Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

ISO 27001 Controls Explained (Annex A, 2022)

The controls in ISO 27001 all live in Annex A of the standard. The 2022 version lists 93 controls grouped into four themes: organisational, people, physical and technological. You don’t blindly implement all of them; instead you select the controls relevant to your risks and record your decisions in a Statement of Applicability. In audit after audit, the organisations that come unstuck are the ones that treated Annex A as a checklist to tick off rather than a considered response to the risks they’d actually identified. Here’s how that works in practice.

Analyst monitoring a cyber security dashboard
ISO 27001:2022 Annex A reorganised the previous 114 controls into 93, adding 11 new controls across four themes.

What are ISO 27001 controls?

Controls are the safeguards you put in place to treat information security risks: things like access management, encryption, backups and supplier security. Annex A of ISO/IEC 27001:2022 provides a reference set of 93 controls. They are not a checklist to be implemented wholesale; they’re a menu you draw from based on the risks identified in your risk assessment.

The four control themes

The 2022 update reorganised the previous 114 controls into 93, grouped under four themes:

  • Organisational (37 controls): policies, roles, supplier and information-handling controls, threat intelligence and incident management.
  • People (8 controls): screening, terms of employment, awareness and training, and what happens when people change or leave roles.
  • Physical (14 controls): secure areas, equipment, clear desk and screen, and protection against physical and environmental threats.
  • Technological (34 controls): access control, cryptography, secure development, logging and monitoring, and network and endpoint security.
ThemeControlsExamples
Organisational37Policies, access control, supplier security, incident management
People8Screening, awareness training, remote working, confidentiality
Physical14Secure areas, equipment security, clear desk, secure disposal
Technological34Access control, cryptography, logging, malware protection, secure development
Total93Across all four themes (ISO 27001:2022 Annex A)
The four ISO 27001:2022 Annex A control themes and their 93 controls.

Do you have to implement all 93?

No. ISO 27001 is risk-based. You assess your risks, decide how to treat them, and then select the Annex A controls that address those risks. Any controls you exclude must be justified. All of this is documented in your Statement of Applicability (SoA), the central document that lists every Annex A control, whether it applies, and why. The SoA is one of the first things a certification auditor will look at. The practical tell I look for is simple: I’ll point at a control marked “applicable” and ask to see it working. If no one can connect it back to a specific risk, or show me any evidence it actually runs, that’s usually where the cracks are.

How the controls relate to the Essential Eight

Many of the technological controls overlap with Australia’s Essential Eight: multi-factor authentication, patching, application control and backups all appear in both. If you already meet an Essential Eight maturity level, you’ve done a good chunk of the technical work ISO 27001 expects; the standard then adds the governance and risk framework around it. See Essential Eight vs ISO 27001 for how the two fit together.

How to choose your controls

The practical sequence is: define your scope, identify your information assets and risks, decide how to treat each risk, then map the relevant Annex A controls and implement them. Done well, you end up with a right-sized set of controls that genuinely fit your business rather than a bloated system. This is exactly the part where an experienced auditor saves you time, and where AI-built systems most often miss the mark.

Frequently asked questions

How many controls are in ISO 27001:2022?

93 controls across four themes, down from 114 in the 2013 version, which were reorganised and updated (with 11 new controls added) in the 2022 revision.

Are all the controls mandatory?

No. Only the management system clauses (4-10) are mandatory. Annex A controls are selected based on your risk assessment and justified in your Statement of Applicability. See our ISO 27001 requirements checklist for the mandatory parts.

Related reading

  • ISO 27001 requirements: a practical checklist
  • Preparing for an ISO 27001 audit
  • ISO 27001 certification cost and timeline in Australia

Speak with an experienced ISO auditor

Want help selecting and implementing the right ISO 27001 controls? Email hello@streamline.business or call us:

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire