InfoSec

Which controls the standard defines, how many apply to you, and what the 2022 revision changed.

Which controls the standard defines, how many apply to you, and what the 2022 revision changed.

Author
Dr. Kilian Schmidt
Date
1.7.2025
Updated on
9.8.2026
Which controls the standard defines, how many apply to you, and what the 2022 revision changed.

Key Takeaways

  • ISO 27001 controls are the 93 security measures in Annex A of the standard, grouped into four themes: 37 organizational, 8 people, 14 physical, and 34 technological controls.
  • The revision published on 25 October 2022 restructured the previous 114 controls: 11 were added, 57 merged into 24, 23 renamed, 3 removed, and 35 carried over unchanged.
  • The 11 new controls cover ground that did not exist in 2013, including threat intelligence (A.5.7), cloud security (A.5.23), data masking (A.8.11), and secure coding (A.8.28).
  • No company implements all 93 controls. Which ones apply follows from your risk assessment, and the result is recorded in the Statement of Applicability.
  • The transition period to the 2022 version closed on 31 October 2025. Certificates issued against ISO 27001:2013 are no longer valid, and no audit can be conducted against the older edition.

What are ISO 27001 controls?

ISO 27001 controls are the 93 security measures listed in Annex A of the standard. Each control states a security objective and the measure that achieves it, such as managing access rights, protecting against malware, or reporting security incidents. The standard itself uses the word "controls"; some national translations use "measures", and practitioners use both interchangeably.

The distinction from the main body of the standard matters. Clauses 4 to 10 set out the mandatory requirements for the management system itself: context, leadership, planning, operation, evaluation, and improvement. Those clauses always apply in full. Annex A, by contrast, is a reference list you select from. How the two parts work together, and what auditors actually examine, is covered in our guide to ISO 27001 certification.

A persistent misconception is that Annex A is a checklist to work through. It is not. Annex A is a completeness check. You identify your risks first, derive controls from them, and then compare the result against Annex A to see what you missed. Working in the opposite order produces an ISMS that fits the standard but not the business.

The detailed implementation guidance for each control sits not in ISO 27001 but in its companion standard, ISO 27002:2022. There, every control also carries five attributes that make filtering easier: control type (preventive, detective, corrective), information security property (confidentiality, integrity, availability), cybersecurity concept following the NIST pattern from Identify to Recover, operational capability, and security domain.

How many controls does ISO 27001 have?

ISO 27001:2022 contains 93 controls across four themes. The numbering follows the theme: organizational controls run from A.5.1 to A.5.37, people controls from A.6.1 to A.6.8, physical controls from A.7.1 to A.7.14, and technological controls from A.8.1 to A.8.34.

Theme Numbers Count What it covers
Organizational controls A.5.1 to A.5.37 37 Policies, roles, suppliers, incidents, legal requirements
People controls A.6.1 to A.6.8 8 Hiring, training, remote work, departure
Physical controls A.7.1 to A.7.14 14 Entry, offices, equipment, storage media, disposal
Technological controls A.8.1 to A.8.34 34 Access, cryptography, networks, logging, development
Total A.5 to A.8 93 Annex A of ISO/IEC 27001:2022

The split says something about the nature of the standard. Only 34 of the 93 controls are technical. The majority concern organization, documentation, and people. Teams that scope ISO 27001 as a pure IT project therefore routinely underestimate the work in A.5 and A.6.

The four control categories in detail

Organizational controls (A.5.1 to A.5.37)

The 37 organizational controls govern how information security is steered: which policies exist, who is accountable, how suppliers are managed, and how the company responds to incidents. It is the largest group and usually the most time-consuming, because it requires documents that often did not exist before.

No. Control No. Control
A.5.1Policies for information securityA.5.20Information security within supplier agreements
A.5.2Information security roles and responsibilitiesA.5.21Security in the ICT supply chain
A.5.3Segregation of dutiesA.5.22Monitoring and change management of supplier services
A.5.4Management responsibilitiesA.5.23Information security for use of cloud services (new)
A.5.5Contact with authoritiesA.5.24Incident management planning and preparation
A.5.6Contact with special interest groupsA.5.25Assessment and decision on security events
A.5.7Threat intelligence (new)A.5.26Response to information security incidents
A.5.8Information security in project managementA.5.27Learning from information security incidents
A.5.9Inventory of information and other associated assetsA.5.28Collection of evidence
A.5.10Acceptable use of information and other associated assetsA.5.29Information security during disruption
A.5.11Return of assetsA.5.30ICT readiness for business continuity (new)
A.5.12Classification of informationA.5.31Legal, statutory, regulatory, and contractual requirements
A.5.13Labelling of informationA.5.32Intellectual property rights
A.5.14Information transferA.5.33Protection of records
A.5.15Access controlA.5.34Privacy and protection of personal data
A.5.16Identity managementA.5.35Independent review of information security
A.5.17Authentication informationA.5.36Compliance with policies, rules, and standards
A.5.18Access rightsA.5.37Documented operating procedures
A.5.19Information security in supplier relationships

People controls (A.6.1 to A.6.8)

The 8 people controls cover the full employment lifecycle, from screening before hire to obligations that survive departure. It is the smallest group and still produces a disproportionate share of audit findings, because the evidence is missing: training happens, but nobody documents attendance.

No. Control
A.6.1Screening
A.6.2Terms and conditions of employment
A.6.3Information security awareness, education, and training
A.6.4Disciplinary process
A.6.5Responsibilities after termination or change of employment
A.6.6Confidentiality or non-disclosure agreements
A.6.7Remote working
A.6.8Information security event reporting

Physical controls (A.7.1 to A.7.14)

The 14 physical controls protect sites, rooms, and equipment. Even a pure cloud company with no data center of its own cannot exclude them wholesale: offices, laptops, storage media, and the disposal of old hardware all fall under A.7. For outsourced data centers, the burden of evidence shifts to supplier management in A.5.19 to A.5.22.

No. Control
A.7.1Physical security perimeters
A.7.2Physical entry
A.7.3Securing offices, rooms, and facilities
A.7.4Physical security monitoring (new)
A.7.5Protecting against physical and environmental threats
A.7.6Working in secure areas
A.7.7Clear desk and clear screen
A.7.8Equipment siting and protection
A.7.9Security of assets off-premises
A.7.10Storage media
A.7.11Supporting utilities
A.7.12Cabling security
A.7.13Equipment maintenance
A.7.14Secure disposal or re-use of equipment

Technological controls (A.8.1 to A.8.34)

The 34 technological controls address the IT estate: access rights, encryption, networks, logging, backups, and secure software development. Seven of the eleven new controls from the 2022 revision sit in this group, which shows where the standard's authors saw the largest gap.

No. Control No. Control
A.8.1User endpoint devicesA.8.18Use of privileged utility programs
A.8.2Privileged access rightsA.8.19Installation of software on operational systems
A.8.3Information access restrictionA.8.20Networks security
A.8.4Access to source codeA.8.21Security of network services
A.8.5Secure authenticationA.8.22Segregation of networks
A.8.6Capacity managementA.8.23Web filtering (new)
A.8.7Protection against malwareA.8.24Use of cryptography
A.8.8Management of technical vulnerabilitiesA.8.25Secure development life cycle
A.8.9Configuration management (new)A.8.26Application security requirements
A.8.10Information deletion (new)A.8.27Secure system architecture and engineering principles
A.8.11Data masking (new)A.8.28Secure coding (new)
A.8.12Data leakage prevention (new)A.8.29Security testing in development and acceptance
A.8.13Information backupA.8.30Outsourced development
A.8.14Redundancy of information processing facilitiesA.8.31Separation of development, test, and production environments
A.8.15LoggingA.8.32Change management
A.8.16Monitoring activities (new)A.8.33Test information
A.8.17Clock synchronizationA.8.34Protection of information systems during audit testing

The 11 new controls in the 2022 revision

The 2022 revision introduced 11 controls. They close the gaps that opened between 2013 and 2022: cloud adoption, distributed work, software supply chains, and how data is handled in test environments.

No. Control What the standard requires
A.5.7Threat intelligenceCollect and analyze threat information, then feed it back into the risk assessment
A.5.23Information security for use of cloud servicesAssess cloud services before use, define responsibilities contractually, and plan for exit
A.5.30ICT readiness for business continuitySet recovery objectives for IT systems, implement them, and test them regularly
A.7.4Physical security monitoringContinuously monitor sensitive areas for unauthorized access
A.8.9Configuration managementDefine and document secure configurations, then detect drift from them
A.8.10Information deletionDelete data once its purpose ends; maps directly onto Art. 5 and Art. 17 GDPR
A.8.11Data maskingProtect sensitive data through masking, pseudonymization, or encryption
A.8.12Data leakage preventionDetect and prevent information leaving via endpoints, networks, and services
A.8.16Monitoring activitiesContinuously monitor networks, systems, and applications for anomalous behavior
A.8.23Web filteringTechnically restrict access to websites carrying malicious content
A.8.28Secure codingDefine secure coding practices and apply them across the development life cycle

The effort behind these eleven controls is distributed very unevenly. A.8.10 and A.8.11 can often be derived from existing data protection processes, since a deletion concept and pseudonymization are already needed for GDPR. A.5.7 and A.8.16, by contrast, require ongoing processes that cannot be assembled in the two weeks before an audit. To map Annex A against your own security architecture, our overview of where NIS2 and ISO 27001 overlap also gives the correspondence to the risk management measures in Article 21 of the NIS2 Directive.

What changed between the 2013 and 2022 versions

ISO/IEC 27001:2022 was published on 25 October 2022 and replaced the 2013 edition. The previous 114 controls in 14 domains became 93 controls in four themes. The count fell; the scope did not. Most of the reduction comes from mergers rather than removals.

Change Number of controls
Added11
Merged (57 old controls became 24 new ones)57 → 24
Renamed23
Split (1 old control became 2 new ones)1 → 2
Removed3
Carried over unchanged35

The title of the annex changed too, from "Reference control objectives and controls" to "Information security controls reference". That is more than cosmetic: the control objectives are gone, and the intent now sits inside each control itself.

The transition period has closed. Set by the IAF for accredited certification bodies, it ended on 31 October 2025; certificates based on ISO 27001:2013 have not been valid since that date. For a first certification, the older edition is therefore irrelevant. If a quote you receive today still references the 2013 version, that is worth questioning.

In 2024, ISO/IEC 27001:2022/Amd 1:2024 added a small amendment. It does not touch Annex A but clauses 4.2 and 6.1.2: companies must consider whether climate change is relevant to their management system. The count of 93 controls is unaffected.

Which controls apply to your company?

Which of the 93 controls are applicable follows from your risk assessment, not from a prescription in the standard. You record the result in the Statement of Applicability. That document lists all 93 controls and justifies, for each one, whether it applies and why. Auditors read it first; it is the single most scrutinized document in the entire ISMS.

Exclusions are explicitly permitted, but only with a substantive justification. "Not relevant" is not enough. "We do not develop software in house, so A.8.25 to A.8.31 do not apply" is a justification that holds, as long as it matches the actual business model.

A concrete example: a 45-person SaaS company running entirely on AWS, with no data center of its own and a single office. Almost all organizational and people controls apply, because they are independent of size. On the physical side, the work reduces to the office, endpoints, and disposal, while data center security is evidenced through supplier management. The technological controls are almost fully in scope, because the company writes its own software. In the end, very few genuine exclusions remain.

The most common misconception in a first certification is that a control is handled once a document exists. An audit does not check that a policy exists; it checks that the policy is followed. For every applicable control you need continuous evidence, not just an approval. That is where most findings originate: not on missing controls, but on controls with no evidence from the preceding months available at audit time. How the four audit phases run, and what auditors examine in each, is covered in the ISO 27001 certification guide.

What that effort translates to in numbers, meaning audit days, certification body fees, and internal time, is set out in our breakdown of ISO 27001 certification costs.

How Kertos supports control implementation

Kertos maps all 93 Annex A controls in the platform and links each one to the evidence that supports it. Instead of collecting evidence in the run-up to an audit, automated checks pull it continuously from connected systems such as identity management, device management, and the cloud environment. The Statement of Applicability is generated from the risk assessment and stays connected to it, rather than aging as a separate spreadsheet.

Alongside the platform sit certified experts who share responsibility for control selection and justification, and who accompany you through the audit. AskUI reached ISO 27001 certification in 8 to 10 weeks this way. What an ISMS requires before individual controls come into play is covered in our guide to building an ISMS.

To see what the mapping from controls to evidence looks like in your environment, book a demo.

Frequently asked questions

How many controls does ISO 27001 have?

ISO 27001:2022 contains 93 controls in Annex A, split into 37 organizational, 8 people, 14 physical, and 34 technological controls. The previous edition, ISO 27001:2013, contained 114 controls across 14 domains.

Do I have to implement all 93 controls?

No. Which controls apply follows from your risk assessment. You do have to assess all 93 individually in the Statement of Applicability and give a substantive justification for every exclusion. An unjustified exclusion becomes a finding at audit.

What is the difference between ISO 27001 controls and the clauses of the standard?

Clauses 4 to 10 set out the mandatory management system requirements and always apply in full. Annex A is a reference list of 93 controls that you select from on a risk basis. Certification covers both, but only the main body is binding without exception.

Which controls are new in ISO 27001:2022?

Eleven controls were added in 2022: threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).

Is there a downloadable list of the ISO 27001 controls?

The complete list is in the tables above, sorted by the four themes. The binding wording and the implementation guidance sit in the standards themselves: the requirements in ISO/IEC 27001:2022, and the detailed guidance per control in ISO/IEC 27002:2022. Both are available from ISO for a fee.

Is an ISO 27001:2013 certificate still valid?

No. The transition period ended on 31 October 2025. Certificates based on ISO 27001:2013 have not been valid since that date, and audits are conducted exclusively against the 2022 edition.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder at Kertos

Kilian had a strong focus on legal processes from an early age and began his career at Home24 as a Senior Legal Counsel and Data Protection Officer for the Home24 group. After a stint at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where he expanded the company's legal and public policy departments from one to 65 cities and from 50 to 800 employees. Driven by the lack of technology in the legal field and confirmed by his consulting work at Gorillas Technologies, he decided to found Kertos to develop the next generation of compliance – made in Europe.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check