ISO 27001 Annex A: Easy to Follow Guide

Understanding ISO 27001 Annex A

For many business owners, especially those juggling day-to-day operations, cybersecurity and compliance can feel overwhelming. The good news? ISO 27001 Annex A simplifies the process of managing your information security controls. Whether you’re safeguarding customer data, meeting GDPR compliance, or preparing for an ISO 27001 audit, Annex A provides a structured path toward protecting your business.

Whether you’re already implementing an ISMS or just dipping your toes into compliance waters, this guide explains everything you need to know in plain English — and how to actually use Annex A in your business.

What is ISO 27001 Annex A?

ISO 27001 Annex A is a curated list of information security controls included in the ISO/IEC 27001:2022 standard.

These controls are designed to help organisations implement and maintain an effective Information Security Management System (ISMS).

Think of Annex A as your security toolkit. It doesn’t just outline what you should protect—it gives you options for how to do it. These controls are especially useful when responding to identified risks during a risk assessment.

How Is Annex A Structured in ISO 27001?

Annex A is divided into 93 individual controls, grouped under four key themes:

  • Organisational controls – Covering policies, roles, and responsibilities.

  • People controls – Focusing on employee awareness, training, and human factors.

  • Physical controls – Securing physical access to facilities and hardware.

  • Technological controls – Relating to software, encryption, and digital access management.

This structure helps businesses align their ISMS with real-world security needs, ensuring coverage across people, processes, and technology.

Contents hide
1 ISO 27001 Annex A: Easy to Follow Guide
ISO 27001 Annex A Infographic

Why ISO 27001 Annex A Matters for Businesses

Still wondering why Annex A deserves your attention? It helps:

  • Meet legal obligations like GDPR

  • Avoid costly breaches and reputational damage

  • Prove to clients and stakeholders you take security seriously

  • Support smooth ISO 27001 certification audits

What are the Objectives of ISO 27001 Annex A Control?

The primary objective of ISO 27001 Annex A controls is to reduce and manage information security risks across your organisation. Each control aligns with a specific control objective, ensuring that confidentiality, integrity, and availability of data are maintained. These objectives feed directly into your broader risk treatment plan and support your ISO 27001 implementation strategy.

Each control supports one or more of the following principles:

  • Confidentiality – Keeping sensitive information out of the wrong hands

  • Integrity – Ensuring data isn’t changed or corrupted

  • Availability – Making sure authorised users can access systems and data when needed

These three objectives are the backbone of information security — and the reason ISO 27001 exists in the first place.

How Many Controls Are in Annex A?

The ISO 27001:2022 revision streamlined Annex A by reducing the total number of controls from 114 to 93. These controls are now grouped into four modern themes: Organisational, People, Physical, and Technological.

This new structure makes it easier for organisations to align controls with their information assets, enhance threat identification, and build a scalable cybersecurity framework.

Theme Number of Controls
Organisational 37
People 8
Physical 14
Technological 34

Each theme targets a different area of risk. Think of them as “security lenses” helping you see and protect your business from multiple angles.

How Annex A Aligns with an ISMS

Your Information Security Management System (ISMS) is the engine that drives your security practices — and Annex A is the dashboard providing the control indicators. Each control in Annex A is tied to an information security objective and helps maintain compliance with standards such as GDPR, especially when integrated with a well-documented Statement of Applicability (SoA) and internal audit process.

This alignment ensures that your ISMS is not just a set of policies, but a living system built on risk-based decision-making and continuous improvement.

Themes of ISO 27001 Annex A

ISO 27001 Annex A Infographic

Each control in Annex A falls into one of four themes:

  • Organisational Controls – Covering governance, risk management, and compliance.

  • People Controls – Focused on employee awareness, training, and responsibilities.

  • Physical Controls – Safeguarding physical access and infrastructure.

  • Technological Controls – Encompassing digital defences like encryption and access control.

This thematic approach makes it easier to match controls to risks — and explain them to your team.

Control Groups in Annex A Explained

Let’s break these down for clarity. ISO 27001 Annex A categorises its 93 controls into four distinct groups: Organisational, People, Physical, and Technological. Each group targets a specific area of information security, helping businesses apply the right measures in the right places.

Organisational Controls

These address the policies, procedures, roles, and responsibilities that shape your entire information security posture. Examples include:

  • Information security policies

  • Contact with authorities and special interest groups

  • Asset management and acceptable use policies

  • Secure development and change management

People Controls

This group tackles the human side of security — from pre-employment screening to training and accountability.

  • Background checks

  • Security awareness programmes

  • Disciplinary actions for policy violations

Physical Controls

These ensure that buildings, offices, and equipment are protected against theft, damage, or unauthorised access.

  • Physical entry controls

  • Equipment disposal and relocation

  • Visitor access and monitoring

Technological Controls

This is where cybersecurity tools and configurations come into play.

  • Encryption

  • Antivirus and anti-malware

  • Access control and authentication

  • Monitoring and logging

Practical Tips for Applying ISO 27001 Annex A Controls

Applying ISO 27001 Annex A effectively starts with identifying information assets and assessing the potential threats and vulnerabilities they face. Use a structured risk register to map out these risks and determine which Annex A controls are most applicable.

Once risks are documented, align them with specific control objectives and outline your risk treatment plan. Each control should either be implemented or justifiably excluded — and this decision-making must be clearly recorded in your Statement of Applicability (SoA).

For a smooth ISO 27001 implementation, make sure your choices are supported by clear documentation and backed by input from relevant stakeholders. This makes future internal audits and certification processes more efficient while also strengthening your overall cybersecurity framework.

Applying all 93 controls may feel overwhelming. But ISO 27001 doesn’t expect that. Instead:

  • Identify your risks using a risk assessment

  • Select relevant controls from Annex A

  • Justify exclusions (yes, you can skip some)

  • Document decisions in your Statement of Applicability (SoA)

How to Map Risks to Annex A Controls

Mapping Risks to ISO 27001 Annex A Controls Infographic

Mapping your risks to the appropriate Annex A controls is a key part of building a strong, audit-ready Information Security Management System (ISMS). Here’s how to do it:

  1. Identify Your Information Assets
    Start by listing all critical data, systems, hardware, and people involved in your operations.
  2. Conduct a Threat and Vulnerability Assessment
    Examine potential threats (e.g., data breaches, system failures) and vulnerabilities that could impact each asset.
  3. Create a Risk Register
    Document the identified risks, assign likelihood and impact scores, and calculate the overall risk level.
  4. Select Relevant Annex A Controls
    For each risk, choose the most appropriate control from ISO 27001 Annex A that mitigates or manages the threat.
  5. Justify Your Control Selection in the SoA
    Use the Statement of Applicability (SoA) to explain why a control is included or excluded, tying it back to your risk assessment.
  6. Strengthen Your Security Incident Response Plan
    Ensure controls are in place to detect, respond to, and recover from security incidents.
  7. Prepare for the ISO 27001 Certification Audit
    Clear mapping and documentation will make it easier to meet auditor expectations and demonstrate your compliance.

This approach ensures you’re only applying controls that genuinely matter to your business.

What’s New in ISO 27001:2022 Annex A?

The ISO 27001:2022 update brought significant changes to Annex A, modernising the structure to better address today’s cybersecurity threats. Here’s what’s new:

  • Number of controls reduced from 114 to 93

  • Four new themes introduced: Organisational, People, Physical, and Technological

  • 11 brand-new controls added, including ones related to cloud security, threat intelligence, and data masking

  • Simplified grouping of controls for easier integration with your risk treatment plan and information security policies

These updates make Annex A more relevant, more adaptable, and better aligned with modern information security frameworks.

ISO 27002 vs Annex A: What’s the Difference?

Many organisations confuse Annex A and ISO 27002, but understanding the difference is key to successful ISO 27001 implementation.

  • Annex A: This is a high-level list of 93 reference controls included in the ISO 27001 standard.

  • ISO 27002: This supporting standard offers detailed implementation guidance for each control, including examples, best practices, and advice for aligning with your organisation’s risk assessment.

Think of Annex A as what you need to consider, and ISO 27002 as how you can do it effectively.

Common Misconceptions About Annex A

There are several persistent myths about Annex A that can derail your compliance journey. Let’s clear them up:

  • “All controls are mandatory.”
    Not true. You only need to implement controls relevant to your risk context, and you must justify exclusions in your Statement of Applicability (SoA).

  • “Annex A is just for large enterprises.”
    Wrong again. Small and medium-sized businesses also benefit from Annex A by improving their data protection and showing commitment to cyber resilience.

  • “It’s just a checklist.”
    Annex A is not a tick-box exercise — it’s a flexible framework that should be tailored to your organisation’s needs and continuously reviewed.

Annex A is flexible by design. It scales beautifully whether you’re a five-person start-up or a multinational.

iso 27001 annex a controls list

How to Determine Which Annex A Controls Apply

Determining which controls from Annex A apply to your business is central to your ISO 27001 certification journey. Here’s how to get it right:

1. Understand Your Business Context

Assess internal and external issues that impact your organisation’s information security objectives.

2. Conduct a Risk Assessment

Identify threats and vulnerabilities, evaluate impact and likelihood, and map findings in a risk register.

3. Select Relevant Controls

Choose controls from Annex A that mitigate your identified risks, ensuring alignment with your risk treatment plan.

4. Complete Your Statement of Applicability (SoA)

Document the controls you’ve implemented, and explain any exclusions — this is a core requirement for certification.

5. Demonstrate Structure During Certification

Auditors will look for a systematic, risk-based approach, clear documentation, and evidence of control implementation.

The Role of Annex A in Achieving Certification

Auditors love clarity. They’re not looking for perfection, but they are looking for structure. Annex A helps you:

  • Demonstrate a methodical approach to security

  • Provide evidence for risk-based control selection

  • Align security policies with real-world threats

Creating an Annex A Control List for Your Business

Rather than copy-pasting controls from the standard, create a practical list that maps:

Risk Relevant Control Implementation Summary
Data breach via email A.8.9 Email security Enabled 2FA, staff training, encryption
Lost laptops A.7.10 Storage media disposal Enforced disk encryption and secure wipes

Examples of Real-World Annex A Controls in Action

Let’s bring it to life.

  • A.5.9: Inventory of information and other associated assets – Create a spreadsheet listing laptops, cloud services, and documents.

  • A.6.3: Segregation of duties – Separate approval and execution roles in finance.

  • A.8.16: Monitoring activities – Use Microsoft 365 audit logs to monitor file sharing.

These aren’t theoretical. They’re doable — today.

Integrating GDPR with Annex A Controls

If you handle personal data, GDPR applies. Good news: Annex A supports GDPR compliance directly:

  • Access controls prevent unauthorised access to personal data

  • Logging and monitoring help prove compliance

  • Data masking and deletion match privacy by design principles

Supporting Your ISMS with Annex A

Your Information Security Management System (ISMS) is only as strong as its foundation. Annex A supports your ISMS by:

  • Providing practical controls to enforce policies

  • Offering coverage for known risk areas

  • Aligning with the PDCA model — Plan, Do, Check, Act

Using the PDCA Cycle with Annex A Controls

PDCA (Plan-Do-Check-Act) brings Annex A to life.

  • Plan – Select controls based on your risk assessment

  • Do – Implement and train your team

  • Check – Audit control effectiveness

  • Act – Improve where needed

Repeat annually — and document it!

Top Tools and Templates for Annex A Implementation

To make your implementation smoother, use these common tools:

  • Risk Register – Identifies and scores threats

  • Statement of Applicability (SoA) – Maps controls to risks

  • Control Implementation Matrix – Who owns what, where, and how

  • Audit Logs and Checklists – Record proof of compliance

Annex A and Auditor Expectations: What You Must Know

Auditors don’t expect you to implement everything. But they do expect:

  • Documented risk assessments

  • A completed Statement of Applicability

  • Evidence that controls are active and effective

  • An understanding of why you made each decision

Maintaining Compliance with Annex A Over Time

ISO 27001 isn’t a “tick the box and move on” standard. Use these strategies to keep your controls alive:

  • Schedule regular control reviews

  • Update policies when business or risk changes

  • Conduct annual internal audits

  • Train staff on updates and new threats

Remember: A living ISMS is a secure ISMS.

Hints and Tips for Business Owners Implementing Annex A

  • Don’t over-engineer controls — practicality beats perfection

  • Prioritise risks with real-world impact (e.g. phishing, supplier breaches)

  • Involve your team early — they’re your first line of defence

  • Use external consultants if you need clarity or speed

  • Track progress with a checklist or task manager 

How Consultants Like Us Can Help

Implementing ISO 27001 Annex A can be daunting — especially if it’s your first time navigating an information security framework. That’s where we come in.

As ISO 27001 consultants for UK businesses, we help you:

  • Conduct a gap analysis to see where your current security posture stands

  • Develop your Statement of Applicability (SoA) with clear justifications

  • Map risks to controls using a tailored risk treatment plan

  • Organise documentation for ISO 27001 certification audits

  • Train your staff and stakeholders on key Annex A controls

We provide ongoing support to keep your ISMS compliant, scalable, and aligned with GDPR requirements and industry best practices.

FAQs about ISO 27001 Annex A

Is Annex A mandatory for ISO 27001 certification?
Yes, but you’re not required to implement every control — only justify those you exclude.

Can Annex A help with GDPR compliance?
Absolutely. Many controls (like access, logging, and encryption) directly support GDPR principles.

What’s the difference between ISO 27001 and ISO 27002?
27001 defines the framework. 27002 provides practical advice on how to implement each Annex A control.

How do I know which controls apply to my business?
Perform a risk assessment and use your business context to decide. Then, document your reasoning in the SoA.

What if I have limited budget or staff?
Start with high-risk areas and build over time. Annex A is flexible and scalable for SMEs.

How often should Annex A controls be reviewed?
At least annually, or when there’s a major change in your environment, risks, or regulations.

iso annex a controls list

Conclusion: Making Annex A Work for You

ISO 27001 Annex A is more than just a list of controls — it’s a flexible, powerful framework that helps your business:

  • ✔️ Build trust with clients and stakeholders

  • 📉 Reduce the risk of security breaches

  • 🔐 Strengthen your data protection strategy

  • 🧩 Support a risk-based, scalable cybersecurity framework

  • 📚 Prepare confidently for ISO 27001 certification

Whether you’re just starting your ISMS journey or looking to improve your compliance posture, Annex A gives you a practical, structured way to manage risks and demonstrate your commitment to information security.