ISO 27001 Annex A Controls: A Practical Guide to the 93 Controls | Lorikeet Security Skip to main content
Back to Blog

ISO 27001 Annex A Controls: A Practical Guide to the 93 Controls

Lorikeet Security Team February 28, 2026 13 min read

Annex A is the control catalogue of ISO 27001. It lists the security controls your organization can implement to address the risks identified in your risk assessment. The 2022 revision restructured the controls from 14 domains into four themes, consolidated overlapping controls, and added 11 new controls reflecting modern security challenges.

Understanding which controls matter most for your organization, and how to implement them practically rather than just on paper, is the difference between an ISMS that passes audit and one that actually improves security.


The Four Control Themes

Theme Controls Focus Areas
Organizational 37 controls (A.5) Policies, roles, asset management, access control, supplier management, incident management, compliance, business continuity
People 8 controls (A.6) Screening, employment terms, awareness training, disciplinary process, termination responsibilities, confidentiality, remote working
Physical 14 controls (A.7) Physical perimeters, entry controls, office security, environmental threats, equipment security, clear desk, secure disposal
Technological 34 controls (A.8) Endpoint devices, access rights, authentication, cryptography, vulnerability management, logging, network security, secure development, data protection

New Controls in the 2022 Revision

The 2022 revision added 11 entirely new controls that reflect the evolution of the threat landscape and modern IT environments:


Controls That Matter Most

While all applicable controls must be implemented, auditors and real-world security outcomes consistently show that some controls carry more weight than others.

High-impact organizational controls

High-impact technological controls

Practical tip: Map your Annex A controls to your existing SOC 2 controls if you already have SOC 2 compliance. Approximately 70% of ISO 27001 controls have direct SOC 2 equivalents, which significantly reduces implementation effort for dual certification.


The Statement of Applicability

The Statement of Applicability (SoA) is the document that connects your risk assessment to your control implementation. For each of the 93 Annex A controls, the SoA must state whether the control is applicable, the justification for its inclusion or exclusion, and whether it is currently implemented.

The SoA is one of the most scrutinized documents during certification audits. Auditors look for controls excluded without adequate justification, controls marked as implemented but lacking evidence, and gaps between your risk treatment plan and your SoA. Take the time to write clear, specific justifications rather than boilerplate text.

Need security testing or compliance support?

We provide penetration testing, compliance assessments, and security consulting for organizations at every stage.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

We've completed 170+ security engagements across web apps, APIs, cloud infrastructure, and AI-generated codebases. Everything we publish here comes from patterns we see in real client work.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!