Definition

Annex A controls

Annex A controls are the reference set of security safeguards that accompany ISO 27001 and give organizations a menu to draw from when treating risk. The 2022 revision groups 93 controls into four themes: organizational, people, physical, and technological. You are not required to adopt every one; instead you justify your selections in the Statement of Applicability based on your own risk assessment. Companion guidance in ISO 27002 explains how each control works in practice. Treat Annex A as a well-tested checklist that keeps you from overlooking a common protection, not as a rigid mandate.

FINAUDIT CPA · ASSURANCE · VERIFIED · INDEPENDENT ·

Ready when you are

Ready to make trust your competitive advantage?

One licensed CPA firm for your SOC, ISO, HIPAA, and VAPT programs — and the financial audits behind them. Talk to a senior auditor, not a sales rep.

Call Book a Consultation