ISO 27001 Annex A

Big guide to ISO 27001 Annex A

The logic behind Annex A controls

ISO 27001 is intended for companies of all sizes, and for all industries — since security cannot be the same in different companies, ISO 27001 allows for flexibility when companies choose their safeguards (i.e., “controls” in the terminology of ISO standards).

ISO 27001 offers a catalog of 93 controls — the process of choosing which control is applicable for a particular company starts by identifying requirements of interested parties and assessing security risks, and then based on those inputs, documenting in the Statement of Applicability which controls will be used. Learn more about this process in this article: ISO 27001 Risk Assessment, Treatment, & Management: The Complete Guide.

The list of controls from Annex A

ISO 27001 Annex A is structured in four sections that contain the 93 controls mentioned above. You’ll find the list of sections and their controls below — click the name of any control to find out more about it.

A.5 – Organizational controls — this section describes 37 controls that are mainly about information security governance:

A.6 – People controls — this section describes eight controls related to secure management of human resources:

A.7 – Physical controls — this section describes 14 controls related to protection of the physical environment that can influence the security of information:

A.8 – Technological controls — this section describes 34 controls that are mainly related to the security of IT: