3.1 Annex A Architecture & Attribute Taxonomy
Key Takeaways
- ISO/IEC 27001:2022 restructured Annex A from 114 controls across 14 domains (2013 version) into 93 controls organized into 4 thematic clauses (Organizational, People, Physical, Technological).
- The 2022 revision introduced 11 entirely new controls, merged 24 control pairs/groups, and updated 58 existing controls to align with modern cloud, threat intelligence, and privacy landscapes.
- ISO/IEC 27002:2022 established a standardized 5-attribute taxonomy matrix (Control Type, Information Security Properties, Cybersecurity Concepts, Operational Capabilities, Security Domains) to facilitate dynamic filtering, Statement of Applicability (SoA) alignment, and regulatory mapping.
- Lead auditors evaluate how organizations customize and apply attribute tags to their Statement of Applicability (SoA) to demonstrate comprehensive risk treatment and gap analysis.
ISO/IEC 27001:2022 Annex A Architecture & Attribute Taxonomy
Auditor Note: The transition from ISO/IEC 27001:2013 to ISO/IEC 27002:2022 and ISO/IEC 27001:2022 represents a fundamental shift in control organization. Lead auditors must understand not only the reduction in total control count from 114 to 93, but also the operational utility of the new 5-attribute taxonomy model when evaluating an organization's Statement of Applicability (SoA).
1. Structural Evolution: 2013 vs. 2022 Architecture
The 2013 edition of Annex A structured controls into 14 domains (A.5 through A.18) containing 35 control objectives and 114 controls. While comprehensive, this structure led to artificial silos between physical, technical, and operational security measures, making it cumbersome for cloud-native, remote, and hybrid enterprises.
ISO/IEC 27001:2022 radically simplified this framework by organizing controls into 4 thematic clauses based on operational ownership:
- Clause 5: Organizational Controls (37 controls)
- Clause 6: People Controls (8 controls)
- Clause 7: Physical Controls (14 controls)
- Clause 8: Technological Controls (34 controls)
In addition to consolidating domains, the 2022 revision removed explicit control objectives, replacing them with concise purpose statements for each control within ISO/IEC 27002:2022. This focuses the auditor's attention on intent and risk mitigation outcomes rather than prescriptive boilerplate compliance.
+-----------------------------------------------------------------------------------+
| STRUCTURAL REORGANIZATION |
+-----------------------------------------------------------------------------------+
| ISO/IEC 27001:2013 ISO/IEC 27001:2022 |
| ------------------ ------------------ |
| - 14 Domains (A.5 - A.18) - 4 Themes (Clause 5 - 8) |
| - 35 Control Objectives - 0 Control Objectives |
| - 114 Total Controls - 93 Total Controls |
| - 11 New Controls |
| - 24 Merged Controls |
| - 58 Updated Controls |
+-----------------------------------------------------------------------------------+
2. Quantitative Breakdown: New, Merged, and Updated Controls
Although the total control count dropped from 114 to 93, the actual scope of security controls expanded. The numerical reduction was achieved primarily through consolidation:
- 58 Controls Updated: Retained single-control mapping from 2013, with modernized wording to cover cloud, remote work, and modern threat vectors.
- 24 Controls Merged: Combined 57 legacy controls into 24 broader, logically grouped controls (e.g., combining separate mobile device and teleworking policies into unified controls).
- 1 Control Split: ISO/IEC 27001:2013 A.18.2.3 (Technical compliance review) was divided to distinguish general technical compliance from secure coding and configuration auditing.
- 11 Brand-New Controls: Introduced to plug critical coverage gaps in modern enterprise environments.
Summary Table of the 11 New Annex A Controls
| Control ID | Control Name | Theme | Primary Objective / Focus Area |
|---|---|---|---|
| 5.7 | Threat intelligence | Organizational | Formal collection, analysis, and application of tactical/strategic threat intelligence feeds. |
| 5.23 | Information security for use of cloud services | Organizational | Comprehensive governance, architecture, and SLA monitoring across IaaS, PaaS, and SaaS environments. |
| 5.30 | ICT readiness for business continuity | Organizational | Technical infrastructure availability, RTO/RPO alignment, and disaster recovery testing. |
| 7.4 | Physical security monitoring | Physical | Continuous monitoring of physical perimeters, data centers, and sensitive facilities via CCTV/IDS. |
| 8.9 | Configuration management | Technological | Establishing, hardening, maintaining, and monitoring baseline configurations across infrastructure. |
| 8.10 | Information deletion | Technological | Secure deletion of data in compliance with legal/privacy mandates and media retention schedules. |
| 8.11 | Data masking | Technological | Implementation of pseudonymization, anonymization, and encryption for sensitive datasets/PII. |
| 8.12 | Data leakage prevention (DLP) | Technological | Technical controls to detect, monitor, and prevent unauthorized data exfiltration across endpoints & networks. |
| 8.16 | Monitoring activities | Technological | Continuous network, endpoint, and application security monitoring via SIEM/SOC infrastructure. |
| 8.23 | Web filtering | Technological | Restriction of access to malicious, inappropriate, or unapproved web domains and external resources. |
| 8.28 | Secure coding | Technological | Establishing secure software development principles, static/dynamic security testing (SAST/DAST). |
3. The 5-Attribute Taxonomy Framework
To prevent the 93 controls from becoming a rigid monolithic list, ISO/IEC 27002:2022 introduced a standardized 5-attribute taxonomy. Each control is assigned metadata across five distinct taxonomy dimensions, allowing organizations and lead auditors to view, slice, filter, and audit controls through multiple operational lenses.
+-----------------------------------------------------------------------------------+
| THE 5 ATTRIBUTE TAXONOMY DIMENSIONS |
+-----------------------------------------------------------------------------------+
| 1. CONTROL TYPE ---> [Preventive] [Detective] [Corrective] |
| 2. INFOSEC PROPERTIES ---> [Confidentiality] [Integrity] [Availability] |
| 3. CYBERSECURITY CONCEPTS ---> [Identify] [Protect] [Detect] [Respond] [Recover] |
| 4. OPERATIONAL CAPABILITIES ---> [15 Functional Areas e.g., Governance, IAM] |
| 5. SECURITY DOMAINS ---> [Governance_&_Ecosystem] [Protection] [Defense]... |
+-----------------------------------------------------------------------------------+
1. Control Type
Defines the temporal mechanism by which the control affects a risk event:
- Preventive: Inhibits the occurrence of an incident (e.g., multi-factor authentication, physical locks).
- Detective: Identifies when an incident or policy violation occurs (e.g., SIEM alerts, physical intrusion alarms).
- Corrective: Restores normal operations or mitigates impact after an incident (e.g., data backups, incident response playbook execution).
2. Information Security Properties
Aligns controls directly with the CIA Triad:
- Confidentiality: Protects against unauthorized disclosure (e.g., Data Masking 8.11, DLP 8.12).
- Integrity: Protects against unauthorized modification or destruction (e.g., Secure Coding 8.28, Configuration Management 8.9).
- Availability: Ensures timely and reliable access (e.g., ICT Readiness for Business Continuity 5.30, Redundancy 8.14).
3. Cybersecurity Concepts
Maps controls directly to the international cybersecurity lifecycle (aligned with ISO/IEC 27032 and the NIST Cybersecurity Framework):
- Identify | Protect | Detect | Respond | Recover
4. Operational Capabilities
Categorizes controls into 15 practical security functions within an enterprise IT organization:
- Governance
- Asset management
- Information protection
- Human resource security
- Physical security
- System and network security
- Application security
- Secure configuration
- Identity and access management (IAM)
- Threat and vulnerability management
- Continuity
- Supplier relationships security
- Legal and compliance
- Information security event management
- Information security assurance
5. Security Domains
Groups controls according to strategic architectural domains:
- Governance and Ecosystem: Executive oversight, risk management, third-party relations.
- Protection: Safeguarding assets, access management, cryptography.
- Defense: Active threat detection, SOC monitoring, network defense.
- Resilience: Business continuity, disaster recovery, incident handling.
4. Statement of Applicability (SoA) & Attribute Mapping in Audits
During an ISO/IEC 27001 audit, the Statement of Applicability (SoA) is a core audit artifact (Clause 6.1.3 d). The SoA must list all 93 controls, state whether each control is included or excluded, provide clear justification for exclusions, and document the implementation status.
How Lead Auditors Evaluate Attribute-Tagged SoAs
- Dynamic Filtering for Risk Assessment: Auditors cross-reference the organization's Risk Treatment Plan (RTP) against attribute tags. For example, if a high-risk finding relates to ransomware, the auditor filters the SoA by
Cybersecurity Concept: #RecoverandOperational Capability: #Continuityto verify that all corresponding controls (e.g., 5.30, 8.13) are marked as Applicable. - Custom Attribute Extensions: Organizations are permitted to define custom attributes (e.g.,
#GDPR_Compliance,#PCI_DSS,#Cloud_Native). Lead auditors verify that custom attributes accurately reflect regulatory and contractual boundaries. - Justification of Exclusions: Under ISO/IEC 27001:2022, excluding any of the 93 controls requires explicit justification. If an organization excludes Control 8.11 (Data Masking), the lead auditor must verify whether PII or sensitive data exists in development or testing environments.
5. Lead Auditor Worked Scenario
Scenario Background
During a Stage 2 Certification Audit of CloudNexus Systems, a SaaS platform provider, Lead Auditor Elena is reviewing the organization's SoA transition from ISO/IEC 27001:2013 to the 2022 version. CloudNexus operates entirely within AWS and uses third-party threat feeds.
Audit Observation & Evidence Review
- SoA Exclusions: CloudNexus marked Control 7.4 (Physical security monitoring) as Excluded, stating: "We operate 100% in AWS, so physical controls do not apply to us."
- Attribute Mapping Check: CloudNexus mapped Control 5.7 (Threat intelligence) under
Control Type: #Preventive, but failed to assign operational responsibility or link it to their threat vulnerability management process. - Control 5.23 (Cloud Services): CloudNexus implemented AWS GuardDuty and Security Hub, but had no documented policy governing cloud configuration reviews or third-party cloud SLA reviews.
Auditor Evaluation & Findings
- Finding 1 (Minor Nonconformity against Clause 6.1.3 d & Control 7.4): While CloudNexus does not own physical data centers, they maintain physical corporate headquarters housing executive endpoints and network equipment. Control 7.4 was excluded without assessing physical perimeter monitoring for corporate premises.
- Finding 2 (Opportunity for Improvement against Control 5.7): Threat intelligence (5.7) is tagged only as
#Preventive. The auditor recommends adding#Detectiveand#Identifyattribute tags to ensure feeds feed directly into the SOC's incident response playbooks. - Finding 3 (Minor Nonconformity against Control 5.23): Absence of documented cloud governance and vendor SLA monitoring criteria violates the mandatory requirements of Control 5.23 for a 100% cloud-dependent organization.
Which of the following correctly describes the structural changes introduced in Annex A of ISO/IEC 27001:2022 compared to the 2013 edition?
An organization is updating its Statement of Applicability (SoA) using the ISO/IEC 27002:2022 5-attribute taxonomy. How should Control 8.12 (Data leakage prevention) be categorized under the 'Information Security Properties' attribute?
During an ISO/IEC 27001:2022 audit, a lead auditor notes that an organization excluded Control 5.7 (Threat intelligence) from its SoA, claiming that threat intelligence is only required for financial institutions. What is the auditor's correct course of action?