Skip to content

Annex a

Definition

The normative annex to ISO/IEC 27001 that lists 93 information security controls across four themes: organisational (37 controls), people (8), physical (14), and technological (34). The standard requires organisations to reference Annex A when determining controls, but permits exclusions with justification. The full implementation guidance for each control is in ISO/IEC 27002.

Standard
ISO/IEC 27001, normative annex
Control count
93 controls
Themes
Organisational, people, physical, technological
Detail source
ISO/IEC 27002 gives implementation guidance
Exclusions
Allowed with documented justification

Common questions

Can an organisation skip a control listed in Annex A?+

Yes. ISO/IEC 27001 requires the organisation to compare its risk-treatment plan against Annex A and produce a Statement of Applicability, but a control can be marked not applicable if the organisation documents why it does not apply to its risk environment.

How did Annex A change from the 2013 to the 2022 revision?+

The 2022 revision reorganised the older 14-domain, 114-control structure into four themes totalling 93 controls, merging and consolidating many prior clauses and adding new controls such as those covering cloud services and data leakage prevention.

Is Annex A itself enough to build a security programme?+

No. Annex A states control objectives at a summary level; an auditor or implementer turns to ISO/IEC 27002 for the fuller description of purpose, implementation guidance, and other information behind each control.

Related terms

Statement of Applicability (SoA)
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...
Continual Improvement
The ISO/IEC 27001 requirement (clause 10) that the organisation must actively improve the suitability, adequacy, and effectiveness of the ISMS over time....
High-Level Structure (HLS)
The common clause framework mandated by ISO for all management system standards. Clauses 4 through 10 of ISO 27001 follow the same...
Information Security Management System (ISMS)
The set of policies, processes, procedures, and controls that an organisation establishes to manage information security risk. ISO 27001 specifies the requirements...
ISMS Scope
The explicit boundaries of the management system: which organisational units, sites, processes, and information assets are covered. Defined under ISO/IEC 27001 clause...
ISO/IEC 27002
A guidance standard (not certifiable) that provides implementation advice for each of the 93 controls in ISO 27001 Annex A. Updated in...
Management Review
The annual governance meeting required under ISO 17025 Clause 8.9, at which laboratory management reviews the aggregated quality performance data (PT results,...
Risk Owner
The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
Risk Treatment Plan
A document that records, for each identified risk, the chosen treatment option (accept, avoid, transfer, or reduce), the specific controls selected to...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.