7.1 Annex A Structure: 93 Controls in 4 Themes
Key Takeaways
- ISO/IEC 27001:2022 Annex A contains 93 controls grouped into 4 themes: Organizational (37), People (8), Physical (14), and Technological (34)
- The 2022 revision replaced the 2013 structure of 114 controls across 14 domains with a simpler 4-theme model aligned to ISO/IEC 27002:2022
- 11 new controls were introduced in 2022, including Threat Intelligence (5.7), Cloud Services (5.23), Configuration Management (8.9), Data Masking (8.11), and Secure Coding (8.28)
- Annex A lists the control objectives and controls referenced by Clause 6.1.3; implementation guidance for each control lives in ISO/IEC 27002:2022
- Annex A is a reference catalogue, not a checklist — applicability of every control must be justified in the Statement of Applicability (SoA)
Annex A is the control catalogue appended to ISO/IEC 27001:2022. It is the single most heavily tested part of the Foundation exam outside the Clauses themselves, because it is the bridge between Clause 6.1.3 risk treatment and the day-to-day controls an organization actually implements. This section covers the structural rewrite that happened in the 2022 revision, the four themes, and the eleven new controls you must recognize by name.
Why Annex A Matters
Clause 6.1.3 requires the organization to compare the controls identified during risk treatment against Annex A and verify that no necessary control has been omitted. The output of that comparison is the Statement of Applicability (SoA). Annex A therefore is not optional reading — it is the benchmark a candidate ISMS is measured against during certification. Exam questions frequently test whether you know (a) how many controls exist, (b) which theme a control belongs to, and (c) which controls are new in 2022.
The 2022 Restructure
ISO/IEC 27001:2013 Annex A listed 114 controls organized into 14 domains (A.5 through A.18). The 2022 revision consolidated those 14 domains into 4 themes and reduced the total to 93 controls. The reduction is not pure subtraction: many 2013 controls were merged, some were dropped, and 11 brand-new controls were added to reflect modern threats (cloud, threat intelligence, secure coding, data leakage prevention).
The Four Themes
| Theme | Section Range | Control Count | Focus |
|---|---|---|---|
| Organizational | A.5.1 – A.5.37 | 37 | Policies, roles, supplier relationships, threat intelligence, cloud, ICT readiness for business continuity |
| People | A.6.1 – A.6.8 | 8 | Screening, terms of employment, awareness, disciplinary process, confidentiality, remote working, information transfer |
| Physical | A.7.1 – A.7.14 | 14 | Perimeters, entry, monitoring, equipment siting, utilities, cabling, media, secure disposal |
| Technological | A.8.1 – A.8.34 | 34 | User endpoint devices, access control, cryptography, secure coding, configuration management, deletion, masking, DLP, web filtering, logging, monitoring, clock sync, redundancy, network separation |
| Total | 93 |
A useful mnemonic for the counts is "37-8-14-34" — Organizational is largest because policy and supplier work expands; Technological is second largest because attack surface expands; People is smallest because human-centric controls are narrow in scope; Physical sits between.
The 11 New Controls Added in 2022
The exam loves to test whether you can recognize a control that did not exist in the 2013 version. Memorize these eleven by name and number:
| # | Control ID | Control Name | Theme |
|---|---|---|---|
| 1 | 5.7 | Threat intelligence | Organizational |
| 2 | 5.23 | Information security for use of cloud services | Organizational |
| 3 | 5.30 | ICT readiness for business continuity | Organizational |
| 4 | 7.4 | Physical security monitoring | Physical |
| 5 | 8.9 | Configuration management | Technological |
| 6 | 8.10 | Information deletion | Technological |
| 7 | 8.11 | Data masking | Technological |
| 8 | 8.12 | Data leakage prevention | Technological |
| 9 | 8.16 | Monitoring activities | Technological |
| 10 | 8.23 | Web filtering | Technological |
| 11 | 8.28 | Secure coding | Technological |
Why These Were Added
The 2013 standard predated mainstream cloud adoption, the rise of organized threat-intelligence sharing, and the DevOps/CI-CD explosion. The 2022 update reflects the modern threat landscape:
- Threat intelligence (5.7) formalizes collecting and acting on indicators of compromise.
- Cloud services (5.23) acknowledges that most organizations consume SaaS/IaaS rather than running their own data centers.
- ICT readiness for business continuity (5.30) ties ISO/IEC 27031-style ICT continuity into Annex A.
- Configuration management (8.9) and secure coding (8.28) address the infrastructure-as-code and software-supply-chain attack surface.
- Data masking (8.11), data leakage prevention (8.12), and information deletion (8.10) address privacy regulation (GDPR-era) expectations for minimizing and protecting personal data.
- Physical monitoring (7.4) closes the gap left by the 2013 standard's silence on active surveillance.
- Monitoring activities (8.16) consolidates and elevates logging/monitoring into its own control.
Annex A vs ISO/IEC 27002:2022
A common distractor on the exam conflates Annex A with 27002. The relationship is:
- ISO/IEC 27001 Annex A lists the control objectives and the control names — it is normative (mandatory if you claim conformity).
- ISO/IEC 27002:2022 provides the implementation guidance for every Annex A control — how to actually do it, with examples and rationale. 27002 is informative, not certifiable.
If a question asks "where do you find implementation guidance for control 5.23?" the correct answer is ISO/IEC 27002:2022, not Annex A. If a question asks "where are the control objectives that Clause 6.1.3 tells you to compare against?" the correct answer is Annex A of ISO/IEC 27001:2022.
Exam Traps
- Trap 1 — "114 controls in 14 domains." That is the 2013 number. The 2022 answer is 93 controls in 4 themes. Any answer using 114 or 14 is wrong unless the question explicitly asks about the 2013 version.
- Trap 2 — "Annex A controls are mandatory for every organization." They are not. Annex A is a catalogue; each control's applicability is determined through risk treatment and justified in the SoA.
- Trap 3 — Counting "new" controls incorrectly. The number of new controls introduced in 2022 is 11, not 12 or 14. Be careful with Web Filtering — the standard's actual new control is 8.23 Web filtering, which is distinct from 8.22 Segregation of networks (the latter existed in 2013 as A.14.1.2). Treat "web filtering" on the exam as a 2022 new control with its own control ID 8.23, not as a sub-topic of Segregation of networks.
- Trap 4 — Treating Annex A as the only controls you may use. Annex A is a minimum reference set. An organization may add controls outside Annex A (for example, a sector-specific PCI-DSS requirement) and document them in the SoA.
Key Takeaways
- Annex A:2022 = 93 controls in 4 themes (Organizational 37, People 8, Physical 14, Technological 34).
- The 2022 revision replaced the 2013 structure of 114 controls in 14 domains.
- 11 new controls were added, including Threat intelligence (5.7), Cloud services (5.23), Configuration management (8.9), Data masking (8.11), Data leakage prevention (8.12), and Secure coding (8.28).
- Implementation guidance for each Annex A control is in ISO/IEC 27002:2022, not in Annex A itself.
- Annex A is a reference catalogue, not a mandatory checklist — applicability is justified in the SoA.
How many controls are listed in ISO/IEC 27001:2022 Annex A, and how are they grouped?
Which of the following is NOT one of the 11 new controls introduced in ISO/IEC 27001:2022 Annex A?
Where would you find implementation guidance for Annex A control 5.23 (Information security for use of cloud services)?