Certification
Finding your way around 93 controls
Annex A is a list of 93 controls in four themes, which is a hard shape to work with when you are trying to find the ones relevant to a particular risk. There is a second structure underneath it that makes the list navigable, and it lives in a different document.
Facts checked — 2026-09-11
How is Annex A organised?
The themes are organisational (37 controls), people (8), physical (14) and technological (34). That grouping is about where a control lives rather than what it does, which is why scanning by theme works when you are checking coverage and works badly when you are trying to treat a specific risk.
The useful structure is in ISO/IEC 27002:2022 — the guidance companion, not the Annex A list itself, and the distinction matters because people look for this in the wrong document. It tags every control with five attributes: control type (preventive, detective, corrective); information security properties (confidentiality, integrity, availability); cybersecurity concepts (identify, protect, detect, respond, recover, which line up with the NIST functions); operational capabilities; and security domains.
Those tags are explicitly not requirements — nobody audits your use of them. They exist so you can slice the list: every detective control, everything touching availability, everything in the respond phase. That is how you answer "what do we have covering this?" without reading all 93 in order, and it is the fastest route into the set for anyone meeting it for the first time.
The bottom line
Use the themes to check coverage and the ISO/IEC 27002 attributes to find controls by what they actually do. The attributes are optional, unaudited, and the most useful thing in the 2022 revision for anyone who has to work with the list rather than admire it.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.