Skip to content
SecuriFii

Certification

Finding your way around 93 controls

Annex A is a list of 93 controls in four themes, which is a hard shape to work with when you are trying to find the ones relevant to a particular risk. There is a second structure underneath it that makes the list navigable, and it lives in a different document.

Facts checked2026-09-11

How is Annex A organised?

The themes are organisational (37 controls), people (8), physical (14) and technological (34). That grouping is about where a control lives rather than what it does, which is why scanning by theme works when you are checking coverage and works badly when you are trying to treat a specific risk.

The useful structure is in ISO/IEC 27002:2022 — the guidance companion, not the Annex A list itself, and the distinction matters because people look for this in the wrong document. It tags every control with five attributes: control type (preventive, detective, corrective); information security properties (confidentiality, integrity, availability); cybersecurity concepts (identify, protect, detect, respond, recover, which line up with the NIST functions); operational capabilities; and security domains.

Those tags are explicitly not requirements — nobody audits your use of them. They exist so you can slice the list: every detective control, everything touching availability, everything in the respond phase. That is how you answer "what do we have covering this?" without reading all 93 in order, and it is the fastest route into the set for anyone meeting it for the first time.

The bottom line

Use the themes to check coverage and the ISO/IEC 27002 attributes to find controls by what they actually do. The attributes are optional, unaudited, and the most useful thing in the 2022 revision for anyone who has to work with the list rather than admire it.

Related insights