All insights
ISO 27001 May 27, 2026 6 min read

ISO 27001 Annex A Controls: The 2022 Themes Explained

The 2022 revision of ISO/IEC 27001 made its most visible change in Annex A. The control set was restructured from 114 controls in fourteen categories into 93 controls grouped under four themes. If you certified under the 2013 version, the controls have not vanished; they have been reorganised, consolidated and modernised.

This article walks through the four themes, explains what changed, and shows how to apply the controls within your ISMS without treating Annex A as a compliance checklist. For how Annex A fits into the wider management system, see our guide to ISO 27001 certification.

Why Annex A was restructured

The 2013 version organised controls into fourteen domains such as access control, cryptography and supplier relationships. That structure had grown unwieldy and contained overlap. The 2022 revision, aligned with ISO/IEC 27002:2022, regrouped everything by the nature of the control into four themes and attached a set of attributes (such as control type, security property and cybersecurity concept) to help organisations filter and report. The result is fewer controls, clearer grouping, and eleven new controls addressing threats the 2013 set never mentioned.

Crucially, the reduction from 114 to 93 did not weaken protection. Most of the decrease came from merging related controls. Annex A remains a reference catalogue: you select from it based on risk, you do not implement all of it by default.

Theme 1: Organisational controls (A.5, 37 controls)

This is the largest theme and the governance backbone of your security programme. It covers policies, roles and responsibilities, segregation of duties, supplier and cloud relationships, incident management, business continuity, and legal and compliance obligations. These controls set the rules within which the other three themes operate.

Two of the new 2022 controls live here and matter to almost every Australian organisation:

  • Threat intelligence requires you to collect and analyse information about threats so your defences are informed by what attackers are actually doing.
  • Information security for use of cloud services recognises that cloud is now the default, requiring defined processes for acquiring, using, managing and exiting cloud services.

ICT readiness for business continuity also sits here, formalising the requirement that your technology can recover to meet business continuity objectives.

Theme 2: People controls (A.6, 8 controls)

People controls address the human element across the employment lifecycle. They cover screening before employment, terms and conditions, security awareness and training, disciplinary processes, responsibilities after termination or change of role, confidentiality agreements, and remote working.

This theme is small but high-impact, because most incidents involve people in some way, whether through error, compromised credentials or insider action. Remote working is now an explicit control, reflecting a shift that accelerated sharply and is unlikely to reverse. Auditors will check that awareness training is current and that joiner, mover and leaver processes actually run.

Theme 3: Physical controls (A.7, 14 controls)

Physical controls protect the tangible: secure areas, entry controls, protection against environmental threats, equipment security, secure disposal, clear desk and clear screen, and the security of equipment off premises. Organisations running on cloud sometimes assume physical controls no longer apply, but they still cover offices, on-premises equipment, and staff devices.

The new control here is physical security monitoring, which requires premises to be monitored for unauthorised access using measures such as alarms and surveillance. For organisations with data centres, depots or sensitive offices, this is directly relevant; for cloud-first businesses, the justification in your Statement of Applicability should reflect what physical assets you actually hold.

Theme 4: Technological controls (A.8, 34 controls)

This theme is the technical core and the second largest. It covers endpoint protection, privileged access, identity and authentication, cryptography, secure configuration, logging and monitoring, network security, secure development, and change and capacity management. Most of the day-to-day work of a security team maps here.

Several of the eleven new controls are technological, and they reflect a clear shift toward detection and data protection:

  • Configuration management formalises secure baselines for hardware, software and services.
  • Information deletion ensures data is removed when no longer required, supporting privacy obligations.
  • Data masking limits exposure of sensitive data, particularly personal information.
  • Data leakage prevention applies measures to detect and stop unauthorised data exfiltration.
  • Monitoring activities requires networks, systems and applications to be monitored for anomalous behaviour.
  • Web filtering manages access to external websites to reduce exposure to malicious content.
  • Secure coding embeds security principles into software development.

The pattern across these new controls is unmistakable: organisations are now expected to detect and respond, not just prevent, and to take data protection and privacy seriously at a control level.

The attributes: a hidden upgrade in the 2022 set

One of the most useful but least discussed changes in 2022 is the introduction of control attributes. Each control in ISO/IEC 27002:2022 carries five attributes that act as tags you can filter and sort by. They are control type (preventive, detective or corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (aligned to identify, protect, detect, respond, recover), operational capabilities, and security domains.

These attributes are not mandatory, but they are genuinely practical. You can use them to view your control set through a different lens, for example pulling every detective control to check your monitoring posture, or every control tagged to respond and recover to assess incident readiness. For organisations that also report against other frameworks, the attributes make it easier to map and reuse evidence rather than maintaining parallel control sets. They turn Annex A from a flat list into something you can interrogate.

How to apply Annex A without turning it into a checklist

The biggest mistake is treating Annex A as a list to implement top to bottom. The standard does not work that way. Your risk assessment identifies the risks; you select the controls that treat those risks; and your Statement of Applicability records the inclusion or exclusion of every one of the 93 with a justification. You can also include controls beyond Annex A if your risks warrant them.

Use ISO/IEC 27002:2022 as your implementation companion. Annex A gives you the control title and objective; ISO 27002 explains how to implement it and why it exists. Together they let you apply controls that are proportionate to your actual risk rather than a generic maximum.

What the 2022 changes mean if you certified under 2013

If you hold a certificate against the 2013 version, transition to the 2022 standard is required, and the practical work centres on Annex A. You do not start from scratch. Your existing controls largely map across, but you need to re-cut your Statement of Applicability against the new 93-control structure, address the eleven new controls, and confirm the merged controls are fully covered. The new controls are where most organisations have genuine gaps, particularly cloud services, threat intelligence, data leakage prevention, monitoring activities and secure coding, because the 2013 set never required them explicitly.

Treat the transition as an opportunity rather than a paperwork exercise. The new controls reflect where attackers and regulators have moved, so closing those gaps improves your actual security posture, not just your certificate. Work through each new control, decide applicability, and where it applies, plan implementation through your normal risk treatment process.

Mapping controls to your environment

A practical approach is to take each theme in turn, assign an owner, and assess current state honestly against the relevant controls. Where a control is partly in place, note the gap. Where it does not apply, write down the reason now, because that reasoning becomes your Statement of Applicability justification later. This theme-by-theme pass also surfaces overlaps with other frameworks you may already run, such as the Essential Eight, letting you reuse evidence.

Selecting and justifying Annex A controls well is where ISO 27001 programmes succeed or stall. CISO Advisory helps organisations across the private sector and government and council sector map their risks to the right controls and build a defensible ISMS, with ongoing ownership available through our Virtual CISO service. To discuss your control set, call 07 2112 8502 or get in touch.

Frequently asked questions

How many controls are in ISO 27001:2022 Annex A?

ISO/IEC 27001:2022 Annex A contains 93 controls, down from 114 in the 2013 version. The reduction came from merging overlapping controls rather than removing protections, and eleven entirely new controls were introduced to address modern threats such as cloud services and threat intelligence.

What are the four themes in ISO 27001:2022?

The four themes are Organisational controls (37), People controls (8), Physical controls (14) and Technological controls (34). This replaces the fourteen control categories used in the 2013 version, giving a simpler structure organised by the nature of each control rather than by domain.

What are the new controls in ISO 27001:2022?

The eleven new controls cover threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. They reflect cloud, privacy and detection priorities that the 2013 version did not address explicitly.

Do I have to implement all 93 Annex A controls?

No. Annex A is a reference catalogue. Your risk assessment determines which controls are necessary, and the Statement of Applicability records the justification for including or excluding each one. You may also add controls not listed in Annex A if your risk assessment identifies a need.

What is the difference between ISO 27001 Annex A and ISO 27002?

Annex A lists the control titles and objectives in a concise reference form. ISO/IEC 27002:2022 is the companion guidance standard that explains each control in depth, with implementation advice and purpose. Organisations use Annex A for selection and ISO 27002 for how to actually implement each control.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act