Back to Blog
Compliance5 min read

ISO 27001 Annex A Controls: A Practical Breakdown

The 2022 revision restructured 114 controls into 93 across four themes. Here's what changed, what's new, and what matters most for implementation.

ISO 27001:2022 replaced the 2013 version and reorganized its entire control set. If you're working from old training materials or a consultant's template built on the 2013 standard, you're starting from the wrong place. Here's what actually changed and what it means for your implementation.

The Restructure: From 14 Domains to 4 Themes

The 2013 standard had 114 controls organized across 14 domains (A.5 through A.18). The 2022 version has 93 controls in 4 themes:

ThemeControlsCount
A.5 — Organizational controlsPolicies, roles, supplier security, incident management, BCP37
A.6 — People controlsScreening, employment terms, awareness, remote working8
A.7 — Physical controlsPerimeters, access, monitoring, clear desk14
A.8 — Technological controlsEndpoint, identity, encryption, network, SIEM, SDLC34

The total went from 114 to 93, but this isn't because 21 controls were removed. Controls were merged, split, and renamed. Some that existed implicitly in 2013 were made explicit in 2022.

11 New Controls in 2022

These controls didn't exist in the 2013 standard at all:

A.5.7 — Threat intelligence: Collect and analyze information about threats relevant to your organization. This formalizes what mature security teams were already doing — subscribing to feeds, participating in ISACs, tracking CVEs relevant to your tech stack. Now it's required.

A.5.23 — Information security for use of cloud services: Establish and communicate specific security requirements for acquiring, using, managing, and exiting cloud services. In 2013, cloud was an afterthought. Now it has its own control. This includes vetting providers, contractual security requirements, and knowing what happens to your data when you leave.

A.5.30 — ICT readiness for business continuity: ICT (information and communications technology) continuity planning, beyond just having a BCP document. You need to plan for how your information systems come back, not just your operations generally.

A.7.4 — Physical security monitoring: Monitoring of premises for unauthorized physical access. Cameras, access logs, visitor records.

A.8.9 — Configuration management: Configurations of hardware, software, services, and networks must be documented, implemented, monitored, and reviewed. This includes security hardening baselines.

A.8.10 — Information deletion: Verify that data is deleted when no longer required. Not just a policy — evidence of actual deletion.

A.8.11 — Data masking: Use masking, pseudonymization, or anonymization based on access policy. Relevant to development and testing environments where production data historically ended up.

A.8.12 — Data leakage prevention: Technical measures to prevent unauthorized exfiltration. DLP tools, network monitoring, endpoint controls. This is now explicit.

A.8.16 — Monitoring activities: Detect anomalous behavior and potential security incidents across networks, systems, and applications. Formalizes the expectation that you're not just collecting logs — you're reviewing them.

A.8.23 — Web filtering: Manage which external websites users can access to reduce exposure to malicious content.

A.8.28 — Secure coding: Apply secure engineering principles to software development. This was implied in A.14 (System Acquisition, Development, and Maintenance) in 2013 — now it's explicit.

What the Statement of Applicability Requires

For every one of the 93 controls, your Statement of Applicability (SoA) must document:

  1. Whether the control is included or excluded
  2. Justification for the decision
  3. Implementation status (if included)

"This doesn't apply to us" is a valid position — but you have to document why. A cloud-only company might legitimately exclude A.7.1 (Physical security perimeters), but you need to state that and explain your reasoning. Auditors will look at your exclusions as carefully as your inclusions.

Common mistake: marking controls as "not applicable" because they're hard to implement, rather than because they genuinely don't apply. Auditors push back on this.

What Matters Most for Small Teams

If you're building an ISO 27001 ISMS with limited resources, the controls that require the most work and generate the most audit questions cluster around:

Access management (A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, A.8.3): Identity lifecycle — provisioning, de-provisioning, privileged access, MFA. You need evidence that access is granted based on job function, reviewed periodically, and removed when someone leaves. This is the area where small organizations typically have the most undocumented exceptions.

Risk management (A.5.9, A.8.8): Asset inventory and vulnerability management. You can't assess risk against assets you haven't identified. The risk register and risk treatment plan need to connect to real assets, not abstract categories.

Supplier security (A.5.19–A.5.22): Vendor risk management. Every vendor who touches your information assets needs to be evaluated. For small organizations, this is often 5-15 vendors — manageable if you start early.

Configuration and change management (A.5.37, A.8.9): Documented processes for making changes to systems and managing their configurations. Change management is frequently under-documented at small organizations because "we just make changes when needed."

Incident management (A.5.24–A.5.28): Not just having an incident response plan, but evidence of testing and lessons learned from real incidents.

The 2022 Transition Deadline

If you're an existing ISO 27001:2013 certificate holder, the transition deadline to the 2022 standard was October 31, 2025. If you're working toward initial certification, you're certifying to ISO 27001:2022 — the 2013 version is no longer available for new certifications.


SOURCES

  • ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements: iso.org/standard/27001
  • ISO/IEC 27002:2022 — Information security controls (implementation guidance): iso.org/standard/75652.html
  • ISMS.online, "ISO 27001:2022 Annex A Controls Explained": isms.online
  • BSI Group, ISO 27001:2022 transition guidance: bsigroup.com

Working toward ISO 27001 certification? Schedule a consultation to talk through your current control set and what's actually required.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch