From books

The 2022 Annex A holds 93 controls in four themes and is a cross-check list, not a project plan you must tick off in full.

The information security controls listed in Annex A are not exhaustive and additional information security controls can be included if needed.ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, clauza 6.1.3 c), NOTA 3

Annex A is a checklist, not a shopping list.

The 2022 edition restructured the annex: from 114 controls in 14 clauses there are now 93, grouped in four themes — organizational (37), people (8), physical (14) and technological (34). Eleven are entirely new: threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28). The implementation guidance lives in ISO/IEC 27002:2022, which gives every control five attributes for filtering: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. The attributes are a sorting tool, not extra requirements. And 27002 is guidance: nobody gets certified against it.

Why it mattersProjects that start by implementing all 93 controls spend heavily on risks they do not have and still fail at the Statement of Applicability.

Organizational —37People — 8Physical — 14Technological —34
The 93 Annex A controls of the 2022 edition, across four themes.

Back to the feed