
Introduction
The 2022 revision of the standard brought the most significant update to Annex A in a decade, consolidating and modernizing the control set to reflect how organizations actually manage information security today including cloud services, remote working and emerging threats that barely existed when the 2013 edition was published.
Tip: Build your ISMS around ISO 27001 Clauses 4–10, using Annex A controls based on identified risks and treatment decisions.
Structure of Annex A
The 2022 edition restructured this significantly, consolidating the controls down to 93 and reorganizing them into just four overarching themes.
The four themes at a glance
A.5 Organizational controls - 37 controls
A.6 People controls - 8 controls
A.7 Physical controls - 14 controls
A.8 Technological controls - 34 controls
What changed from the 2013 edition?
A number of overlapping or outdated controls from the 2013 edition were merged, and 11 entirely new controls were introduced to address areas such as threat intelligence, cloud security, data masking, and secure coding reflecting how information security risk has evolved since 2013.
Control attributes
Each control in the 2022 edition is also tagged with attributes covering control type, security properties, cybersecurity concepts, operational capabilities and security domains.
These attributes give organizations a more flexible way to filter, group and report on controls beyond the four fixed themes, for example by generating a view of all "preventive" controls or all controls relevant to "governance."
Organizational controls
Organizational controls, listed under A.5, form the largest theme in Annex A with 37 controls. These address the policies, governance structures, roles, processes and third-party relationships that underpin an organization's approach to information security.
Rather than covering technical safeguards, this theme focuses on how security is directed, managed and embedded across the organization.
Governance, roles and policy
Representative areas covered here include information security policies, roles and responsibilities, segregation of duties, contact with authorities and special interest groups, and independent review of information security.
These controls establish who is accountable for security decisions and how those decisions are documented and reviewed.
Asset, project and supplier management
This theme also covers inventory of information and other associated assets, acceptable use, information security in project management, and supplier relationships and information security in supply chains.
These controls extend security accountability beyond the organization's own boundaries to the vendors, contractors and partners it works with.
Incident, continuity and compliance
Further controls address incident management, business continuity, and legal and contractual requirements, ensuring the organization can respond to disruptions and remain compliant with applicable obligations.
New organizational controls introduced in 2022
Several of the controls newly introduced in the 2022 edition sit within this theme, including threat intelligence (A.5.7), information security for use of cloud services (A.5.23), and ICT readiness for business continuity (A.5.30).
These additions reflect the growing reliance on external cloud providers and the need for organizations to actively monitor the threat landscape rather than relying solely on reactive incident response.
People, physical and technological controls
People controls (A.6)
People controls cover the eight controls related to how an organization manages its workforce from a security perspective: screening, terms and conditions of employment, information security awareness, education and training, disciplinary processes, responsibilities after termination or change of employment, confidentiality or non-disclosure agreements, remote working, and information security event reporting.
This is the smallest theme by control count, but it addresses risks that technology alone cannot mitigate, since human error and insider behavior remain leading causes of security incidents.
Physical controls (A.7)
Physical controls comprise 14 controls addressing the security of physical locations and equipment, including physical security perimeters, physical entry controls, securing offices and facilities, protection against environmental threats, working in secure areas, clear desk and clear screen practices, equipment siting and protection, secure disposal or reuse of equipment, and security of assets off-premises.
These controls remain essential even as organizations shift toward remote and hybrid work, since physical access to devices, facilities and data centers continues to represent a significant attack surface.
Technological controls (A.8)
Technological controls form the second-largest theme, with 34 controls covering the technical safeguards applied to systems, networks and data.
This includes user endpoint devices, privileged access rights, information access restriction, use of cryptography, secure system architecture and engineering principles, protection against malware, technical vulnerability management, network security, application security, secure coding, and data leakage prevention.
Takeaway: Organizational controls establish security direction, while people, physical and technological controls translate it into practical safeguards across operations.
New technological controls introduced in 2022
New controls introduced in this theme in the 2022 edition include data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28), reflecting the growing importance of data protection and application-layer security.
Statement of Applicability
The Statement of Applicability (SoA) is a mandatory document required under Clause 6.1.3(d) of ISO 27001 and is one of the most important deliverables in the certification process.
It records which of the 93 Annex A controls an organization has determined are necessary based on its risk assessment and risk treatment plan, and, just as importantly, provides justification for including or excluding each control.
What the Statement of Applicability must include?
Building the Statement of Applicability
Completing a risk assessment that identifies information security risks relevant to the organization.
Selecting controls from Annex A (or supplementary controls, where needed) to address identified risks through the risk treatment process.
Documenting a justification for the inclusion of each selected control.
Documenting a justification for the exclusion of any Annex A control not selected, since Annex A is a reference set and not every control will apply to every organization.
Confirming whether each included control has actually been implemented, since selection and implementation are reviewed separately during certification audits.
Reviewing and updating the Statement of Applicability whenever risks, the organization's context or its risk treatment plan change.
How auditors use the Statement of Applicability?
Auditors use the Statement of Applicability as a central reference point during certification audits, cross-checking it against the risk assessment, risk treatment plan and evidence of actual implementation.
A Statement of Applicability that lists controls as implemented without corresponding evidence or that excludes relevant controls without adequate justification is one of the most common sources of audit findings.
Common implementation mistakes
A frequent mistake is treating Annex A as a checklist to work through control by control, rather than starting from the risk assessment and selecting controls based on identified risks.
Another common mistake is excluding controls from the Statement of Applicability without adequate justification, or including controls that are not actually implemented in practice.
Organizations transitioning from the 2013 edition sometimes also assume the mapping between old and new controls is one-to-one, when in fact several 2013 controls were merged or restructured, requiring a genuine review rather than a simple renumbering exercise.
How Pacific Certifications can help?
Pacific Certifications can provide:
Review of proposed ISO/IEC 27001:2022 certification scopes
Independent ISO/IEC 27001:2022 certification audits where applicable
Stage 1 documentation and certification-readiness audits, including review of the Statement of Applicability
Stage 2 implementation and effectiveness audits
Annual surveillance audits and triennial recertification audits
Pacific Certifications conducts impartial certification audits and does not design, implement or manage information security management systems for its certification clients.
Contact Us
To request an ISO/IEC 27001:2022 certification priorities contact support@pacificcert.com or visit www.pacificcert.com.
Also read: ISO/IEC 27002 best practices for implementing ISO 27001 controls
