# ISO/IEC 27001:2022 Controls Explained | Complete Guide
Author: Pacific Certifications
Author URL: https://blog.pacificcert.com/author/pacific-certifications/
Published: 2026-09-29
Category: System Certification
Category URL: https://blog.pacificcert.com/category/system-certification/
Meta Title: ISO/IEC 27001:2022 Controls & Annex A Explained
Meta Description: Understand ISO/IEC 27001:2022 controls, the 4 new themes, Statement of Applicability, and audit tips in this complete Annex A guide for certification.
Tags: ISO 27001 Information Security, ISO 27001 certification, ISO/IEC 27001:2022
Tag URLs: ISO 27001 Information Security (https://blog.pacificcert.com/tag/iso-27001-information-security/), ISO 27001 certification (https://blog.pacificcert.com/tag/iso-27001-certification/), ISO/IEC 27001:2022 (https://blog.pacificcert.com/tag/isoiec-270012022/)
URL: https://blog.pacificcert.com/iso-iec-27001-2022-controls-explained/

![ISO 27001:2022 Controls Explained | Complete Guide](https://prod.superblogcdn.com/site_cuid_cljse4miw184303tp9kqsuho9k/images/isoiec-270012022-controls-explained-1790675271300-compressed.jpg)

## **Introduction**

The 2022 revision of the standard brought the most significant update to Annex A in a decade, consolidating and modernizing the control set to reflect how organizations actually manage information security today including cloud services, remote working and emerging threats that barely existed when the 2013 edition was published.

> **Tip:** Build your ISMS around ISO 27001 Clauses 4–10, using Annex A controls based on identified risks and treatment decisions.

* * *

## **Structure of Annex A**

The 2022 edition restructured this significantly, consolidating the controls down to 93 and reorganizing them into just four overarching themes.

**The four themes at a glance**

- **A.5 Organizational controls** \- 37 controls

- **A.6 People controls** \- 8 controls

- **A.7 Physical controls** \- 14 controls

- **A.8 Technological controls** \- 34 controls


Explore the 93 ISO 27001 Annex A Controls

* * *

## **What changed from the 2013 edition?**

A number of overlapping or outdated controls from the 2013 edition were merged, and 11 entirely new controls were introduced to address areas such as threat intelligence, cloud security, data masking, and secure coding reflecting how information security risk has evolved since 2013.

### **Control** attributes

Each control in the 2022 edition is also tagged with attributes covering control type, security properties, cybersecurity concepts, operational capabilities and security domains.

These attributes give organizations a more flexible way to filter, group and report on controls beyond the four fixed themes, for example by generating a view of all "preventive" controls or all controls relevant to "governance."

### **Organizational** controls

Organizational controls, listed under A.5, form the largest theme in Annex A with 37 controls. These address the policies, governance structures, roles, processes and third-party relationships that underpin an organization's approach to information security.

Rather than covering technical safeguards, this theme focuses on how security is directed, managed and embedded across the organization.

### **Governance,** roles **and policy**

Representative areas covered here include information security policies, roles and responsibilities, segregation of duties, contact with authorities and special interest groups, and independent review of information security.

These controls establish who is accountable for security decisions and how those decisions are documented and reviewed.

### **Asset, project** and **supplier management**

This theme also covers inventory of information and other associated assets, acceptable use, information security in project management, and supplier relationships and information security in supply chains.

These controls extend security accountability beyond the organization's own boundaries to the vendors, contractors and partners it works with.

### **Incident,** continuity **and compliance**

Further controls address incident management, business continuity, and legal and contractual requirements, ensuring the organization can respond to disruptions and remain compliant with applicable obligations.

* * *

## **New organizational controls introduced in 2022**

Several of the controls newly introduced in the 2022 edition sit within this theme, including threat intelligence (A.5.7), information security for use of cloud services (A.5.23), and ICT readiness for business continuity (A.5.30).

These additions reflect the growing reliance on external cloud providers and the need for organizations to actively monitor the threat landscape rather than relying solely on reactive incident response.

Strengthen Your Organizational Security Controls

* * *

## **People, physical and technological controls**

### **People controls (A.6)**

People controls cover the eight controls related to how an organization manages its workforce from a security perspective: screening, terms and conditions of employment, information security awareness, education and training, disciplinary processes, responsibilities after termination or change of employment, confidentiality or non-disclosure agreements, remote working, and information security event reporting.

This is the smallest theme by control count, but it addresses risks that technology alone cannot mitigate, since human error and insider behavior remain leading causes of security incidents.

### **Physical controls (A.7)**

Physical controls comprise 14 controls addressing the security of physical locations and equipment, including physical security perimeters, physical entry controls, securing offices and facilities, protection against environmental threats, working in secure areas, clear desk and clear screen practices, equipment siting and protection, secure disposal or reuse of equipment, and security of assets off-premises.

These controls remain essential even as organizations shift toward remote and hybrid work, since physical access to devices, facilities and data centers continues to represent a significant attack surface.

### **Technological controls (A.8)**

Technological controls form the second-largest theme, with 34 controls covering the technical safeguards applied to systems, networks and data.

This includes user endpoint devices, privileged access rights, information access restriction, use of cryptography, secure system architecture and engineering principles, protection against malware, technical vulnerability management, network security, application security, secure coding, and data leakage prevention.

> **Takeaway:** Organizational controls establish security direction, while people, physical and technological controls translate it into practical safeguards across operations.

* * *

## **New technological controls introduced in 2022**

New controls introduced in this theme in the 2022 edition include data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28), reflecting the growing importance of data protection and application-layer security.

* * *

## **Statement of Applicability**

The Statement of Applicability (SoA) is a mandatory document required under Clause 6.1.3(d) of ISO 27001 and is one of the most important deliverables in the certification process.

It records which of the 93 Annex A controls an organization has determined are necessary based on its risk assessment and risk treatment plan, and, just as importantly, provides justification for including or excluding each control.

Strengthen Your ISO 27001 Statement of Applicability

* * *

## **What the Statement of Applicability must include?**

### **Building the Statement of Applicability**

1. **Completing** a risk assessment that identifies information security risks relevant to the organization.

2. **Selecting** controls from Annex A (or supplementary controls, where needed) to address identified risks through the risk treatment process.

3. **Documenting** a justification for the inclusion of each selected control.

4. **Documenting** a justification for the exclusion of any Annex A control not selected, since Annex A is a reference set and not every control will apply to every organization.

5. **Confirming** whether each included control has actually been implemented, since selection and implementation are reviewed separately during certification audits.

6. **Reviewing** and updating the Statement of Applicability whenever risks, the organization's context or its risk treatment plan change.


* * *

## **How auditors use the Statement of Applicability?**

Auditors use the Statement of Applicability as a central reference point during certification audits, cross-checking it against the risk assessment, risk treatment plan and evidence of actual implementation.

A Statement of Applicability that lists controls as implemented without corresponding evidence or that excludes relevant controls without adequate justification is one of the most common sources of audit findings.

* * *

## **Common implementation mistakes**

A frequent mistake is treating Annex A as a checklist to work through control by control, rather than starting from the risk assessment and selecting controls based on identified risks.

Another common mistake is excluding controls from the Statement of Applicability without adequate justification, or including controls that are not actually implemented in practice.

Organizations transitioning from the 2013 edition sometimes also assume the mapping between old and new controls is one-to-one, when in fact several 2013 controls were merged or restructured, requiring a genuine review rather than a simple renumbering exercise.

Assess Your ISO 27001 Audit Readiness

* * *

## **How Pacific Certifications can help?**

Pacific Certifications can provide:

- Review of proposed ISO/IEC 27001:2022 certification scopes

- Independent ISO/IEC 27001:2022 certification audits where applicable

- Stage 1 documentation and certification-readiness audits, including review of the Statement of Applicability

- Stage 2 implementation and effectiveness audits

- Annual surveillance audits and triennial recertification audits


Pacific Certifications conducts impartial certification audits and does not design, implement or manage information security management systems for its certification clients.

* * *

## **Contact Us**

To request an ISO/IEC 27001:2022 certification priorities contact [**support@pacificcert.com**](mailto:support@pacificcert.com) or visit [**www.pacificcert.com**](https://pacificcert.com/).

Apply for ISO/IEC 27001:2022 Certification

Strengthen information security and risk management by implementing appropriate organizational, people, physical and technological controls within your ISO/IEC 27001 ISMS.

[Apply for ISO/IEC 27001 Certification](https://pacificcert.com/contact-us/)

**Also read:** [ISO/IEC 27002 best practices for implementing ISO 27001 controls](https://blog.pacificcert.com/iso-iec-27002-best-practices-for-implementing-iso-iec-27001/)

![Pacific Certifications](https://prod.superblogcdn.com/site_cuid_cljse4miw184303tp9kqsuho9k/images/pacific-logo-1765431609081-compressed.png)
## FAQs
Q: How many controls are in ISO/IEC 27001:2022 Annex A?
A: There are 93 controls, organized into four themes: organizational, people, physical and technological.

Q: How does the 2022 structure differ from the 2013 edition?
A: The 2013 edition had 114 controls across 14 domains. The 2022 edition consolidated these into 93 controls across four themes, merging overlapping controls and adding 11 new ones.

Q: Is every organization required to implement all 93 controls?
A: No. Organizations select controls based on their risk assessment and document their decisions, including justified exclusions, in the Statement of Applicability.

Q: What is the purpose of the Statement of Applicability?
A: It records which Annex A controls an organization has included or excluded, with justification for each decision, based on its risk assessment and risk treatment plan.

Q: What are some of the new controls introduced in 2022?
A: Examples include threat intelligence, information security for cloud services, data masking, data leakage prevention, and secure coding, reflecting risks that were less prominent in 2013.




---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

