UprootSecurity
Book a demo
Compliance

ISO 27001 Requirements: Understanding the 93 Annex A Controls

RJ

Robin Joseph

Senior Security Consultant

Published
Updated
Reading24 min · 4,807 words
ISO 27001 Requirements: Understanding the 93 Annex A Controls

Last reviewed: September 2026.

ISO 27001 requirements are the rules an organization follows to build, run, and maintain an Information Security Management System (ISMS), published by ISO and IEC and used in over 150 countries.

These requirements are split into two parts. First, the clauses (4 to 10) define how your ISMS should run, covering scope, leadership, risk assessment, documentation, and continuous improvement. They ensure your security program is structured and repeatable, not dependent on guesswork. Second, Annex A includes 93 controls across organizational, people, physical, and technological areas. You don't implement all of them. You select controls based on your risks and document them in your Statement of Applicability.

Is ISO 27001 Certification Mandatory?

No law requires ISO 27001 certification. In practice, it's often non-negotiable anyway.

Enterprise buyers, government contracts, and financial-sector vendors routinely make it a condition of doing business, not a nice-to-have on a vendor questionnaire. If your sales team keeps losing deals to a security review, or a security review keeps stalling a deal already in motion, that's usually the real trigger, not a compliance team's own initiative.

Smaller companies sometimes get by with a SOC 2 report instead, since it covers similar ground for a US-based buyer. ISO 27001 tends to matter more once you're selling into Europe, the public sector, or regulated industries where an internationally recognized certification carries more weight than a SOC 2 report alone. If you're still deciding whether now's the time, our guide on ISO 27001 for startups covers the signals worth watching.

What Are ISO 27001 Requirements and Why Do They Matter?

ISO 27001 requirements are the rules organizations follow to build, implement, and maintain an Information Security Management System (ISMS). They help you identify risks, apply the right controls, and continuously improve how you protect sensitive information.

The 7 ISO 27001 Clauses at a Glance

ClauseNameWhat It Requires
4Context of the OrganizationDefine the ISMS scope and the internal/external issues that affect it
5LeadershipTop management commits, sets policy, and assigns responsibility
6PlanningRisk assessment, risk treatment, and measurable security objectives
7SupportResources, competence, awareness, communication, and documented information
8OperationExecute the risk treatment plan and control operational processes
9Performance EvaluationMonitor, measure, run internal audits, and conduct management review
10ImprovementHandle nonconformities and continually improve the ISMS

Clause 6 gets the deepest look below because it's one of the areas auditors flag most often, usually a mismatch between the risk methodology, the risk register, and the Statement of Applicability (common audit findings). That doesn't make the other six optional. Skipping Clause 7's competence and awareness records, or Clause 10's nonconformity log, is as much an audit finding as a missing Annex A control.

ISO 27001 Clause 6 Risk Assessment and Planning Framework

This is where ISO 27001 stops being theory and starts working. Clause 6 turns risk into action, forcing you to assess threats, plan responses, and define measurable goals that actually reduce exposure.

Understanding ISO 27001 Clause 6 Risk Assessment

ISO 27001 Clause 6 risk assessment is the process used to identify, analyze, and evaluate information security risks within your ISMS. It ensures risks are handled through a structured, repeatable method rather than guesswork. Clause 6.1.2 requires you to define risk criteria, assess likelihood and impact, and determine what level of risk is acceptable.

Start with an asset register covering hardware, software, data, people, and locations. Assign a single owner to each asset. Then evaluate risks by assigning likelihood and impact values, calculate risk scores, and compare them against your acceptance criteria to decide next steps.

Creating a Risk Treatment Plan

Once risks are identified, you have four options: terminate, treat, transfer, or tolerate. The choice depends on your risk appetite and business priorities, but every decision must be justified and documented clearly.

Your risk treatment plan connects risks to controls. It outlines what action you'll take, why you chose it, who's responsible, timelines, resources, and how success will be measured. This is where strategy turns into execution.

Auditors rely heavily on this document because it shows your methodology isn't just theoretical. It's applied consistently across real risks and controls.

Setting Measurable Security Objectives

Clause 6.2 requires organizations to define security objectives that align with their ISMS policy and risk landscape. These objectives must be measurable where possible, monitored regularly, and clearly communicated across teams.

Use the SMART framework to make them effective. Avoid vague goals like "improve security." Instead, define targets such as "patch critical vulnerabilities within 48 hours" or "maintain 99.9% uptime."

Each objective should include actions, ownership, timelines, and metrics. Clear objectives keep teams focused and prove your ISMS is delivering measurable results.

ISO 27001 Mandatory Documents and ISMS Policy Requirements

Documentation is where ISO 27001 gets real. Auditors don't trust claims, they want proof. Every decision, control, and process must be backed by clear, consistent records that show your ISMS actually works.

ISO 27001 ISMS Policy Requirements

Clause 5.2 requires an information security policy tailored to your organization, not a generic template. It must define or reference security objectives, commit to meeting requirements, and ensure continual improvement of the ISMS. Management must approve it, document it, and communicate it internally while making it available to relevant stakeholders.

Beyond this, you need supporting policies for areas like access control, supplier security, acceptable use, and data classification. Each policy requires approval, periodic review, and evidence of communication. Without this, your ISMS lacks structure and accountability.

ISO 27001 Statement of Applicability

The Statement of Applicability (SoA) connects your risk assessment to the controls you implement. Auditors rely on it to understand your decisions. For each of the 93 Annex A controls, you must define status, inclusion or exclusion, justification, and link it to supporting evidence.

Skipping controls or providing weak justification leads to nonconformities. The SoA should clearly explain how controls address risks and why some are excluded. It acts as your security blueprint and must reflect real business decisions, not assumptions.

Risk Assessment and Treatment Reports

Risk assessment reports capture your methodology, identified risks, likelihood and impact scores, and final risk levels. They provide a structured view of how risks are identified and evaluated across the organization.

Treatment reports go further by showing how controls address those risks. They connect Annex A controls to business processes, explain exclusions, assign ownership, and provide evidence. Together, these documents prove your decisions are consistent and defensible.

Internal Audit and Management Review Records

Clause 9.2 requires internal audits at planned intervals to verify your ISMS is working. You must define scope, criteria, and maintain records showing audits were conducted, findings reported, and actions tracked.

Clause 9.3 requires management reviews covering performance, risks, incidents, and improvement opportunities. These reviews must show real decisions, ownership, and timelines. Without substance, your documentation fails to demonstrate control.

ISO 27001 Certification Process, Timeline, and Cost

Knowing the requirements is one thing. Getting certified against them is another, and it's the question most buyers actually have.

The Certification Process

Certification runs through an external audit in two stages, conducted by an accredited certification body, not by ISO itself.

  • Stage 1 (documentation review): the auditor checks that your ISMS documentation, policies, risk assessment, and Statement of Applicability exist and meet the standard's requirements.
  • Stage 2 (implementation audit): the auditor tests whether the controls you documented are actually operating, through interviews, evidence sampling, and system checks.
  • Certification decision: pass both stages and the certification body issues your ISO 27001 certificate, valid for three years.
  • Surveillance audits: shorter audits in years 1 and 2 confirm the ISMS is still operating as certified.
  • Recertification audit: a full audit in year 3 renews the certificate for another three-year cycle.

For the full step-by-step rollout, including how to prepare for each stage, see our ISO 27001 certification process guide.

How Long ISO 27001 Certification Takes

Most first-time organizations take 6 to 12 months from starting implementation to certification, depending on company size, how mature existing security practices already are, and how many Annex A controls apply. Smaller, cloud-native startups with few systems can move faster; regulated or multi-location organizations usually take longer.

How Much ISO 27001 Certification Costs

Costs vary by company size, auditor, and scope, but budget for three buckets:

Cost AreaTypical RangeWhat It Covers
Preparation$15,000 to $40,000+Gap assessment, policy writing, risk assessment, internal resourcing or consultants
Certification audit$8,000 to $20,000Stage 1 and Stage 2 audits by the certification body
Ongoing maintenance$5,000 to $15,000/yearSurveillance audits, internal audits, policy upkeep

Compliance automation platforms reduce the preparation cost and timeline most, since manual evidence collection and spreadsheet-based risk registers are what usually stretch a project past 12 months.

Breaking Down the ISO 27001 Annex A Controls List

ISO 27001 Annex A controls are a structured list of 93 security measures used to manage information risks. These controls are grouped into four domains: organizational, people, physical, and technological, so you can map risks to the right safeguards. You don't implement all controls blindly. You select what applies to your risks and justify it in your Statement of Applicability.

DomainControlsWhat It Covers
Organizational (A.5)37Policies, governance, supplier security, incident response
People (A.6)8Hiring, training, behavior, offboarding
Physical (A.7)14Facilities, equipment, environmental protection
Technological (A.8)34Systems, networks, encryption, monitoring

Organizational Controls (37 Controls)

This is your governance layer, where structure, policies, and accountability come together.

ControlNameWhat It Covers
A.5.1Policies for Information SecurityDefine how security is managed
A.5.2Information Security Roles and ResponsibilitiesAssign accountability for security tasks
A.5.3Segregation of DutiesPrevent conflicts of interest in sensitive tasks
A.5.4Management ResponsibilitiesEnsure leadership actively supports the ISMS
A.5.5Contact With AuthoritiesMaintain contact with regulators and law enforcement
A.5.6Contact With Special Interest GroupsStay current with security forums and associations
A.5.7Threat IntelligenceIdentify emerging risks
A.5.8Information Security in Project ManagementBuild security into every project from the start
A.5.9Inventory of Information and Other AssetsTrack critical assets
A.5.10Acceptable Use of AssetsDefine rules for handling assets
A.5.11Return of AssetsRecover company property when access ends
A.5.12Classification of InformationLabel data by sensitivity
A.5.13Labelling of InformationMark information per its classification
A.5.14Information TransferSecure data movement between parties
A.5.15Access ControlDefine access rules
A.5.16Identity ManagementManage user identities through their lifecycle
A.5.17Authentication InformationProtect passwords and credentials
A.5.18Access RightsGrant, review, and revoke access appropriately
A.5.19Information Security in Supplier RelationshipsManage third-party risks
A.5.20Security in Supplier AgreementsPut security terms in contracts
A.5.21Security in the ICT Supply ChainSecure the technology supply chain
A.5.22Monitoring of Supplier ServicesTrack supplier performance and changes
A.5.23Cloud Services SecuritySecure cloud usage
A.5.24Incident Management PlanningPrepare a response plan before incidents happen
A.5.25Assessment of Security EventsDecide which events count as incidents
A.5.26Response to IncidentsHandle security events
A.5.27Learning From IncidentsImprove controls based on past incidents
A.5.28Collection of EvidencePreserve evidence for investigations
A.5.29Security During DisruptionMaintain security during outages or crises
A.5.30ICT Readiness for Business ContinuitySupport business continuity
A.5.31Legal and Regulatory RequirementsTrack applicable legal obligations
A.5.32Intellectual Property RightsProtect IP and licensing compliance
A.5.33Protection of RecordsKeep records accurate and tamper-proof
A.5.34Privacy and Protection of PIISafeguard personal data
A.5.35Independent Review of SecurityGet outside validation of the ISMS
A.5.36Compliance With Policies and StandardsVerify internal policies are actually followed
A.5.37Documented Operating ProceduresKeep IT operations documented and repeatable

Without strong governance, controls become inconsistent and ineffective.

People Controls (8 Controls)

These controls address risks caused by human actions and behavior.

ControlNameWhat It Covers
A.6.1ScreeningVerify trust before granting access
A.6.2Terms and Conditions of EmploymentSet security expectations in employment contracts
A.6.3Security Awareness, Education and TrainingTrain employees regularly
A.6.4Disciplinary ProcessHandle violations
A.6.5Responsibilities After TerminationRemove access promptly
A.6.6Confidentiality or Non-Disclosure AgreementsBind staff and contractors to confidentiality
A.6.7Remote WorkingSecure distributed teams
A.6.8Information Security Event ReportingMake it easy for staff to report suspicious activity

People remain one of the most unpredictable risk factors in security.

Physical Controls (14 Controls)

These controls protect facilities and physical assets from threats.

ControlNameWhat It Covers
A.7.1Physical Security PerimetersDefine secure boundaries
A.7.2Physical EntryRestrict access
A.7.3Securing Offices, Rooms and FacilitiesProtect workspaces from unauthorized access
A.7.4Physical Security MonitoringDetect suspicious activity
A.7.5Protecting Against Physical and Environmental ThreatsPrevent damage
A.7.6Working in Secure AreasSet rules for restricted zones
A.7.7Clear Desk and Clear ScreenReduce exposure
A.7.8Equipment Siting and ProtectionPosition and protect hardware from risk
A.7.9Security of Assets Off-PremisesProtect devices used outside the office
A.7.10Storage MediaControl removable media
A.7.11Supporting UtilitiesProtect power, cooling, and other utilities
A.7.12Cabling SecurityPrevent interception or damage to cabling
A.7.13Equipment MaintenanceKeep hardware properly serviced
A.7.14Secure Disposal or Re-Use of EquipmentDestroy data safely

Physical weaknesses can bypass even the strongest digital defenses.

Technological Controls (34 Controls)

These controls secure systems, networks, and data.

ControlNameWhat It Covers
A.8.1User Endpoint DevicesSecure endpoints
A.8.2Privileged Access RightsLimit admin rights
A.8.3Information Access RestrictionRestrict access based on need
A.8.4Access to Source CodeProtect source code from unauthorized changes
A.8.5Secure AuthenticationUse strong login and verification methods
A.8.6Capacity ManagementPlan system capacity to avoid failures
A.8.7Protection Against MalwarePrevent threats
A.8.8Management of Technical VulnerabilitiesIdentify and patch vulnerabilities
A.8.9Configuration ManagementMaintain secure setups
A.8.10Information DeletionSecurely erase data no longer needed
A.8.11Data MaskingLimit exposure
A.8.12Data Leakage PreventionPrevent data loss
A.8.13Information BackupEnsure data can be recovered
A.8.14Redundancy of Processing FacilitiesBuild in failover for critical systems
A.8.15LoggingTrack activity
A.8.16Monitoring ActivitiesWatch for abnormal behavior in real time
A.8.17Clock SynchronizationKeep system clocks aligned for accurate logs
A.8.18Use of Privileged Utility ProgramsRestrict powerful system tools
A.8.19Software Installation on Operational SystemsControl what software runs in production
A.8.20Networks SecurityProtect communications
A.8.21Security of Network ServicesSecure the services running on your network
A.8.22Segregation of NetworksSeparate networks to limit blast radius
A.8.23Web FilteringBlock harmful sites
A.8.24Use of CryptographyProtect sensitive data
A.8.25Secure Development Life CycleBuild security into every stage of development
A.8.26Application Security RequirementsDefine security requirements before building
A.8.27Secure System ArchitectureDesign systems securely from the ground up
A.8.28Secure CodingFollow secure coding standards
A.8.29Security Testing in DevelopmentTest for vulnerabilities before release
A.8.30Outsourced DevelopmentApply security standards to contracted development work
A.8.31Separation of Dev, Test and ProductionKeep environments isolated
A.8.32Change ManagementControl how changes are made to systems
A.8.33Test InformationProtect data used in testing
A.8.34Protection of Systems During Audit TestingPrevent audits from disrupting live systems

Your security is only as strong as your weakest control. Control A.8.29 in particular is where a periodic penetration test earns its keep: it's the most direct piece of evidence an auditor can point to for "security testing in development" actually happening, rather than being a policy statement with nothing behind it.

Critical Annex A Controls: Access Control and Asset Management

Access control and asset management are where most ISO 27001 failures happen. Weaknesses here lead to audit issues, unauthorized access, and security incidents that are difficult and expensive to fix.

ISO 27001 Access Control Requirements

ISO 27001 access control is built on four core principles: Need to Know, Least Privilege, Segregation of Duties, and Role-Based Access Control. These ensure users only access what they need and nothing beyond their role.

Annex A.5.15 defines your policy, while A.5.16 and A.5.18 manage the full lifecycle: granting, reviewing, and removing access. Strong access control prevents misuse and reduces exposure to internal and external threats.

User Access Provisioning and Deprovisioning

The Joiner-Mover-Leaver lifecycle ensures access stays aligned with roles as employees join, change positions, or leave. Timely provisioning and immediate removal of access are critical to maintaining security.

Regular access reviews help identify permission creep, where users accumulate unnecessary access over time. Automation tools can streamline updates, but consistent monitoring ensures access remains accurate and controlled.

ISO 27001 Asset Management Framework

Asset management ensures you know exactly what you own and what needs protection. Control A.5.9 requires maintaining an inventory of assets, including hardware, software, and data.

Each asset must have a single owner responsible for its lifecycle. This accountability ensures assets are tracked, protected, and properly managed from creation to disposal.

Information Classification and Handling

Information classification defines how data is handled based on its sensitivity and business impact. Control A.5.12 requires classification frameworks that guide how information is stored, shared, and protected.

Control A.5.13 requires clear labeling so users understand handling requirements. Proper classification reduces the risk of accidental exposure and ensures consistent data protection practices.

Advanced Security Controls: Cryptography and Supplier Security

Your external security perimeter depends on two things: strong encryption and secure suppliers. Weak controls here expose sensitive data and create backdoors that bypass even the strongest internal defenses.

ISO 27001 Cryptography Controls and Key Management

Cryptography under ISO 27001 ensures sensitive data is protected through defined encryption standards and secure key management practices. Annex A.8.24 requires clear policies on algorithms, key sizes, and how encryption is implemented.

Keys must be generated securely, stored in HSMs or cloud KMS platforms, and protected with multi-factor authentication. Avoid hardcoding keys in applications. Rotate keys regularly, and immediately after any suspected compromise.

Secure Data Transfer and Storage Encryption

Data must be protected both in transit and at rest to prevent interception or unauthorized access. Encryption ensures confidentiality across systems, networks, and storage environments.

Use HTTPS/TLS with strong configurations for data in transit, and enforce encryption across APIs and endpoints. For data at rest, apply standards like AES-256 across databases, backups, and logs. Automation helps maintain consistency and reduce errors.

ISO 27001 Supplier Relationship Security

Supplier security ensures third parties do not become weak links in your security posture. ISO 27001 includes multiple controls to manage risks across the supplier lifecycle.

Controls A.5.19 to A.5.23 cover supplier relationships, agreements, ICT supply chains, monitoring, and cloud services. Organizations must define expectations, document requirements, and ensure suppliers meet security standards consistently.

Third-Party Risk Assessment and Monitoring

Third-party risk management focuses on evaluating, monitoring, and controlling supplier risks over time. Initial assessments ensure suppliers meet security expectations before engagement.

Ongoing monitoring and audits verify continued compliance. Contracts must clearly define access controls, data handling, and security responsibilities. Without continuous oversight, suppliers can quickly become a major security risk.

ISO 27001 2022 Updates to Annex A Controls

October 2022 reshaped ISO 27001, going beyond minor updates to restructure how organizations manage security. If you're on the 2013 version, you must revisit controls, documentation, and risk treatment.

Key Changes in Control Structure

The number of Annex A controls dropped from 114 to 93, but the structure became more streamlined and easier to use. The old 14 domains were consolidated into four: Organizational, People, Physical, and Technological.

Behind the scenes, several controls were merged, updated, or renamed to remove duplication and improve clarity. The result is a more practical framework that aligns better with how modern organizations operate and manage risk.

New and Revised Controls in ISO 27001:2022

The 2022 update introduced new controls focused on areas like cloud security, monitoring, and data protection, reflecting today's threat landscape.

  • A.5.7: Threat intelligence
  • A.5.23: Cloud services security
  • A.5.30: ICT continuity readiness
  • A.7.4: Physical security monitoring
  • A.8.9: Configuration management
  • A.8.10: Information deletion
  • A.8.11: Data masking
  • A.8.12: Data leakage prevention
  • A.8.16: Monitoring activities
  • A.8.23: Web filtering
  • A.8.28: Secure coding

These additions target gaps that were not fully addressed in earlier versions.

Mapping Old Controls to Updated Controls

Organizations transitioning from ISO 27001:2013 must remap all controls to the updated 2022 structure, as old references no longer align. Existing mappings become outdated and unreliable.

This impacts risk registers, policies, procedures, and supporting documentation. Every control must be reviewed, updated, and correctly mapped to maintain consistency, ensure proper risk treatment, and stay fully prepared for certification and transition audits.

Implications for Risk Assessment and Treatment

The risk assessment process remains unchanged, but the updated control set directly impacts how risks are evaluated and treated within your ISMS. Organizations must reassess how controls map to identified risks.

Your Statement of Applicability must be updated to reflect the new 93 controls. Without proper alignment, outdated mappings can lead to gaps in risk treatment and potential audit nonconformities.

Preparing Your ISMS for the Updated Standard

The transition deadline was October 31, 2025, after which ISO 27001:2013 certificates are no longer valid. Organizations must act to remain compliant.

This includes conducting gap assessments against the new controls, updating the Statement of Applicability, revising risk assessments, and aligning ISMS policies with the 2022 structure. Proper preparation ensures a smooth transition and avoids certification disruptions or audit failures.

Frequently Asked Questions

93 controls, organized into four themes: Organizational (37), People (8), Physical (14), and Technological (34). This replaced the 114 controls across 14 categories in the 2013 version.

Turning ISO 27001 Into Real Security

You don't need all 93 controls. You need the right controls for your risks. That's the core of ISO 27001, and where most organizations either overcomplicate things or completely miss what actually matters in practice today.

We've covered control categories, mandatory documents, risk frameworks, the certification process, and the 2022 updates. But compliance isn't about knowing the standard. It's about connecting risks to the right controls, and proving it with clear, consistent, auditable evidence that stands up during audits and real-world scenarios.

If you were on the 2013 version, the October 2025 deadline changed everything. Now it's about aligning your ISMS with the updated structure, running gap assessments, updating your Statement of Applicability, and fixing documentation gaps. This isn't just about certification. It's about protecting your data, systems, reputation, and the trust your customers place in you every day.

Strengthen your information security and stay audit-ready with UprootSecurity, making ISO 27001 compliance simple and practical. See how it fits together on our ISO 27001 compliance page.

→ Book a demo today

Part of

ISO 27001

Read the complete ISO 27001 guide
RJ

Robin Joseph

Senior Security Consultant

Keep reading

more from the team
ISO 27001 for Startups: Benefits, Process & Cost
Compliance·March 24, 2026

ISO 27001 for Startups: Benefits, Process & Cost

Read article→

Get the compliance playbook in your inbox.

One new playbook, checklist, or comparison guide every two weeks.

Real customer numbers and benchmarks, not vendor fluff.

First-look at new templates and calculators we ship.

14,200+ engineers subscribed · unsubscribe anytime · no third parties