The Ultimate ISO 27001 Controls Guide is the most comprehensive ISO 27001 reference guide there is. For the beginner, and the practitioner, this guide covers everything you need to know. Updated for the 2022 update with all the latest guidance and insider trade secrets that others simply do not want you to know.
In this ultimate guide to the ISO 27001 controls we are going to explore the security control requirements. We will go through the ISO 27001 controls, the old version of the ISO 27002:2013 controls and the new and updated ISO 27002:2022 control list. What controls do you need to implement? Let’s take a deep dive. I am Stuart Barker the ISO 27001 Lead Auditor and this is ISO 27001 Controls.
Table of contents
- Key Takeaways
- The 11 New ISO 27001:2022 Controls
- ISO 27001 Controls Overview
- The Difference Between Clauses and Controls
- ISO 27001:2022 Clauses
- ISO 27001 Clause 4 Context of Organisation
- ISO 27001 Clause 5 Leadership
- ISO 27001 Clause 6 Planning
- ISO 27001 Clause 7 Support
- ISO 27001 Clause 8 Operation
- ISO 27001 Clause 9 Performance Evaluation
- ISO 27001 Clause 10 Improvement
- ISO 27001:2022 Annex A 5: Organisational controls
- ISO 27001:2022 Annex A 6: People controls
- ISO 27001:2022 Annex A 7: Physical controls
- ISO 27001:2022 Annex A 8: Technological controls
- ISO 27001 Control Change Mapping
- FAQ
- About the author
Key Takeaways
The new ISO 27001:2022 controls are now in four pillars of information security. There are 93 controls that are logically grouped into 4 themes. This is a move from broad policy and governance to specific technical implementations. The four pillars are:
| Control Theme | Number of Controls | Description |
|---|---|---|
| Organisational Controls | 37 | Governance and operational security management frameworks. |
| People Controls | 8 | Security requirements relating to human resources and staff behaviour. |
| Physical Controls | 14 | Protection of physical assets, sites, and equipment. |
| Technological Controls | 34 | Technical security measures and digital safeguard implementations. |
The ISO/IEC 27001:2022 update introduced 11 new controls to Annex A, bringing the total to 93 (down from 114) after significant merging and restructuring. These controls are categorised into four themes: Organisational, People, Physical, and Technological.
The 11 New ISO 27001:2022 Controls
| Control Reference | Control Name | Key Security Objective |
|---|---|---|
| A.5.7 | Threat Intelligence | Gathering and analysing threat data to enable proactive security mitigation. |
| A.5.23 | Information Security for Use of Cloud Services | Managing security risks across the lifecycle of cloud service procurement and use. |
| A.5.30 | ICT Readiness for Business Continuity | Ensuring IT systems are resilient and prepared for significant operational disruptions. |
| A.7.4 | Physical Security Monitoring | Continuous monitoring of physical locations to detect and deter unauthorised access. |
| A.8.9 | Configuration Management | Standardising security settings for hardware and software to prevent vulnerabilities. |
| A.8.10 | Information Deletion | Securing the permanent removal of data when it is no longer required for use. |
| A.8.11 | Data Masking | Using pseudonymisation or anonymisation to limit exposure of sensitive information. |
| A.8.12 | Data Leakage Prevention | Detecting and preventing unauthorised extraction of sensitive data from the network. |
| A.8.16 | Monitoring Activities | Active oversight of systems and networks for anomalous behaviour or incidents. |
| A.8.23 | Web Filtering | Managing access to external websites to protect against malicious online content. |
| A.8.28 | Secure Coding | Applying security principles throughout the entire software development lifecycle. |
ISO 27001 Controls Overview
I like the controls because they are standard controls that are easy to implement. When you buy a copy of the standard they are all laid out. Let us take a look at the ISO 27001 controls checklist. I have summarised them in the table of contents for ease of navigation.
ISO 27001 is the international standard for information security. It has has a check list of ISO 27001 controls. These controls are set out in the ISO 27001 Annex A. Often referred to as ISO 27002.
| Standard Reference | Primary Purpose | Relationship to Annex A Controls | Further Information |
|---|---|---|---|
| ISO 27001:2022 | The certifiable international standard that defines the requirements for an Information Security Management System (ISMS). | Mandates the selection of security controls via a formal Risk Assessment, referenced in Annex A. | Essential Guide to ISO 27001:2022 |
| ISO 27002:2022 | A guidance standard designed to support the implementation of the controls found in ISO 27001 Annex A. | Provides the specific implementation guidance and technical details for each of the 93 controls. | Guide to ISO 27002 Controls |
We previously explored What is the difference between ISO 27001 and ISO 27002.
The Difference Between Clauses and Controls
| Feature | ISO 27001 Clauses (4-10) | ISO 27001 Annex A Controls |
|---|---|---|
| Primary Purpose | Defines the mandatory requirements for the Information Security Management System (ISMS) framework. | Provides a reference set of security safeguards to mitigate identified risks. |
| Function | Ensures the system is planned, managed, evaluated, and improved (governance). | Defines the technical, physical, and organisational implementation of security. |
| Mandatory Status | Mandatory: Every clause must be satisfied for certification. | Selective: Controls are chosen based on the results of a formal Risk Assessment. |
| Structure | Logically grouped into 7 main domains (Context, Leadership, Planning, etc.). | Grouped into 4 themes: Organisational, People, Physical, and Technological. |
ISO 27001:2022 Clauses
ISO 27001 is the standard that you certify against. It is a management framework. Let’s start with a look at the ISO 27001 information security management system controls. ISO 27001 is divided into clauses which act as domains or groups of related controls.
First lets look at each of the ISO 27001 clauses and how the break down.
| Clause | Focus Area | Core Implementation Requirements |
|---|---|---|
| 4 | Context of Organisation | Demonstrate an understanding of the organisation’s context, determine the ISMS scope, and identify the needs of interested parties. |
| 5 | Leadership | Evidence top-down commitment, establish the Information Security Policy, and document roles, responsibilities, and authorities. |
| 6 | Planning | Implement risk management processes including risk registers, assessments, and treatment plans alongside defined security objectives. |
| 7 | Support | Manage resources, competency, and security awareness. Document operating procedures and maintain control of documented information. |
| 8 | Operation | Execute operational planning and control, ensuring regular information security risk assessments and risk treatments are performed. |
| 9 | Performance Evaluation | Monitor and measure ISMS performance. Execute internal audits and conduct formal management reviews with structured agendas. |
| 10 | Improvement | Manage non-conformities and corrective actions to drive the foundation of continual improvement within the standard. |
ISO 27001 Clause 4 Context of Organisation
The context of organisation controls look at being able to show that you understand the organisation and its context. That you understand the needs and expectations of interested parties and that you have determining the scope of the information security management system.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 4.1 | Understanding the Organisation and its Context | Identifying internal and external issues relevant to the organisation’s purpose and its ability to achieve information security outcomes. |
| 4.2 | Understanding the Needs and Expectations of Interested Parties | Determining who the interested parties are and what requirements they have regarding information security. |
| 4.3 | Determining the Scope of the ISMS | Defining the boundaries and applicability of the Information Security Management System, considering internal/external issues and requirements. |
| 4.4 | Information Security Management System | Establishing, implementing, maintaining, and continually improving the ISMS in accordance with ISO 27001 requirements. |
ISO 27001 Clause 5 Leadership
ISO 27001 wants top down leadership and to be able to evidence leadership commitment. We require Information Security Policies that say what we do. We document the organisational roles and responsibilities.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 5.1 | Leadership and Commitment | Evidence of top-down commitment to the ISMS, ensuring resources are available and security is integrated into business processes. |
| 5.2 | Policy | Establishment of high-level Information Security Policies that define the organisation’s security direction and goals. |
| 5.3 | Organisational roles, responsibilities and authorities | Formal documentation and communication of security-related roles to ensure accountability across the organisation. |
ISO 27001 Clause 6 Planning
Planning addresses actions to address risks and opportunities. ISO 27001 is a risk based system so risk management is a key part, with risk registers and risk processes in place. We ensure that we have objectives and measure in place for the information security management system.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 6.1.1 | General Planning | Identifying risks and opportunities that need to be addressed to ensure the ISMS can achieve its intended outcomes. |
| 6.1.2 | Information Security Risk Assessment | Establishing and applying an information security risk assessment process that produces consistent, valid, and comparable results. |
| 6.1.3 | Information Security Risk Treatment | Defining a process to select appropriate risk treatment options and determining all controls necessary to implement the chosen options. |
| 6.2 | Information Security Objectives | Establishing measurable security objectives at relevant functions and levels, supported by a clear plan to achieve them. |
ISO 27001 Clause 7 Support
Education and awareness is put in place and a culture of security is implemented. A communication plan is created and followed. Resources are allocated and competency of resources is managed and understood. If it isn’t written down it does not exist so standard operating procedures are documented and documents are controlled.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 7.1 | Resources | Determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the ISMS. |
| 7.2 | Competence | Ensure that persons doing work under the organisation’s control that affects its information security performance are competent. |
| 7.3 | Awareness | Ensure persons doing work are aware of the information security policy and their contribution to the effectiveness of the ISMS. |
| 7.4 | Communication | Determine the internal and external communications relevant to the ISMS, including what, when, with whom and who shall communicate. |
| 7.5.1 | Documented Information – General | Ensure the ISMS includes documented information required by the standard and determined by the organisation as necessary. |
| 7.5.2 | Creating and Updating Documents | Ensure appropriate identification, description, format and review/approval of documented information. |
| 7.5.3 | Control of Documented Information | Ensure documented information is available, adequately protected, and controlled regarding distribution, storage, and versioning. |
ISO 27001 Clause 8 Operation
Operations are managed and controlled and risk assessments undertaken.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 8.1 | Operational planning and control | Executing the plans determined in Clause 6 to meet information security requirements, including documented control of outsourced processes. |
| 8.2 | Information security risk assessment | Performing information security risk assessments at planned intervals or when significant changes occur, ensuring valid and comparable results. |
| 8.3 | Information security risk treatment | Implementing the risk treatment plan as defined in the planning phase to ensure risks are reduced to an acceptable level. |
ISO 27001 Clause 9 Performance Evaluation
Monitors and measures as well as the processes of analysis and evaluation are implemented. As part of continual improvement audits are planned and executed, management reviews are undertaken following structured agendas.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 9.1 | Monitoring, measurement, analysis and evaluation | Determine what needs to be monitored, the methods for measurement, and when the results shall be analysed and evaluated. |
| 9.2 | Internal audit | Conduct internal audits at planned intervals to provide information on whether the ISMS conforms to requirements and is effectively implemented. |
| 9.2.1 | General Internal Audit | Establish the baseline for conformity to both the organisation’s requirements and the international standard. |
| 9.2.2 | Internal audit programme | Planning, establishing, implementing and maintaining an audit programme(s) including frequency, methods, and reporting. |
| 9.3 | Management review | Top management must review the organisation’s ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. |
| 9.3.1 | Management review – General | The structured execution of the review process to ensure the ISMS remains aligned with business goals. |
| 9.3.2 | Management review inputs | Collation of required data: audit results, feedback from interested parties, and status of risk assessments. |
| 9.3.3 | Management review results | Decisions and actions related to continual improvement and any needed changes to the ISMS. |
ISO 27001 Clause 10 Improvement
Improvement is a foundation of The ISO 27001 standard. The ability to adapt and continually improve. We are going to look at how we manage non conformities and corrective actions and our processes for managing continual improvement.
| Clause | Requirement Name | Description and Compliance Focus |
|---|---|---|
| 10.1 | Continual improvement | Demonstrating that the organisation continually improves the suitability, adequacy, and effectiveness of the ISMS. |
| 10.2 | Nonconformity and corrective action | Reacting to nonconformities by taking action to control, correct, and deal with consequences while eliminating the root cause. |
ISO 27001:2022 Annex A 5: Organisational controls
There are 37 organisational controls that establish a top down governance and operational framework for information security. These controls are related to policy, roles, asset management and supplier relationships. They form the strategic backbone of your information security posture.
| Control | Organisational Control Name | Requirement & Objective |
|---|---|---|
| 5.1 | Policies for information security | Ensure suitability, adequacy and effectiveness of management’s direction and support. |
| 5.2 | Information security roles and responsibilities | Establish a defined, approved and understood structure for ISMS operation. |
| 5.3 | Segregation of duties | Reduce risks of fraud, error and bypassing of information security controls. |
| 5.4 | Management responsibilities | Require all personnel to apply security in accordance with established policies. |
| 5.5 | Contact with authorities | Establish and maintain contact with relevant regulatory and legal authorities. |
| 5.6 | Contact with special interest groups | Ensure appropriate flow of security information via forums or associations. |
| 5.7 | Threat intelligence | Provide awareness of the threat environment to trigger appropriate mitigation. |
| 5.8 | Information security in project management | Address security risks throughout the project life cycle and deliverables. |
| 5.9 | Inventory of information and other associated assets | Identify assets to preserve security and assign appropriate ownership. |
| 5.10 | Acceptable use of information and assets | Identify, document and implement rules for handling and acceptable use. |
| 5.11 | Return of assets | Protect assets during changes or termination of employment and contracts. |
| 5.12 | Classification of information | Understand protection needs based on the information’s importance. |
| 5.13 | Labelling of information | Facilitate communication of classification and support management automation. |
| 5.14 | Information transfer | Maintain security of information transferred internally or to external parties. |
| 5.15 | Access control | Prevent unauthorised access to information and associated assets. |
| 5.16 | Identity management | Unique identification of entities to enable appropriate access rights assignment. |
| 5.17 | Authentication information | Ensure proper entity authentication and prevent process failures. |
| 5.18 | Access rights | Define and authorise access according to business requirements. |
| 5.19 | Information security in supplier relationships | Maintain an agreed level of security across the external supply base. |
| 5.20 | Security within supplier agreements | Codify security requirements into formal third-party contracts. |
| 5.21 | Managing security in the ICT supply chain | Address security across the complex ICT technology provider network. |
| 5.22 | Review and change of supplier services | Maintain security delivery in line with agreed supplier terms. |
| 5.23 | Security for use of cloud services | Specify and manage security for the adoption of cloud-based technology. |
| 5.24 | Incident management planning | Ensure quick, effective and orderly response to security incidents. |
| 5.25 | Assessment of security events | Ensure effective categorisation and prioritisation of security events. |
| 5.26 | Response to security incidents | Ensure efficient and effective response to confirmed incidents. |
| 5.27 | Learning from security incidents | Reduce the likelihood or consequences of future security breaches. |
| 5.28 | Collection of evidence | Maintain consistent management of evidence for legal or disciplinary action. |
| 5.29 | Information security during disruption | Protect information and associated assets during business interruptions. |
| 5.30 | ICT readiness for business continuity | Ensure asset availability during significant service disruption. |
| 5.31 | Identification of legal requirements | Ensure compliance with all security-related legal and contractual mandates. |
| 5.32 | Intellectual property rights | Ensure compliance with requirements related to IP and proprietary products. |
| 5.33 | Protection of records | Ensure compliance with expectations related to record protection and availability. |
| 5.34 | Privacy and protection of PII | Ensure compliance with legal requirements related to personal data protection. |
| 5.35 | Independent review of information security | Ensure continuing suitability and effectiveness of the management approach. |
| 5.36 | Compliance with policies and standards | Operate in accordance with organisational policies and security standards. |
| 5.37 | Documented operating procedures | Ensure the correct and secure operation of information processing facilities. |
ISO 27001:2022 Annex A 6: People controls
There are 8 controls focussed purely on people and managing the human factors throughout the employment of the information security lifecycle. Security is a human responsibility and these controls cover pre-employment screening to security awareness training and post employment responsibilities.
| Control No. | People Control Name | Requirement & Objective |
|---|---|---|
| 6.1 | Screening | Ensure all personnel are eligible and suitable for the roles for which they are considered and remain eligible and suitable during their employment. |
| 6.2 | Terms and conditions of employment | Ensure personnel understand their information security responsibilities for the roles for which they are considered. |
| 6.3 | Information security awareness, education and training | Ensure personnel and relevant interested parties are aware of and fulfil their information security responsibilities. |
| 6.4 | Disciplinary process | Ensure personnel and other relevant interested parties understand the consequences of information security policy violation, to deter and appropriately deal with personnel and other relevant interested parties who committed the violation. |
| 6.5 | Responsibilities after termination or change of employment | Protect the organisation’s interests as part of the process of changing or terminating employment or contracts. |
| 6.6 | Confidentiality or non-disclosure agreements | Maintain confidentiality of information accessible by personnel or external parties. |
| 6.7 | Remote working (New) | Ensure the security of information when personnel are working remotely. |
| 6.8 | Information security event reporting | Support timely, consistent and effective reporting of information security events that can be identified by personnel. |
ISO 27001:2022 Annex A 7: Physical controls
There are 14 controls focussed on preventing unauthorised physical access, damage and interference. They cover the protection of the physical environment from security perimeters and entry controls to the secure siting, maintenance and disposal of equipment.
| Control No. | Physical Control Name | Requirement & Objective |
|---|---|---|
| 7.1 | Physical security perimeter | Ensure physical security is in place to stop unauthorised individuals from gaining physical access to property and assets. |
| 7.2 | Physical entry controls | Protect secure areas with defined access points and robust entry control mechanisms. |
| 7.3 | Securing offices, rooms and facilities | Prevent unauthorised physical access, damage and interference to the organisation’s information and associated assets. |
| 7.4 | Physical security monitoring | Utilise perimeters and monitoring to protect offices and information processing facilities. |
| 7.5 | Protecting against physical and environmental threats | Prevent or reduce the consequences of events originating from physical and environmental threats. |
| 7.6 | Working in secure areas | Protect information in secure areas from damage and unauthorised interference by personnel working in these areas. |
| 7.7 | Clear desk and clear screen | Address risks of unauthorised access, loss of or damage to information on desks and screens during and outside normal working hours. |
| 7.8 | Equipment siting and protection | Reduce risks from physical and environmental threats, and from unauthorised access and damage. |
| 7.9 | Security of assets off-premises | Protect equipment by siting it securely and ensuring it is adequately protected when away from the site. |
| 7.10 | Storage media (New) | Ensure storage media is protected throughout its lifecycle against unauthorised access or compromise. |
| 7.11 | Supporting utilities | Prevent loss or interruption to operations due to the failure or disruption of supporting utilities such as power and cooling. |
| 7.12 | Cabling security | Prevent damage, theft or compromise of information assets and interruption to operations related to power and communications cabling. |
| 7.13 | Equipment maintenance | Prevent loss, damage or compromise caused by a lack of maintenance on equipment and information assets. |
| 7.14 | Secure disposal or re-use of equipment | Prevent information leakage from equipment that is intended to be disposed of or re-used. |
ISO 27001:2022 Annex A 8: Technological controls
There are 34 controls focussed on technology.The controls are the technical blueprint that cover access control, malware protection, logging, secure development and network security. In the 2022 update to the standard new controls were introduced:
| Control | Technological Control Name | Requirement & Objective |
|---|---|---|
| 8.1 | User endpoint devices (New) | Protect information against the risks introduced by using user endpoint devices. |
| 8.2 | Privileged access rights | Ensure only authorised users, software components and services are provided with privileged access rights. |
| 8.3 | Information access restriction | Ensure only authorised access and to prevent unauthorised access to information and other associated assets. |
| 8.4 | Access to source code | Prevent the introduction of unauthorised functionality, avoid unintentional or malicious changes and to maintain the confidentiality of valuable intellectual property. |
| 8.5 | Secure authentication | Ensure a user or an entity is securely authenticated, when access to systems, applications and services is granted. |
| 8.6 | Capacity management | Ensure the required capacity of information processing facilities, human resources, offices and other facilities. |
| 8.7 | Protection against malware | Ensure information and other associated assets are protected against malware. |
| 8.8 | Management of technical vulnerabilities | Ensure information and other associated assets are protected from the exploitation of technical vulnerabilities. |
| 8.9 | Configuration management | Ensure hardware, software, services and networks function correctly with required security settings, and configuration is not altered by unauthorised or incorrect changes. |
| 8.10 | Information deletion (New) | Make sure you are deleting data when it is no longer required in a way that it cannot be recovered. |
| 8.11 | Data masking (New) | Ensure you limit the exposure of sensitive data including PII, and you comply with legal, statutory, regulatory and contractual requirements. |
| 8.12 | Data leakage prevention (New) | Detect and prevent the unauthorised disclosure and extraction of information by individuals or systems. |
| 8.13 | Information backup | Enable recovery from loss of data or systems. |
| 8.14 | Redundancy of information processing facilities | Ensures the continuous operation of information processing facilities. |
| 8.15 | Logging | Record events, generate evidence, ensure the integrity of log information, and identify security events to support investigations. |
| 8.16 | Monitoring activities | Detect anomalous behaviour and potential information security incidents. |
| 8.17 | Clock synchronisation | Enable the correlation and analysis of security-related events and support incident investigations. |
| 8.18 | Use of privileged utility programs | Ensure the use of utility programmes does not harm system and application controls. |
| 8.19 | Installation of software on operational systems | Ensure the integrity of operational systems and prevent exploitation of technical vulnerabilities. |
| 8.20 | Network controls | Protect information in networks and supporting facilities from compromise via the network. |
| 8.21 | Security of network services | Ensure security in the use of network services. |
| 8.22 | Segregation in networks | Split the network into security boundaries and control traffic based on business needs. |
| 8.23 | Web filtering (New) | Protect systems from being compromised by malware and prevent access to unauthorised web resources. |
| 8.24 | Use of cryptography | Ensure proper use of cryptography to protect confidentiality, authenticity or integrity according to requirements. |
| 8.25 | Secure development lifecycle | Ensure information security is designed and implemented within the secure development life cycle. |
| 8.26 | Application security requirements (New) | Ensure all security requirements are identified and addressed when developing or acquiring applications. |
| 8.27 | Secure system architecture and engineering principles (New) | Ensure information systems are securely designed, implemented and operated within the development life cycle. |
| 8.28 | Secure Coding | Ensure software is written securely to reduce potential information security vulnerabilities. |
| 8.29 | Security testing in development and acceptance | Validate if information security requirements are met when applications or code are deployed. |
| 8.30 | Outsourced development | Ensure measures required by the organisation are implemented in outsourced system development. |
| 8.31 | Separation of development, test and production environments | Protect the production environment and data from compromise by development and test activities. |
| 8.32 | Change management | Preserve information security when executing changes. |
| 8.33 | Test information | Ensure relevance of testing and protection of operational information used for testing. |
| 8.34 | Protection of information systems during audit and testing (New) | Minimise the impact of audit and other assurance activities on operational systems. |
ISO 27001 Control Change Mapping
| ISO/IEC 27001:2022 | ISO/IEC 27001:2013 |
|---|---|
| Clause 4: Context of the Organisation | Clause 4: Context of the Organisation |
| Clause 4.1 Understanding the organisation and its context | Clause 4.1 Understanding the organisation and its context |
| Clause 4.2 Understanding the needs and expectations of interested parties | Clause 4.2 Understanding the needs and expectations of interested parties |
| Clause 4.3 Determining the scope of the ISMS | Clause 4.3 Determining the scope of the ISMS |
| Clause 4.4 Information security management system | Clause 4.4 Information security management system |
| Clause 5: Leadership | Clause 5: Leadership |
| Clause 5.1 Leadership and commitment | Clause 5.1 Leadership and commitment |
| Clause 5.2 Policy | Clause 5.2 Policy |
| Clause 5.3 Organisational roles, responsibilities and authorities | Clause 5.3 Organizational roles, responsibilities and authorities |
| Clause 6: Planning | Clause 6: Planning |
| Clause 6.1 Actions to address risks and opportunities | Clause 6.1 Actions to address risks and opportunities |
| Clause 6.3 Planning of Changes | NEW |
| Clause 7: Support | Clause 7: Support |
| Clause 7.5 Documented information | Clause 7.5 Documented information |
| Clause 8: Operation | Clause 8: Operation |
| Clause 8.1 Operational planning and control | Clause 8.1 Operational planning and control |
| Clause 9: Performance Evaluation | Clause 9: Performance Evaluation |
| Clause 9.2.1 General & 9.2.2 Internal audit programme | NEW (Restructured) |
| Clause 9.3.1, 9.3.2, 9.3.3 Management Review | NEW (Restructured) |
| Clause 10: Improvement | Clause 10: Improvement |
| Clause 10.1 Continual improvement | Clause 10.2 Continual improvement |
| Annex A Information security controls reference | ISO 27002:2022 updated control set |
FAQ
Yes. If it is not written down it does not exist. Even though you are doing great things you will have to document what you do and be able to provide evidence that you do it. Sorry.
Using a word processor and a spreadsheet. You can consider a portal or web based application but the cheapest, simplest, fastest and most flexible approach for an SME business is basic office applications. You already know how to use them and you already own them.
Yes, you can save the ISO 27001 controls spreadsheet that comes as part of our implementation in PDF format.
Yes. They are an Annex to the ISO 27001 standard.
ISO 27002 is a guidance standard to ISO 27001 Annex A. ISO 27002 sets out each control with implementation guidance for you to consider when implementing the control. ISO 27002 was updated in 2022 and is officially called ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information
security controls
There are 93 controls in ISO 27001:2022.
There are 93 controls in ISO 27002:2022.
The ISO 27001:2022 Annex A controls are not mandatory but they are a list of controls that commonly mitigate information security risks. Once you have conducted your information security risk assessment you will pick the controls from ISO 27001 Annex A that mitigate risk. In addition you will review client requirements and legal and regulatory requirements to ensure that any controls required are also included.
Yes. They are summarised here and you should purchase a copy of the standard for the details. The checklist forms part of our deliverables.
Yes. This is included in our ISO 27001 implementation.
There are 114 controls in ISO 27002:2013.
There are 114 controls in ISO 27001:2013.
Yes, if you are operating the 2013 version of the standard. Or a good reason why you don’t. In reality they are not mandatory so don’t have them for the sake of it. If you don’t have them or need them just document why. Remember this is an international standard based on best practice and years of refinement. We find software development is usually the one that gets left out, for those that don’t do software development of course.
The actual list of controls is in the ISO 27001 standard which you should purchase.
ISO 27001 Annex A is broken down into 4 control domains. These domains group together controls into logical domains.
ISO 27001:2022 Annex A 5 Organisational controls
ISO 27001:2022 Annex A 6 People controls
ISO 27001:2022 Annex A 7 Physical controls
ISO 27001:2022 Annex A 8 Technological controls

