The controls in ISO 27001 all live in Annex A of the standard. The 2022 version lists 93 controls grouped into four themes: organisational, people, physical and technological. You don’t blindly implement all of them; instead you select the controls relevant to your risks and record your decisions in a Statement of Applicability. In audit after audit, the organisations that come unstuck are the ones that treated Annex A as a checklist to tick off rather than a considered response to the risks they’d actually identified. Here’s how that works in practice.

What are ISO 27001 controls?
Controls are the safeguards you put in place to treat information security risks: things like access management, encryption, backups and supplier security. Annex A of ISO/IEC 27001:2022 provides a reference set of 93 controls. They are not a checklist to be implemented wholesale; they’re a menu you draw from based on the risks identified in your risk assessment.
The four control themes
The 2022 update reorganised the previous 114 controls into 93, grouped under four themes:
- Organisational (37 controls): policies, roles, supplier and information-handling controls, threat intelligence and incident management.
- People (8 controls): screening, terms of employment, awareness and training, and what happens when people change or leave roles.
- Physical (14 controls): secure areas, equipment, clear desk and screen, and protection against physical and environmental threats.
- Technological (34 controls): access control, cryptography, secure development, logging and monitoring, and network and endpoint security.
| Theme | Controls | Examples |
|---|---|---|
| Organisational | 37 | Policies, access control, supplier security, incident management |
| People | 8 | Screening, awareness training, remote working, confidentiality |
| Physical | 14 | Secure areas, equipment security, clear desk, secure disposal |
| Technological | 34 | Access control, cryptography, logging, malware protection, secure development |
| Total | 93 | Across all four themes (ISO 27001:2022 Annex A) |
Do you have to implement all 93?
No. ISO 27001 is risk-based. You assess your risks, decide how to treat them, and then select the Annex A controls that address those risks. Any controls you exclude must be justified. All of this is documented in your Statement of Applicability (SoA), the central document that lists every Annex A control, whether it applies, and why. The SoA is one of the first things a certification auditor will look at. The practical tell I look for is simple: I’ll point at a control marked “applicable” and ask to see it working. If no one can connect it back to a specific risk, or show me any evidence it actually runs, that’s usually where the cracks are.
How the controls relate to the Essential Eight
Many of the technological controls overlap with Australia’s Essential Eight: multi-factor authentication, patching, application control and backups all appear in both. If you already meet an Essential Eight maturity level, you’ve done a good chunk of the technical work ISO 27001 expects; the standard then adds the governance and risk framework around it. See Essential Eight vs ISO 27001 for how the two fit together.
How to choose your controls
The practical sequence is: define your scope, identify your information assets and risks, decide how to treat each risk, then map the relevant Annex A controls and implement them. Done well, you end up with a right-sized set of controls that genuinely fit your business rather than a bloated system. This is exactly the part where an experienced auditor saves you time, and where AI-built systems most often miss the mark.
Frequently asked questions
How many controls are in ISO 27001:2022?
93 controls across four themes, down from 114 in the 2013 version, which were reorganised and updated (with 11 new controls added) in the 2022 revision.
Are all the controls mandatory?
No. Only the management system clauses (4-10) are mandatory. Annex A controls are selected based on your risk assessment and justified in your Statement of Applicability. See our ISO 27001 requirements checklist for the mandatory parts.
Speak with an experienced ISO auditor
Want help selecting and implementing the right ISO 27001 controls? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











