The Annex A controls, by theme
The withdrawn ISO/IEC 27001:2013 had 114 in 14 clauses. The count fell because controls were merged, not because requirements were removed — 11 of the 93 did not exist at all before 2022.
Two things are worth settling before the list. The edition year belongs with every control count, because both numbers are still in circulation. And Annex A is not what you are certified against — clauses 4 to 10 are. Annex A is the reference set you check your risk treatment against.
The same diagram as a table
| Theme | Reference | Controls | Covers |
|---|---|---|---|
| Organisational | A.5 | 37 | Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed. |
| People | A.6 | 8 | Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working. |
| Physical | A.7 | 14 | Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring. |
| Technological | A.8 | 34 | Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about. |
| ISO/IEC 27001:2022 total | 93 | Four themes | |
| ISO/IEC 27001:2013 total | 114 | 14 clauses, A.5 to A.18. Withdrawn. | |
The four themes
| Theme | Reference | Controls | What sits in it |
|---|---|---|---|
| Organisational | A.5 | 37 | Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed. |
| People | A.6 | 8 | Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working. |
| Physical | A.7 | 14 | Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring. |
| Technological | A.8 | 34 | Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about. |
The arrangement is the headline change from 2013, where the controls sat in 14 clauses numbered A.5 to A.18. The four themes are easier to allocate to owners, which matters more than it sounds: most of the practical failure in an ISMS is a control that nobody thinks belongs to them.
Each control also carries attributes in ISO/IEC 27002:2022 — control type, information security properties, cybersecurity concepts, operational capabilities and security domains — which exist so you can slice the set in whatever way suits your organisation. They are a navigation aid, not a requirement, and no auditor will ask you to have used them.
The 11 genuinely new controls
These have no counterpart in the 2013 edition. If your management system was built before October 2022 and has not been revisited since, this is the list to start from.
| Reference | Control | Why it is new |
|---|---|---|
| A.5.7 | Threat intelligence | The 2013 edition had nothing about knowing what is being used against you. Expect to be asked what sources you use and what you do with what they tell you. |
| A.5.23 | Information security for use of cloud services | Cloud was treated as ordinary supplier risk in 2013. It now has its own control covering acquisition, use, management and exit. |
| A.5.30 | ICT readiness for business continuity | Business continuity for the technology, separately from business continuity in general. |
| A.7.4 | Physical security monitoring | The physical counterpart to logging. Monitoring of premises for unauthorised access. |
| A.8.9 | Configuration management | Configurations have to be established, documented, implemented, monitored and reviewed. In practice this is where infrastructure-as-code earns its keep. |
| A.8.10 | Information deletion | Deleting information when it is no longer required — which is also a data protection obligation, so the two usually get evidenced together. |
| A.8.11 | Data masking | Masking in line with access control policy. Most often relevant to non-production environments containing real data. |
| A.8.12 | Data leakage prevention | Detecting and preventing unauthorised disclosure. Rarely satisfied by buying a product. |
| A.8.16 | Monitoring activities | Networks, systems and applications monitored for anomalous behaviour, with defined responses. |
| A.8.23 | Web filtering | Managing which external sites can be reached, to reduce exposure to malicious content. |
| A.8.28 | Secure coding | Secure coding principles applied to software development. The control most often under-evidenced by teams that genuinely do it well. |
Where the count went
11 new, 24 formed by merging controls from the 2013 edition, and 58 updated. That is 93. A smaller number of controls describing more ground is a reorganisation, not a relaxation.
Annex A is not a checklist, and treating it as one is expensive
The sequence the standard actually sets out runs the other way from the one most teams assume. You assess risk (clause 6.1.2), decide how to treat it (6.1.3), and then compare the controls your treatment produced against Annex A to verify that nothing necessary was overlooked. Annex A is the cross-check, not the starting point.
Clause 6.1.3 d) then asks for a Statement of Applicability containing the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control you left out. That last part is the one organisations under-do. “Not applicable” is a conclusion; the standard asks for the reasoning that produced it.
There is a commercial consequence. Approaching the standard as 93 controls to implement produces an enormous amount of unnecessary work and an ISMS that does not reflect what your organisation actually risks. It is also how a consultancy engagement gets quoted at a size nobody needed.
What auditors sample, and what they find
The controls that produce findings are rarely the exotic ones. They are the ones where the activity is real but the evidence is not:
- Monitoring activities (A.8.16) — the alerting exists, but nobody can show what was reviewed, by whom, or what happened next.
- Configuration management (A.8.9) — configurations are managed in practice, but not documented, monitored and reviewed in a way that can be sampled. Teams running everything as code are usually closest to compliant and furthest from evidencing it.
- Secure coding (A.8.28) — review happens on every pull request, and there is no stated principle, no record of training, and nothing tying it to the control.
- Supplier controls (A.5.19 to A.5.23) — a folder of supplier certificates that nobody has checked for expiry or scope. Since certificates against the withdrawn edition expired on 31 October 2025, that folder is worth a pass.
- Physical controls in a remote-first company (A.7) — waved away rather than reasoned about. Homes and devices are premises for this purpose, and the exclusions need the same justification as everything else.
Annex A, ISO 27002, and which one to buy
Annex A gives you the control titles and a line each. ISO/IEC 27002:2022, Information security controls is a separate standard covering the same controls at length: purpose, implementation guidance and other information for each one. You are certified against ISO 27001; ISO 27002 is what your team reads when working out what a control means in your context.
Neither is free. If you are buying one to start with, buy ISO 27001, because it contains the clauses you are actually audited against. ISO 27002 becomes worth having once somebody is doing the implementation work and arguing about what “adequate” means.
Where to go next
- The certification process
- Running the ISMS in your own tools
- Who should do this work
- What it will cost
Common questions
How many controls does ISO 27001 have?
ISO/IEC 27001:2022 lists 93 controls in Annex A, arranged in four themes: organisational (37), people (8), physical (14), technological (34). The withdrawn ISO/IEC 27001:2013 had 114 in 14 clauses numbered A.5 to A.18. Always attach the edition to the number: a document that says 114 today was written before October 2022 and has not been revisited.
Did the 2022 edition remove requirements?
No. The count fell from 114 to 93 because controls were merged, not dropped. Of the 93, 11 are genuinely new, 24 were formed by merging controls from the 2013 edition, and 58 are updated versions of existing ones. The scope of what is expected went up, not down — threat intelligence, cloud services, secure coding and data leakage prevention were not there before.
Do we have to implement all of them?
No, and a Statement of Applicability that applies all 93 without reasoning is as much of a finding as one that excludes too many. Annex A is a reference set. Clause 6.1.3 requires you to compare the controls your risk treatment produced against Annex A to check you have not missed anything, then produce a Statement of Applicability giving the justification for inclusions and for exclusions. The reasoning is the deliverable, not the count.
What is the difference between ISO 27001 Annex A and ISO 27002?
Annex A of ISO/IEC 27001 gives the control titles in one page each, as a reference set to check your risk treatment against. ISO/IEC 27002:2022 is the separate, much longer standard that explains each of the same controls: purpose, guidance and other information. You are certified against ISO 27001. ISO 27002 is what your team reads when deciding what a control actually means in your organisation.
Which controls do organisations most often get wrong?
From the shape of the standard rather than any survey: the ones requiring evidence of an ongoing activity rather than a document. Monitoring activities, configuration management and secure coding are all things competent teams do daily and rarely record in a form an auditor can sample. The other recurring gap is the exclusion justification in the Statement of Applicability — writing “not applicable” where the standard asks for the reason.
Do the four themes map onto our teams?
Loosely, and it is worth not forcing it. The technological theme is the largest at 34 controls and is mostly engineering. Organisational, at 37, is the largest single block and spans legal, procurement, HR and management. People, at 8, is HR almost entirely. Physical, at 14, belongs to whoever runs your premises — and for a fully remote company is the theme most often waved away when it should be reasoned about instead.
What changed with the 2024 amendment?
ISO/IEC 27001:2022/Amd 1:2024, Climate action changes, published February 2024. Two climate-change additions to clause 4: whether climate change is a relevant issue must be determined, and interested parties may have climate-related requirements. It changed no Annex A control and added no new control. If a supplier tells you the amendment added controls, they are mistaken.
Sources cited on this page
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO/IEC 27002:2022, Information security controls
- ISO/IEC 27001:2022/Amd 1:2024, Climate action changes
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Work out which of these you already satisfy
Say what exists today and a consultancy can tell you what is genuinely missing rather than quoting for all 93 of them.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.