ISO 27001 Annex A Controls, in Plain English
Ninety-three controls sounds like a checklist someone hands you and expects you to tick to the bottom. It isn't. Here's what Annex A really is, and why you almost certainly won't be doing all of it.
The short version
- Annex A is a menu, not a mandate. It's the reference list of information security controls at the back of the ISO 27001 standard — a catalogue you choose from based on your own risks, not a set of tasks you all have to complete.
- There are 93 controls across four themes: Organisational (37), People (8), Physical (14) and Technological (34). They add up to 93, and each theme covers a different side of keeping information safe.
- You don't implement all 93. You run a risk assessment, decide which controls actually apply, and record those decisions in a Statement of Applicability (SoA) — the document that justifies what's in and what's out.
- The 2022 version reorganised things. The older 2013 standard had 114 controls in 14 domains; the current version regrouped them into 93 across 4 themes and added 11 genuinely new controls.
- Some of it overlaps with work you may already do. Several of the technical controls line up neatly with Cyber Essentials, so the groundwork isn't wasted.
If you’ve started looking into ISO 27001, you’ve almost certainly bumped into the phrase “Annex A” and a slightly intimidating number attached to it: 93 controls. It reads like a checklist someone is about to hand you and then expect you to tick, line by line, to the very bottom. That’s the wrong picture, and it puts a lot of business owners off before they’ve properly begun.
A better way to think about Annex A is as a menu rather than a mandate. Below, I’ll walk through what it actually is, how those 93 controls are organised, and the part most people miss on the first read: you choose from the list based on your own risks. You don’t have to do all of it.
What Annex A actually is (and what it isn’t)
Annex A is the reference list of information security controls that sits at the back of the ISO 27001 standard: a catalogue you select from, not a set of jobs you all have to finish.
The heart of ISO 27001 isn’t the control list at all. It’s the requirement to build and run an Information Security Management System, usually shortened to an ISMS. In plain terms, that’s a documented, living way of working out what information you hold, what could go wrong with it, and what you’re doing to keep it safe. Annex A comes in at the “what you’re doing to keep it safe” stage. It’s the standard’s suggested toolbox of safeguards, from staff training to backups to controlling who can get into the server cupboard.
So it helps to be clear about what Annex A is not. It isn’t the certificate itself. It isn’t a legal requirement to implement every item. And it isn’t a to-do list you work through in order. It’s a well-organised catalogue that exists so you don’t have to invent your security measures from a blank page, and so an auditor can check your choices against a common reference.
The one idea worth holding on to
Annex A is risk-driven. The standard expects you to look at your own business, work out what's actually at risk, and then reach into the list for the controls that address those risks. A safeguard that has nothing to do with your situation doesn't belong on your list.
The four themes, and how the 93 controls split across them
The 93 controls are grouped into four plain-language themes, and knowing the shape of each one makes the whole list far less daunting.
Here’s how the 93 controls break down:
- Organisational (37 controls). The biggest group. This covers the policies, roles and arrangements that set the tone for everything else: things like your security policies, who’s responsible for what, how you handle suppliers, and your approach to cloud services.
- People (8 controls). The human side. This is about the people in your business and around it: checks before someone joins, security awareness and training, clear responsibilities, and what happens when someone leaves.
- Physical (14 controls). The tangible side. Locks, entry controls, secure areas, protecting equipment, and keeping the physical spaces where information lives safe from prying eyes or a stolen laptop.
- Technological (34 controls). The technical side, and the second-largest group. This is where you’ll find familiar territory: access management, multi-factor authentication, encryption, backups, logging and monitoring, and secure configuration.
Add those up and you get the full 93. Four themes, one number, and none of them a mystery once you see what they’re really about. Most small businesses find the People and Physical groups quick to reason about, while the Organisational and Technological groups carry the bulk of the detail.
You don’t do all 93 — the Statement of Applicability decides
This is the point that changes how the whole thing feels: you’re expected to select the controls that fit your risks, and to write down why, in a document called the Statement of Applicability.
The mechanism works in a sensible order. First you carry out a risk assessment, which is simply a structured look at what could harm the information you hold and how likely and serious that harm would be. Then you decide how you’ll treat each of those risks, and you reach into Annex A for the controls that do the job. Finally, you compare your chosen controls against the full list to make sure you haven’t missed anything obvious.
That comparison lives in the Statement of Applicability, or SoA. It lists the Annex A controls, marks each one as applicable or not, and gives a short justification for every decision, including the ones you’ve decided to leave out. If your business has no physical premises to speak of because everyone works from home on company laptops, some of the physical controls may simply not apply, and you say so plainly. Auditors are entirely comfortable with a control marked “not applicable” as long as your reasoning is honest and clear.
What the SoA is, in a sentence
The Statement of Applicability is the document that answers "which controls did you pick, and why did you leave the others out?" It turns Annex A from a scary list of 93 into a considered, defensible set of choices that fit your actual business.
The practical upshot is reassuring. Two businesses of similar size can produce very different, equally valid control sets, because their risks differ. Nobody is scoring you on how many of the 93 you managed to implement. They’re checking that the ones you selected genuinely address the risks you found.
What changed in the 2022 version
If you’ve read older guidance and seen the number 114, that’s the previous version — the current standard reorganised and modernised the list.
The 2013 version of the standard listed 114 controls spread across 14 domains. The 2022 revision regrouped them into the 93 controls and four themes described above. A large share of the old controls were merged together where they overlapped, and most of the rest were reworded to reflect how organisations actually operate now, with far more of the working day happening in the cloud and on the move.
Eleven of the controls are genuinely new. They fill gaps that had opened up since 2013, and the list of names alone tells you where the world moved: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. If you already work to the older version, none of this should feel like starting again. It’s a tidy-up and a modernisation rather than a reinvention, and much of your existing effort maps straight across.
Examples of controls a typical small business will pick
The list stops feeling abstract the moment you see the sort of everyday controls a normal SME actually lands on.
You won’t recognise every one of the 93, but you’ll recognise a good many. For a typical small or medium business, a selected control set often includes measures like these:
- Requiring multi-factor authentication and sensible access controls, so the right people can reach the right systems and nobody else can.
- Keeping reliable, tested backups, so a ransomware attack or a failed hard drive is an inconvenience rather than a catastrophe.
- Running security awareness training, so the people opening the emails know what a dodgy one looks like.
- Managing joiners and leavers properly, so access is granted deliberately and removed promptly when someone moves on.
- Handling suppliers and cloud services with care, so the tools you rely on aren’t a quiet back door into your data.
- Keeping software patched and devices configured securely, so known weaknesses get closed before someone uses them.
None of that is exotic. Much of it is good practice you may already be part-way to doing. The value of Annex A is that it gives these habits a shared name and a place in a system, so the work is visible, repeatable and provable to a client who asks. If you’d like a fuller sense of whether the standard is the right move at all, our guide to ISO 27001 for SMEs is a good companion read, and what ISO 27001 actually costs covers the money side honestly.
Where Annex A overlaps with work you may already have done
Several of the technological controls line up closely with Cyber Essentials, which means the groundwork isn’t wasted if you’ve already been down that road.
A number of Annex A’s technical controls sit in the same territory as the five controls at the core of Cyber Essentials: firewalls and secure configuration, controlling user access, protecting against malware, and keeping software up to date. If you’ve worked through a Cyber Essentials checklist and hold the certificate, you’ve already built and evidenced practices that map directly onto part of Annex A. That’s real, transferable progress rather than a separate pile of work.
The two aren’t the same thing, and it’s worth understanding the difference so you pitch your effort at the right level. Cyber Essentials is a focused technical baseline; ISO 27001 wraps a full management system around information risk across the whole organisation. Our comparison of Cyber Essentials and ISO 27001 unpacks where each one fits. The encouraging headline is that they build on each other. Sensible security done once tends to keep paying off, and Annex A is designed to recognise the good work you’ve already put in rather than make you repeat it.
SecurSentry is launching soon to help UK SMEs map controls like these to what they already have in place, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.
This article is for general information only and does not constitute legal or compliance advice. Which controls apply varies by organisation; where in doubt, consult a qualified professional or an accredited certification body.