lead auditor, you must understand what Annex A contains, how its controls are grouped into themes, and how it links to the main clauses of the standard (especially Clause 6.1.3 and the Statement of Applicability). You must also know how to audit it. This guide covers what Annex A is, why it matters, how it works in practice, and how to answer exam questions on it confidently.
1. Why Annex A Controls and Their Themes Are Important
It is the bridge between risk and action. Clauses 4 to 10 describe the management system: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A provides the reference set of controls that actually treat information security risks. Without it, risk treatment would have no common benchmark.
It is mandatory to consult. Clause 6.1.3 c) requires the organization to compare the controls it has determined as necessary with those in Annex A. The purpose is to verify that no necessary controls have been omitted. Organizations cannot simply ignore it.
It drives the Statement of Applicability (SoA). The SoA is a mandatory document. It lists the necessary controls, the justification for their inclusion, whether they are implemented, and the justification for excluding any Annex A control. Auditors rely heavily on the SoA when planning and conducting audits.
It supports audit planning and sampling. The four themes give auditors a logical structure for allocating audit time, assigning team members and building audit checklists. For example, a technical expert may take Technological controls while the lead auditor covers Organizational controls.
It reflects the 2022 revision. The 2022 edition restructured the controls completely, moving from 114 controls in 14 domains to 93 controls in 4 themes. Exams frequently test whether candidates know the new structure, the new controls and the transition implications.
2. What Annex A Is
Annex A is titled Information security controls reference. It is normative, meaning it forms a required part of the standard rather than optional guidance. It lists control titles and short control statements that are directly aligned with ISO/IEC 27002:2022. ISO/IEC 27002 provides the detailed implementation guidance, purpose and attributes for each control.
Key facts to memorize:
- Total controls: 93 (down from 114 in ISO/IEC 27001:2013).
- Number of themes: 4 (replacing the 14 domains A.5 to A.18 of the 2013 version).
- New controls: 11.
- Changes from 2013: 24 controls were created by merging earlier controls, and 58 were updated. No control was truly removed; content was consolidated.
- Transition deadline: Certified organizations had until 31 October 2025 to transition to the 2022 version.
The Four Themes
Theme 1: Organizational controls (Clause 5, controls 5.1 to 5.37), 37 controls.
This is the default category for controls that do not fit the other three themes. Examples include:
- 5.1 Policies for information security
- 5.2 Information security roles and responsibilities
- 5.3 Segregation of duties
- 5.7 Threat intelligence (new)
- 5.9 Inventory of information and other associated assets
- 5.12 Classification of information
- 5.15 Access control
- 5.19 to 5.22 Supplier relationships
- 5.23 Information security for use of cloud services (new)
- 5.24 to 5.28 Incident management (planning, assessment, response, learning, collection of evidence)
- 5.29 Information security during disruption
- 5.30 ICT readiness for business continuity (new)
- 5.31 Legal, statutory, regulatory and contractual requirements
- 5.34 Privacy and protection of PII
- 5.35 Independent review of information security
Theme 2: People controls (Clause 6, controls 6.1 to 6.8), 8 controls.
These controls concern individual people. They are:
- 6.1 Screening
- 6.2 Terms and conditions of employment
- 6.3 Information security awareness, education and training
- 6.4 Disciplinary process
- 6.5 Responsibilities after termination or change of employment
- 6.6 Confidentiality or non-disclosure agreements
- 6.7 Remote working
- 6.8 Information security event reporting
Theme 3: Physical controls (Clause 7, controls 7.1 to 7.14), 14 controls.
These controls concern physical objects and environments. Examples include:
- 7.1 Physical security perimeters
- 7.2 Physical entry
- 7.3 Securing offices, rooms and facilities
- 7.4 Physical security monitoring (new)
- 7.5 Protecting against physical and environmental threats
- 7.7 Clear desk and clear screen
- 7.8 Equipment siting and protection
- 7.9 Security of assets off-premises
- 7.10 Storage media
- 7.11 Supporting utilities
- 7.12 Cabling security
- 7.13 Equipment maintenance
- 7.14 Secure disposal or re-use of equipment
Theme 4: Technological controls (Clause 8, controls 8.1 to 8.34), 34 controls.
These controls concern technology. Examples include:
- 8.1 User endpoint devices
- 8.2 Privileged access rights
- 8.5 Secure authentication
- 8.7 Protection against malware
- 8.8 Management of technical vulnerabilities
- 8.9 Configuration management (new)
- 8.10 Information deletion (new)
- 8.11 Data masking (new)
- 8.12 Data leakage prevention (new)
- 8.13 Information backup
- 8.15 Logging
- 8.16 Monitoring activities (new)
- 8.20 Networks security
- 8.23 Web filtering (new)
- 8.24 Use of cryptography
- 8.25 Secure development life cycle
- 8.28 Secure coding (new)
- 8.32 Change management
- 8.34 Protection of information systems during audit testing
Memory aid: O-P-P-T = 37-8-14-34 = 93. Some candidates remember it as "37 Orgs, 8 People, 14 Places, 34 Tech".
The 11 New Controls (frequently examined)
5.7 Threat intelligence; 5.23 Information security for use of cloud services; 5.30 ICT readiness for business continuity; 7.4 Physical security monitoring; 8.9 Configuration management; 8.10 Information deletion; 8.11 Data masking; 8.12 Data leakage prevention; 8.16 Monitoring activities; 8.23 Web filtering; 8.28 Secure coding.
Control Attributes (from ISO/IEC 27002:2022)
ISO/IEC 27002 assigns five attribute types to each control. This allows organizations to filter and view controls in different ways. The attributes are:
- Control type: #Preventive, #Detective, #Corrective.
- Information security properties: #Confidentiality, #Integrity, #Availability.
- Cybersecurity concepts: #Identify, #Protect, #Detect, #Respond, #Recover (aligned with the NIST Cybersecurity Framework).
- Operational capabilities: for example, #Governance, #Asset_management, #Identity_and_access_management, #Threat_and_vulnerability_management.
- Security domains: #Governance_and_Ecosystem, #Protection, #Defence, #Resilience.
Attributes are informative, not mandatory. Organizations may also create their own attributes.
3. How Annex A Works in Practice
Step 1: Risk assessment (Clause 6.1.2). The organization identifies, analyses and evaluates information security risks.
Step 2: Risk treatment options (Clause 6.1.3 a). For each risk, the organization chooses to modify (treat), retain, avoid or share the risk.
Step 3: Determine necessary controls (Clause 6.1.3 b). Controls can be designed by the organization or taken from any source. Annex A is not the only permitted source.
Step 4: Compare with Annex A (Clause 6.1.3 c). The organization checks its determined controls against Annex A to ensure nothing necessary has been overlooked. The standard notes that Annex A is not exhaustive, so additional controls can be included.
Step 5: Produce the Statement of Applicability (Clause 6.1.3 d). The SoA must contain:
- the necessary controls;
- the justification for their inclusion;
- whether they are implemented or not;
- the justification for excluding any Annex A controls.
Step 6: Formulate the risk treatment plan (Clause 6.1.3 e) and obtain risk owner approval (Clause 6.1.3 f). Risk owners must approve the risk treatment plan and accept the residual risks.
Step 7: Implement and operate (Clause 8.3). The organization implements the risk treatment plan and retains documented information on the results.
Step 8: Monitor, audit and improve (Clauses 9 and 10). Controls are measured, internally audited and reviewed by management. Nonconformities are corrected.
Exclusions. An organization may exclude an Annex A control only when it provides a valid justification. Typical reasons are that the risk does not exist or the activity is not performed. For example, 8.28 Secure coding may be excluded if the organization does no software development. Exclusions based on cost or inconvenience alone, without a risk-based rationale, are a red flag for auditors.
How an auditor audits Annex A:
- Review the SoA during the stage 1 audit for completeness, justifications and consistency with the risk assessment and scope.
- During stage 2, sample controls across all four themes. Verify their design and operating effectiveness through interviews, observation and records. Examples include screening records for 6.1, visitor logs for 7.2, backup restore tests for 8.13, and access reviews for 5.18.
- Check traceability in both directions: risk to control to SoA to evidence, and the reverse.
- Raise a nonconformity when a control declared as implemented in the SoA is not effective. Also raise one when an exclusion is unjustified or a necessary control is missing (this is typically a nonconformity against Clause 6.1.3).
- Remember that Annex A controls are audited against the organization's own SoA and policies, not as a rigid checklist imposed on everyone.
4. Common Misconceptions
- "All 93 controls must be implemented." False. Only controls deemed necessary through risk treatment must be implemented. Exclusions must be justified.
- "Annex A is just guidance." False. Annex A is normative. ISO/IEC 27002 is the guidance document.
- "Organizations can only use Annex A controls." False. Controls may come from any source, and Annex A is not exhaustive.
- "Organizations can be certified to ISO/IEC 27002." False. Certification is only to ISO/IEC 27001.
- "Attributes are mandatory." False. Attributes are informative, appear in ISO/IEC 27002, and are optional.
5. Exam Tips: Answering Questions on Annex A Controls and Their Themes
Tip 1: Know the numbers cold. Memorize 93 controls, 4 themes, 37/8/14/34, and 11 new controls. Also know the 2013 figures: 114 controls and 14 domains. Many multiple-choice questions are direct recall of these figures.
Tip 2: Use the theme classification logic. When unsure which theme a control belongs to, apply ISO/IEC 27002's rule:
- Controls concerning individual people are People controls.
- Controls concerning physical objects are Physical controls.
- Controls concerning technology are Technological controls.
- Everything else is an Organizational control.
Watch for traps. 6.7 Remote working and 6.8 Information security event reporting are People controls. Incident management (5.24 to 5.28) is Organizational. Clear desk and clear screen (7.7) is Physical. Access control policy (5.15) is Organizational, while Secure authentication (8.5) is Technological.
Tip 3: Link controls to Clause 6.1.3. Questions often ask where the requirement to compare controls with Annex A is located, or what the SoA must contain. The answer is Clause 6.1.3 c) for the comparison and 6.1.3 d) for the SoA. Remember all four SoA elements.
Tip 4: In scenario questions, think risk-based. If a scenario describes an excluded control, ask whether the exclusion is justified by the risk assessment and scope. Justified exclusions are acceptable. Exclusions made without a justification, or contradicted by the evidence, point to a nonconformity. For example, excluding 8.28 Secure coding while the auditee develops customer-facing applications cannot be justified.
Tip 5: Write nonconformities correctly. In essay-style exams (such as PECB or IRCA-style formats), a good nonconformity statement has three parts: the requirement (clause or Annex A control as stated in the SoA), the evidence (objective, specific and verifiable), and the statement of nonconformity. Grade it as major or minor with a reason. For example: "Control 8.13 is declared implemented in the SoA v3. However, no backup restore test records exist for the past 12 months for the ERP system. This is a minor nonconformity against 8.13 and Clause 8.1."
Tip 6: Distinguish 27001 from 27002. ISO/IEC 27001 contains the requirements and the Annex A control statements. ISO/IEC 27002 contains implementation guidance, purpose and attributes. Auditors audit against 27001 and may use 27002 for interpretation, but cannot raise nonconformities against 27002 guidance alone.
Tip 7: Recognize the new controls in scenarios. If a scenario mentions cloud providers, look to 5.23. Threat feeds point to 5.7. DLP tools point to 8.12. Data masking or pseudonymization points to 8.11. Secure configuration baselines point to 8.9. Data deletion on request points to 8.10. URL blocking points to 8.23. Monitoring networks for anomalies points to 8.16. CCTV and intrusion detection point to 7.4. Developer coding standards point to 8.28. ICT continuity testing points to 5.30.
Tip 8: Match the evidence to the control. Exams may ask which evidence best demonstrates a control. Examples include:
- Background check records for 6.1.
- Training attendance and awareness test results for 6.3.
- Visitor logs and badge access reports for 7.2.
- Patch reports and vulnerability scan results for 8.8.
- Change requests with approvals for 8.32.
- An asset register for 5.9.
- Supplier agreements with security clauses for 5.20.
Tip 9: Use attributes to answer "type of control" questions. If asked whether a control is preventive, detective or corrective, reason from its function. Logging and monitoring are detective. Access control and encryption are preventive. Backup restoration and incident response are corrective. Remember that some controls carry more than one attribute.
Tip 10: Read the question for the 2013 vs 2022 trap. Old references such as A.9 Access control or A.12 Operations security belong to the 2013 version. If the exam is based on the 2022 version, reason in terms of 5.x, 6.x, 7.x and 8.x. Know that control mapping between versions is provided in ISO/IEC 27002:2022 Annex B.
Tip 11: Eliminate absolute answers. Options containing "all controls must be implemented", "Annex A is optional" or "only Annex A controls may be used" are almost always wrong. The standard is risk-based and flexible.
Tip 12: Think like an auditor, not an implementer. When asked what the auditor should do, prefer answers that involve verifying objective evidence, sampling, and checking consistency between the risk assessment, risk treatment plan, SoA and actual practice. Avoid answers where the auditor recommends or designs specific controls, because that would compromise independence.
6. Quick Revision Summary
- Annex A is normative and contains 93 controls in 4 themes: Organizational 37 (5.x), People 8 (6.x), Physical 14 (7.x) and Technological 34 (8.x).
- There are 11 new controls in the 2022 version.
- Clause 6.1.3 requires a comparison with Annex A and a Statement of Applicability with justifications and implementation status.
- Annex A is not exhaustive, and organizations may add controls from other sources.
- ISO/IEC 27002 provides guidance and five attribute types: control type, security properties, cybersecurity concepts, operational capabilities and security domains.
- Auditors verify the SoA, sample controls across all themes, trace risk to evidence, and raise nonconformities for ineffective controls or unjustified exclusions.
Master the structure, the classification logic and the link to risk treatment. With these, you will be able to answer both recall and scenario-based exam questions on Annex A confidently.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!