ISO/IEC 27001:2022 at a Glance

ISO/IEC 27001:2022 is the internationally recognized standard for Information Security Management Systems (ISMS). It provides a systematic approach to managing sensitive information, ensuring its confidentiality, integrity, and availability through a risk management process. The 2022 revision modernized the Annex A controls, restructuring them from 14 categories into 4 streamlined themes with 93 controls, and introduced new controls for threat intelligence, cloud security, data masking, and more. Certification is achieved through accredited third-party audits and is valid for 3 years with annual surveillance audits.

93
Annex A Controls
4
Control Themes
7
ISMS Clauses
2022
Current Version

The Four Annex A Themes

ISO 27001:2022 restructured the Annex A controls from 14 categories into 4 streamlined themes. These cover organizational governance, people security, physical protection, and technological safeguards.

🏢

A.5 Organizational Controls (37)

Controls addressing organizational aspects of information security including policies, roles, threat intelligence, asset management, access control, supplier management, incident management, business continuity, and compliance. The largest theme covering governance and process controls.

37 Controls
👥

A.6 People Controls (8)

Controls related to human resources security — screening, terms of employment, awareness training, disciplinary process, responsibilities after termination, confidentiality agreements, and remote working.

8 Controls
🏣

A.7 Physical Controls (14)

Controls for physical and environmental security — security perimeters, physical entry controls, securing offices/rooms/facilities, monitoring, protecting against physical/environmental threats, equipment security, storage media, utilities, cabling, and maintenance.

14 Controls
💻

A.8 Technological Controls (34)

Technical controls including endpoint devices, privileged access, information access restriction, source code, authentication, capacity management, malware protection, vulnerability management, configuration management, data deletion, data masking, DLP, monitoring, network security, web filtering, cryptography, secure development, testing, change management, and cloud services.

34 Controls

Why Should a Security Engineer Care?

The Global Gold Standard

ISO 27001 is recognized worldwide as THE information security certification. It's referenced by regulations (NIS2, DORA), contractual requirements, and industry standards across all sectors.

Risk-Based Approach

Unlike prescriptive frameworks, ISO 27001 lets you choose controls based on your risk assessment. The Statement of Applicability (SoA) documents which of the 93 controls apply and how they're implemented.

2022 Modernization

The latest revision added 11 new controls for modern threats: threat intelligence (A.5.7), cloud security (A.5.23), ICT readiness for business continuity (A.5.30), data masking (A.8.11), DLP (A.8.12), monitoring (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).

Builds Regulatory Compliance

Implementing ISO 27001 provides 70-80% coverage of NIS2 Art. 21 measures, strong alignment with DORA requirements, and maps directly to NIST CSF and BSI IT-Grundschutz. It's the foundation for multi-framework compliance.

ISO 27001 vs. Other Frameworks

AspectISO 27001NIST CSFBSI IT-GrundschutzNIS2
TypeVoluntary international standardVoluntary frameworkNational standard (Germany)EU Directive (binding)
ScopeAny organization, any sectorAny organizationGerman government & critical infra18 critical sectors in EU
CertificationYes — accredited 3rd-party auditNo formal certificationYes — BSI certificationNo — regulatory compliance
Controls93 controls in 4 themes6 functions, 22 categories~900+ Bausteine & measures10 mandatory measures
Risk ApproachRisk-based with SoARisk-based tiersPrescriptive + risk analysisAll-hazards, proportionate
Update CyclePeriodic revision (~10 years)Periodic (CSF 2.0 in 2024)Continuous updatesFixed — Commission review

The Four Annex A Themes — Deep Dive

Select a theme from the sidebar or filter below to focus on a specific domain.

A.5 Organizational Controls (37 Controls)

Controls addressing organizational aspects of information security including policies, roles, threat intelligence, asset management, access control, supplier management, incident management, business continuity, and compliance. The largest theme covering governance and process controls.

All Organizational Controls

Click any row for detailed context, obligations, and external references.

ControlTitleDescriptionNew
A.5.1Policies for information securitySet of information security policies, approved by management
A.5.2Information security roles & responsibilitiesDefined and allocated roles
A.5.3Segregation of dutiesConflicting duties separated
A.5.4Management responsibilitiesManagement requires personnel compliance
A.5.5Contact with authoritiesEstablish contact with relevant authorities
A.5.6Contact with special interest groupsEstablish contact with security forums and associations
A.5.7Threat intelligenceCollect and analyze threat intelligenceYES
A.5.8Info sec in project managementIntegrate info sec into project management
A.5.9Inventory of information and assetsMaintain inventory of information and associated assets
A.5.10Acceptable use of information and assetsRules for acceptable use
A.5.11Return of assetsReturn assets upon termination
A.5.12Classification of informationClassify information per business needs
A.5.13Labelling of informationLabelling procedures for classified info
A.5.14Information transferRules for information transfer
A.5.15Access controlRules for access based on business/security needs
A.5.16Identity managementManage full lifecycle of identities
A.5.17Authentication informationControl allocation/management of authentication info
A.5.18Access rightsProvision/review/revoke access rights
A.5.19Info sec in supplier relationshipsDefine processes for managing supplier risks
A.5.20Addressing info sec in supplier agreementsEstablish requirements in agreements
A.5.21Managing info sec in ICT supply chainDefine processes for ICT supply chain
A.5.22Monitoring/review/change of supplier servicesMonitor and review supplier services
A.5.23Info sec for cloud servicesManage security for cloud service useYES
A.5.24Incident management planning & preparationPlan and prepare for incident management
A.5.25Assessment & decision on info sec eventsAssess events and decide if they are incidents
A.5.26Response to info sec incidentsRespond according to documented procedures
A.5.27Learning from info sec incidentsUse incident knowledge to strengthen controls
A.5.28Collection of evidenceEstablish procedures for evidence collection
A.5.29Info sec during disruptionMaintain info sec during disruption
A.5.30ICT readiness for business continuityPlan ICT readiness based on BIA and continuity requirementsYES
A.5.31Legal, statutory, regulatory & contractual reqsIdentify and document requirements
A.5.32Intellectual property rightsProtect IPR
A.5.33Protection of recordsProtect records from loss, destruction, falsification
A.5.34Privacy and protection of PIIMeet privacy requirements
A.5.35Independent review of info secReview the ISMS independently
A.5.36Compliance with policies, rules & standardsEnsure compliance
A.5.37Documented operating proceduresDocument operating procedures
Security Engineer Takeaway: The organizational controls are the backbone of your ISMS. Key additions in 2022: Threat Intelligence (A.5.7) formalizes what many SOCs already do but now requires documented processes. Cloud Security (A.5.23) finally gets its own control — assess cloud service provider risks and establish cloud-specific policies. ICT Readiness for Business Continuity (A.5.30) goes beyond traditional BCP by specifically addressing ICT readiness based on business impact analysis.

A.6 People Controls (8 Controls)

Controls related to human resources security throughout the employment lifecycle — from screening and onboarding through employment to termination. Also addresses awareness, training, and remote working.

All People Controls

Click any row for detailed context, obligations, and external references.

ControlTitleDescriptionNew
A.6.1ScreeningBackground verification checks
A.6.2Terms and conditions of employmentState info sec responsibilities
A.6.3Info sec awareness, education & trainingAll personnel receive awareness training
A.6.4Disciplinary processFormalize process for info sec violations
A.6.5Responsibilities after termination or changeDefine responsibilities that remain valid
A.6.6Confidentiality or non-disclosure agreementsIdentify and document confidentiality needs
A.6.7Remote workingSecurity measures for remote working
A.6.8Info sec event reportingMechanism for personnel to report events
Security Engineer Takeaway: People controls are often the weakest link. A.6.3 (awareness training) maps directly to NIS2 Art. 21(2)(g). A.6.7 (remote working) was updated in 2022 to reflect the post-pandemic reality. A.6.8 gives you the internal reporting channel needed to feed your incident management process.

A.7 Physical Controls (14 Controls)

Controls for physical and environmental security of facilities, offices, equipment, and storage media. These protect against unauthorized physical access, damage, and interference with business operations.

All Physical Controls

Click any row for detailed context, obligations, and external references.

ControlTitleDescriptionNew
A.7.1Physical security perimetersDefine security perimeters
A.7.2Physical entrySecure areas by entry controls
A.7.3Securing offices, rooms & facilitiesDesign and apply physical security
A.7.4Physical security monitoringMonitor premises for unauthorized accessYES
A.7.5Protecting against physical & environmental threatsDesign protection against threats
A.7.6Working in secure areasSecurity measures for working in secure areas
A.7.7Clear desk and clear screenRules for desks and screens
A.7.8Equipment siting and protectionSite and protect equipment
A.7.9Security of assets off-premisesProtect off-premises assets
A.7.10Storage mediaManage storage media lifecycle
A.7.11Supporting utilitiesProtect against power/utility failures
A.7.12Cabling securityProtect cabling from damage/interception
A.7.13Equipment maintenanceMaintain equipment for availability/integrity
A.7.14Secure disposal or re-use of equipmentVerify data removal before disposal
Security Engineer Takeaway: Physical controls are often overlooked by security engineers focused on technical controls. A.7.4 (physical security monitoring) is new in 2022 — it requires continuous monitoring of premises, not just access control. Maps to BSI INF layer modules.

A.8 Technological Controls (34 Controls)

Technical controls covering endpoints, access, authentication, malware, vulnerabilities, network security, cryptography, secure development, and more. The second-largest theme and where security engineers spend most of their time.

All Technological Controls

Click any row for detailed context, obligations, and external references.

ControlTitleDescriptionNew
A.8.1User endpoint devicesProtect information on endpoint devices
A.8.2Privileged access rightsRestrict and manage privileged access
A.8.3Information access restrictionRestrict access based on access control policy
A.8.4Access to source codeManage access to source code and development tools
A.8.5Secure authenticationApply secure authentication technologies
A.8.6Capacity managementMonitor and adjust capacity
A.8.7Protection against malwareImplement malware protection
A.8.8Management of technical vulnerabilitiesObtain info about vulnerabilities and take action
A.8.9Configuration managementManage configurations of hardware, software, services, networksYES
A.8.10Information deletionDelete information when no longer neededYES
A.8.11Data maskingUse data masking per access control policy and business needsYES
A.8.12Data leakage preventionApply DLP measures to systems/networks with sensitive infoYES
A.8.13Information backupMaintain and regularly test backup copies
A.8.14Redundancy of info processing facilitiesImplement redundancy for availability
A.8.15LoggingProduce, store, protect, and analyze logs
A.8.16Monitoring activitiesMonitor networks, systems, and applications for anomalous behaviorYES
A.8.17Clock synchronizationSynchronize clocks to approved time sources
A.8.18Use of privileged utility programsRestrict and control use of privileged utilities
A.8.19Installation of software on operational systemsControl software installation
A.8.20Networks securitySecure and control networks
A.8.21Security of network servicesIdentify and implement security for network services
A.8.22Segregation of networksSegregate networks into groups
A.8.23Web filteringManage access to external websites to reduce exposureYES
A.8.24Use of cryptographyDefine and implement rules for cryptography
A.8.25Secure development life cycleEstablish rules for secure development
A.8.26Application security requirementsIdentify and specify security requirements for applications
A.8.27Secure system architecture & engineeringApply secure design principles
A.8.28Secure codingApply secure coding principles in developmentYES
A.8.29Security testing in dev & acceptanceDefine and implement security testing
A.8.30Outsourced developmentDirect and monitor outsourced development
A.8.31Separation of dev, test & productionSeparate and secure environments
A.8.32Change managementSubject changes to change management procedures
A.8.33Test informationSelect, protect, and manage test information
A.8.34Protection of info systems during audit testingPlan and agree audit tests to minimize disruption
Security Engineer Takeaway: The technological controls are where security engineers spend most of their time. Key 2022 additions: Configuration Management (A.8.9) — formalize your hardening baselines. Data Masking (A.8.11) and DLP (A.8.12) — finally recognized as standalone controls. Monitoring (A.8.16) — continuous anomaly detection is now explicitly required (maps to NIS2 and DORA detection requirements). Web Filtering (A.8.23) — control outbound web access. Secure Coding (A.8.28) — secure development practices are no longer just recommended, they're a control.

Control Explorer

All 93 Annex A controls, grouped by theme. Click to expand details, implementation guidance, and practical security notes.

A.5 — Organizational Controls

A.5.1 Policies for information security Critical ▶

A set of information security policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties.

Implementation Guidance

  • Define a top-level information security policy and supporting topic-specific policies
  • Ensure policies are approved by top management or delegated authority
  • Communicate policies to all relevant personnel and interested parties
  • Review policies at planned intervals or when significant changes occur

Framework Mapping

  • NIS2: Art. 21(2)(a) — Risk analysis & IS policies
  • NIST CSF: GV.PO — Policy
  • DORA: Art. 6 — ICT risk management framework
Security Engineer Takeaway: This is the foundation control. Without documented, approved policies, nothing else has authority. Key: policies must be living documents, not shelf-ware. Review at least annually or after significant incidents/changes.
A.5.2 Information security roles & responsibilities Important ▶

Information security roles and responsibilities shall be defined and allocated.

Implementation Guidance

  • Define roles such as CISO, security architects, risk owners, asset owners
  • Document responsibilities in job descriptions and RACI matrices
  • Ensure roles are allocated to specific individuals or teams
Security Engineer Takeaway: Unclear roles cause gaps. Define who owns risk decisions, who responds to incidents, who manages access. Map to your org chart.
A.5.3 Segregation of duties Important ▶

Conflicting duties and conflicting areas of responsibility shall be segregated.

Implementation Guidance

  • Identify duties that create conflicts of interest if combined
  • Separate authorization, execution, and verification functions
  • Where segregation is not possible, implement compensating controls (monitoring, audit trails)
A.5.4 Management responsibilities Standard ▶

Management shall require all personnel to apply information security in accordance with the established policies and procedures.

A.5.5 Contact with authorities Standard ▶

Appropriate contacts with relevant authorities shall be maintained.

Implementation Guidance

  • Maintain contact details for law enforcement, regulators, CSIRTs
  • Under NIS2: know your national CSIRT for incident reporting
A.5.6 Contact with special interest groups Standard ▶

Appropriate contacts with special interest groups or other specialist security forums and professional associations shall be maintained.

A.5.7 Threat intelligence Critical NEW ▶

Information relating to information security threats shall be collected and analysed to produce threat intelligence.

Implementation Guidance

  • Establish processes to collect threat information from multiple sources (ISACs, CERT feeds, vendor advisories)
  • Analyse threats at strategic, tactical, and operational levels
  • Feed threat intelligence into risk assessment and control selection
  • Share threat information with relevant parties per TLP markings

Framework Mapping

  • NIS2: Art. 29 — Information sharing arrangements
  • NIST CSF: ID.RA — Risk Assessment
  • MITRE ATT&CK: Threat-informed defense
Security Engineer Takeaway: New in 2022. Formalizes what mature SOCs already do. You need documented processes for CTI collection, analysis, and dissemination. Subscribe to relevant feeds (sector ISACs, CERT advisories), integrate with SIEM/SOAR, and use STIX/TAXII for structured sharing.
A.5.8 Information security in project management Standard ▶

Information security shall be integrated into project management.

A.5.9 Inventory of information and associated assets Critical ▶

An inventory of information and other associated assets, including owners, shall be identified and maintained.

Implementation Guidance

  • Maintain a comprehensive asset inventory (hardware, software, data, services, cloud resources)
  • Assign owners to each asset
  • Classify assets by criticality and sensitivity
  • Review and update regularly
Security Engineer Takeaway: You cannot protect what you don't know about. This feeds your risk assessment. Use your CMDB, cloud asset discovery tools, and network scans to maintain an up-to-date inventory.
A.5.10 Acceptable use of information and assets Important ▶

Rules for the acceptable use of information and other associated assets shall be identified, documented, and implemented.

A.5.11 Return of assets Standard ▶

Personnel and other interested parties shall return all organizational assets in their possession upon change or termination of employment, contract, or agreement.

A.5.12 Classification of information Important ▶

Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability, and relevant interested party requirements.

A.5.13 Labelling of information Standard ▶

An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme.

A.5.14 Information transfer Important ▶

Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.

A.5.15 Access control Critical ▶

Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.

Implementation Guidance

  • Define access control policy based on least privilege and need-to-know
  • Cover both physical and logical access
  • Consider role-based access control (RBAC) or attribute-based (ABAC)
  • Document and review regularly

Framework Mapping

  • NIS2: Art. 21(2)(i) — HR security, access control, asset management
  • NIST CSF: PR.AC — Access Control
Security Engineer Takeaway: Access control is foundational. Implement least privilege, enforce MFA, and conduct quarterly access reviews. This control is the policy backbone; A.8.2-A.8.5 are the technical implementation.
A.5.16 Identity management Important ▶

The full lifecycle of identities shall be managed.

Implementation Guidance

  • Manage identities from creation through modification to deletion
  • Ensure unique identifiers for all users
  • Integrate with HR processes for joiner/mover/leaver workflows
A.5.17 Authentication information Important ▶

Allocation and management of authentication information shall be controlled by a management process including advising personnel on appropriate handling.

A.5.18 Access rights Important ▶

Access rights to information and other associated assets shall be provisioned, reviewed, modified, and removed in a timely manner.

A.5.19 Information security in supplier relationships Critical ▶

Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier's products or services.

Implementation Guidance

  • Identify and document all suppliers with access to organizational information
  • Assess supplier security posture before engagement
  • Define minimum security requirements for suppliers
  • Maintain a supplier register with risk ratings

Framework Mapping

  • NIS2: Art. 21(2)(d) — Supply chain security
  • DORA: Art. 28-30 — ICT third-party risk management
Security Engineer Takeaway: Supply chain attacks are a top threat vector. This control, with A.5.20-A.5.22, forms a complete supplier security framework that maps well to NIS2 and DORA third-party requirements.
A.5.20 Addressing info sec in supplier agreements Important ▶

Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.

A.5.21 Managing info sec in the ICT supply chain Important ▶

Processes and procedures shall be defined and implemented for managing the information security risks associated with the ICT products and services supply chain.

A.5.22 Monitoring, review & change management of supplier services Important ▶

The organization shall regularly monitor, review, evaluate, and manage change in supplier information security practices and service delivery.

A.5.23 Information security for use of cloud services Critical NEW ▶

Processes for acquisition, use, management, and exit from cloud services shall be established in accordance with the organization's information security requirements.

Implementation Guidance

  • Define cloud security policy covering all service models (IaaS, PaaS, SaaS)
  • Assess cloud provider security (certifications, SOC 2, shared responsibility model)
  • Implement cloud-specific controls: identity federation, encryption, monitoring
  • Plan for cloud exit and data portability
  • Address data residency and sovereignty requirements

Framework Mapping

  • ISO 27017 — Cloud security controls
  • ISO 27018 — PII protection in cloud
  • DORA: Art. 28-30 — Third-party ICT provider requirements
Security Engineer Takeaway: New in 2022. Finally a dedicated cloud security control. Key: understand the shared responsibility model for each provider. Ensure your SoA addresses cloud-specific risks. Map to CSA CCM or ISO 27017 for detailed cloud controls.
A.5.24 Incident management planning & preparation Critical ▶

The organization shall plan and prepare for managing information security incidents by defining, establishing, and communicating incident management processes, roles, and responsibilities.

Framework Mapping

  • NIS2: Art. 21(2)(b) — Incident handling
  • DORA: Art. 17 — ICT-related incident management process
Security Engineer Takeaway: Your IR plan is only as good as your last test. Conduct tabletop exercises quarterly and live exercises annually. Ensure NIS2/DORA reporting timelines are embedded in your playbooks.
A.5.25 Assessment & decision on information security events Important ▶

The organization shall assess information security events and decide if they are to be categorized as information security incidents.

A.5.26 Response to information security incidents Important ▶

Information security incidents shall be responded to in accordance with the documented procedures.

A.5.27 Learning from information security incidents Important ▶

Knowledge gained from information security incidents shall be used to strengthen and improve the information security controls.

A.5.28 Collection of evidence Standard ▶

The organization shall establish and implement procedures for the identification, collection, acquisition, and preservation of evidence related to information security events.

A.5.29 Information security during disruption Important ▶

The organization shall plan how to maintain information security at an appropriate level during disruption.

A.5.30 ICT readiness for business continuity Critical NEW ▶

ICT readiness shall be planned, implemented, maintained, and tested based on business continuity objectives and ICT continuity requirements.

Implementation Guidance

  • Conduct business impact analysis (BIA) to identify ICT dependencies
  • Define RTO and RPO for critical systems
  • Implement and test disaster recovery plans for ICT
  • Ensure backup and restoration processes are verified

Framework Mapping

  • NIS2: Art. 21(2)(c) — Business continuity & crisis management
  • DORA: Art. 11-12 — Business continuity & DR
  • ISO 22301 — Business continuity management
Security Engineer Takeaway: New in 2022. Goes beyond traditional BCP by specifically focusing on ICT readiness. Test your DR plans for ransomware scenarios where all primary systems are unavailable. Can you restore from backups in your defined RTO?
A.5.31 Legal, statutory, regulatory & contractual requirements Important ▶

Legal, statutory, regulatory, and contractual requirements relevant to information security and the organization's approach to meeting these requirements shall be identified, documented, and kept up to date.

A.5.32 Intellectual property rights Standard ▶

The organization shall implement appropriate procedures to protect intellectual property rights.

A.5.33 Protection of records Standard ▶

Records shall be protected from loss, destruction, falsification, unauthorized access, and unauthorized release.

A.5.34 Privacy and protection of PII Important ▶

The organization shall identify and meet the requirements regarding the preservation of privacy and protection of PII as required by applicable legislation, regulations, and contractual requirements.

Framework Mapping

  • GDPR: Art. 32 — Security of processing
  • ISO 27701 — Privacy information management
A.5.35 Independent review of information security Standard ▶

The organization's approach to managing information security and its implementation shall be reviewed independently at planned intervals or when significant changes occur.

A.5.36 Compliance with policies, rules & standards Standard ▶

Compliance with the organization's information security policy, topic-specific policies, rules, and standards shall be regularly reviewed.

A.5.37 Documented operating procedures Standard ▶

Operating procedures for information processing facilities shall be documented and made available to personnel who need them.

A.6 — People Controls

A.6.1 Screening Important ▶

Background verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis taking into account applicable laws, regulations, and ethics and be proportional to the business requirements, the classification of the information to be accessed, and the perceived risks.

A.6.2 Terms and conditions of employment Important ▶

The employment contractual agreements shall state the personnel's and the organization's responsibilities for information security.

A.6.3 Information security awareness, education & training Critical ▶

Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education, and training and regular updates of the organization's information security policy, topic-specific policies, and procedures, as relevant for their job function.

Framework Mapping

  • NIS2: Art. 21(2)(g) — Cyber hygiene & training
  • NIS2: Art. 20(2) — Board cybersecurity training
Security Engineer Takeaway: This maps directly to NIS2 Art. 21(2)(g). Run phishing simulations monthly, track click rates, and provide role-specific training (secure coding for developers, cloud security for ops). Document everything for audit evidence.
A.6.4 Disciplinary process Standard ▶

A disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.

A.6.5 Responsibilities after termination or change of employment Standard ▶

Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced, and communicated to relevant personnel and other interested parties.

A.6.6 Confidentiality or non-disclosure agreements Standard ▶

Confidentiality or non-disclosure agreements reflecting the organization's needs for the protection of information shall be identified, documented, regularly reviewed, and signed by personnel and other relevant interested parties.

A.6.7 Remote working Important ▶

Security measures shall be implemented when personnel are working remotely to protect information accessed, processed, or stored outside the organization's premises.

Security Engineer Takeaway: Updated in 2022 for post-pandemic reality. Ensure VPN/ZTNA, endpoint protection, encrypted storage, and clear guidelines on handling sensitive data remotely.
A.6.8 Information security event reporting Important ▶

The organization shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.

A.7 — Physical Controls

A.7.1 Physical security perimeters Critical ▶

Security perimeters shall be defined and used to protect areas that contain information and other associated assets.

Implementation Guidance

  • Define security zones (public, restricted, secure, high-security)
  • Implement physical barriers (walls, fences, doors with access control)
  • Consider data centre physical security requirements
A.7.2 Physical entry Important ▶

Secure areas shall be protected by appropriate entry controls and access points.

A.7.3 Securing offices, rooms & facilities Standard ▶

Physical security for offices, rooms, and facilities shall be designed and implemented.

A.7.4 Physical security monitoring Important NEW ▶

Premises shall be continuously monitored for unauthorized physical access.

Security Engineer Takeaway: New in 2022. Requires continuous monitoring (CCTV, intrusion detection sensors, security guards). Integrate with your SIEM for physical-cyber correlation.
A.7.5 Protecting against physical & environmental threats Important ▶

Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented.

A.7.6 Working in secure areas Standard ▶

Security measures for working in secure areas shall be designed and implemented.

A.7.7 Clear desk and clear screen Standard ▶

Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.

A.7.8 Equipment siting and protection Standard ▶

Equipment shall be sited securely and protected.

A.7.9 Security of assets off-premises Standard ▶

Off-site assets shall be protected.

A.7.10 Storage media Important ▶

Storage media shall be managed through their lifecycle of acquisition, use, transportation, and disposal in accordance with the organization's classification scheme and handling requirements.

A.7.11 Supporting utilities Standard ▶

Information processing facilities shall be protected from power failures and other disruptions caused by failures in supporting utilities.

A.7.12 Cabling security Standard ▶

Cables carrying power, data, or supporting information services shall be protected from interception, interference, or damage.

A.7.13 Equipment maintenance Standard ▶

Equipment shall be maintained correctly to ensure availability, integrity, and continued fulfilment of information security requirements.

A.7.14 Secure disposal or re-use of equipment Standard ▶

Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.

A.8 — Technological Controls

A.8.1 User endpoint devices Important ▶

Information stored on, processed by, or accessible via user endpoint devices shall be protected.

Implementation Guidance

  • Deploy endpoint protection (EDR), encryption, and remote wipe capabilities
  • Implement device management (MDM/UEM)
  • Enforce security baselines and patch management
A.8.2 Privileged access rights Critical ▶

The allocation and use of privileged access rights shall be restricted and managed.

Implementation Guidance

  • Implement PAM (Privileged Access Management) solutions
  • Use just-in-time privilege elevation
  • Enforce MFA for all privileged access
  • Monitor and log all privileged sessions
  • Review privileged accounts quarterly
Security Engineer Takeaway: Privileged accounts are the number one target. Implement PAM with session recording, enforce MFA, and adopt just-in-time access. Maps to NIS2 Art. 21(2)(i) and (j).
A.8.3 Information access restriction Important ▶

Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.

A.8.4 Access to source code Standard ▶

Read and write access to source code, development tools, and software libraries shall be appropriately managed.

A.8.5 Secure authentication Critical ▶

Secure authentication technologies and procedures shall be established and implemented based on information access restrictions and the topic-specific policy on access control.

Framework Mapping

  • NIS2: Art. 21(2)(j) — MFA & continuous authentication
Security Engineer Takeaway: Implement phishing-resistant MFA (FIDO2/WebAuthn) for all critical and admin access. Maps directly to NIS2 Art. 21(2)(j).
A.8.6 Capacity management Standard ▶

The use of resources shall be monitored and adjusted in line with current and expected capacity requirements.

A.8.7 Protection against malware Critical ▶

Protection against malware shall be implemented and supported by appropriate user awareness.

Security Engineer Takeaway: Deploy EDR on all endpoints and servers. Combine with email filtering, web proxies, and user awareness. Test with simulated attacks.
A.8.8 Management of technical vulnerabilities Critical ▶

Information about technical vulnerabilities of information systems in use shall be obtained in a timely fashion, the organization's exposure to such vulnerabilities shall be evaluated, and appropriate measures shall be taken.

Framework Mapping

  • NIS2: Art. 21(2)(e) — Vulnerability handling and disclosure
Security Engineer Takeaway: Establish SLAs: critical vulns patched within 7 days, high within 30 days. Scan weekly. Feed results into risk assessment. Coordinate with A.5.7 threat intelligence for prioritization.
A.8.9 Configuration management Critical NEW ▶

Configurations, including security configurations, of hardware, software, services, and networks shall be established, documented, implemented, monitored, and reviewed.

Security Engineer Takeaway: New in 2022. Formalize your hardening baselines using CIS Benchmarks or DISA STIGs. Monitor for configuration drift. Use IaC (Infrastructure as Code) for consistency.
A.8.10 Information deletion Important NEW ▶

Information stored in information systems, devices, or in any other storage media shall be deleted when no longer required.

Security Engineer Takeaway: New in 2022. Aligns with GDPR data minimization. Implement automated data lifecycle management and retention policies.
A.8.11 Data masking Important NEW ▶

Data masking shall be used in accordance with the organization's topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration.

Security Engineer Takeaway: New in 2022. Use dynamic data masking for non-production environments, static masking for test data, and tokenization for sensitive fields. Supports GDPR compliance.
A.8.12 Data leakage prevention Critical NEW ▶

Data leakage prevention measures shall be applied to systems, networks, and any other devices that process, store, or transmit sensitive information.

Security Engineer Takeaway: New in 2022. Implement DLP at endpoint, network, and cloud levels. Start with classifying sensitive data, then deploy policies to prevent unauthorized transfer. Integrates with A.5.12 (classification) and A.8.11 (masking).
A.8.13 Information backup Important ▶

Backup copies of information, software, and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.

A.8.14 Redundancy of information processing facilities Standard ▶

Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.

A.8.15 Logging Critical ▶

Logs that record activities, exceptions, faults, and other relevant events shall be produced, stored, protected, and analysed.

Security Engineer Takeaway: Central logging is your forensics and detection foundation. Feed all logs to SIEM. Protect log integrity. Define retention periods. This control pairs with A.8.16 (monitoring) and A.8.17 (clock sync).
A.8.16 Monitoring activities Critical NEW ▶

Networks, systems, and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.

Framework Mapping

  • NIS2: Art. 21(2)(b) — Incident handling (detection)
  • DORA: Art. 10 — Detection
  • NIST CSF: DE.CM — Continuous Monitoring
Security Engineer Takeaway: New in 2022. Explicitly requires continuous anomaly detection — not just logging, but active monitoring. Deploy SIEM with behavioral analytics (UEBA), network detection and response (NDR), and alerting. This maps directly to NIS2 and DORA detection requirements.
A.8.17 Clock synchronization Standard ▶

The clocks of information processing systems used by the organization shall be synchronized to approved time sources.

A.8.18 Use of privileged utility programs Standard ▶

The use of utility programs that might be capable of overriding system and application controls shall be restricted and tightly controlled.

A.8.19 Installation of software on operational systems Standard ▶

Procedures and measures shall be implemented to securely manage software installation on operational systems.

A.8.20 Networks security Critical ▶

Networks and network devices shall be secured, managed, and controlled to protect information in systems and applications.

A.8.21 Security of network services Standard ▶

Security mechanisms, service levels, and service requirements of network services shall be identified, implemented, and monitored.

A.8.22 Segregation of networks Important ▶

Groups of information services, users, and information systems shall be segregated in the organization's networks.

A.8.23 Web filtering Important NEW ▶

Access to external websites shall be managed to reduce exposure to malicious content.

Security Engineer Takeaway: New in 2022. Control outbound web access using DNS filtering, web proxies, or SASE solutions. Block known malicious categories and enforce HTTPS inspection where appropriate.
A.8.24 Use of cryptography Critical ▶

Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.

Framework Mapping

  • NIS2: Art. 21(2)(h) — Cryptography & encryption
Security Engineer Takeaway: Enforce TLS 1.2+ everywhere, encrypt data at rest and in transit, implement proper key management. Start planning for post-quantum cryptography migration.
A.8.25 Secure development life cycle Critical ▶

Rules for the secure development of software and systems shall be established and applied.

Security Engineer Takeaway: Integrate security into CI/CD: threat modeling, SAST, DAST, SCA, container scanning. This is the process control; A.8.28 is the coding practice control.
A.8.26 Application security requirements Standard ▶

Information security requirements shall be identified, specified, and approved when developing or acquiring applications.

A.8.27 Secure system architecture & engineering principles Important ▶

Principles for engineering secure systems shall be established, documented, maintained, and applied to any information system development activities.

A.8.28 Secure coding Critical NEW ▶

Secure coding principles shall be applied to software development.

Framework Mapping

  • NIS2: Art. 21(2)(e) — Security in acquisition, development & maintenance
  • OWASP Top 10 / OWASP ASVS
Security Engineer Takeaway: New in 2022. Secure coding is now a standalone control. Enforce OWASP guidelines, run SAST in CI/CD pipelines, conduct code reviews, and train developers on secure coding practices.
A.8.29 Security testing in development & acceptance Important ▶

Security testing processes shall be defined and implemented in the development life cycle.

A.8.30 Outsourced development Standard ▶

The organization shall direct, monitor, and review the activities related to outsourced system development.

A.8.31 Separation of development, test & production environments Standard ▶

Development, testing, and production environments shall be separated and secured.

A.8.32 Change management Important ▶

Changes to information processing facilities and information systems shall be subject to change management procedures.

A.8.33 Test information Standard ▶

Test information shall be appropriately selected, protected, and managed.

A.8.34 Protection of information systems during audit testing Standard ▶

Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed between the tester and appropriate management.

ISMS Requirements — Clauses 4–10

The ISMS requirements in clauses 4–10 define the management system framework. These are mandatory for certification — you cannot exclude any clause.

ISMS Clauses

Clause 4 — Context of the Organization

Clauses 4.1–4.4
  • Understand the organization and its context (internal and external issues)
  • Understand the needs and expectations of interested parties
  • Determine the scope of the ISMS
  • Establish, implement, maintain, and continually improve the ISMS

Clause 5 — Leadership

Clauses 5.1–5.3
  • Top management shall demonstrate leadership and commitment to the ISMS
  • Establish an information security policy appropriate to the organization
  • Ensure information security roles, responsibilities, and authorities are assigned and communicated

Clause 6 — Planning

Clauses 6.1–6.3
  • Determine actions to address risks and opportunities
  • Define and apply an information security risk assessment process
  • Define and apply an information security risk treatment process
  • Establish information security objectives and plan to achieve them
  • Plan changes to the ISMS when needed

Clause 7 — Support

Clauses 7.1–7.5
  • Determine and provide resources needed for the ISMS
  • Determine necessary competence and ensure personnel are competent
  • Ensure personnel are aware of the security policy, their contribution, and implications of non-conformance
  • Determine internal and external communication needs
  • Control documented information (creation, updating, control)

Clause 8 — Operation

Clauses 8.1–8.3
  • Plan, implement, and control processes to meet ISMS requirements
  • Perform information security risk assessments at planned intervals or when significant changes occur
  • Implement the information security risk treatment plan

Clause 9 — Performance Evaluation

Clauses 9.1–9.3
  • Monitor, measure, analyse, and evaluate ISMS performance
  • Conduct internal audits at planned intervals
  • Top management shall review the ISMS at planned intervals (management review)

Clause 10 — Improvement

Clauses 10.1–10.2
  • React to nonconformities and take corrective action
  • Continually improve the suitability, adequacy, and effectiveness of the ISMS

Certification Process Overview

StageActivityDurationNotes
Stage 1 AuditDocumentation review, readiness assessment1–2 daysAuditor reviews ISMS documentation, SoA, risk assessment
Gap RemediationAddress Stage 1 findings1–3 monthsFix identified gaps before Stage 2
Stage 2 AuditFull ISMS audit, evidence review, interviews3–5 daysAuditor verifies implementation effectiveness
Certification DecisionCertification body decision2–4 weeksMay include minor nonconformities requiring action
Surveillance AuditsAnnual partial audits1–2 days/yearYears 1 and 2 after initial certification
RecertificationFull audit every 3 years3–5 daysComplete reassessment

Statement of Applicability (SoA)

The SoA is the heart of your ISMS. It documents which of the 93 Annex A controls you've selected and why, which you've excluded and why, and how each selected control is implemented. Auditors use the SoA as the primary reference for assessing your ISMS. Keep it a living document: update it whenever controls change, new risks emerge, or your scope evolves.

Key Dates & Timeline

Important milestones in the evolution of ISO 27001.

1995
BS 7799 Part 1 Published
BSI (British Standards Institution) publishes BS 7799 Part 1 — a code of practice for information security management. The ancestor of ISO 27001.
1999
BS 7799 Part 2 Published
BS 7799 Part 2 published, providing certification requirements for an ISMS. This becomes the basis for ISO 27001.
2005
ISO/IEC 27001:2005 Published
First international version of ISO 27001 published, replacing BS 7799-2. Establishes the PDCA (Plan-Do-Check-Act) model for ISMS.
2013
ISO/IEC 27001:2013 Published
Major revision adopting the Annex SL (now Harmonized Structure) for integration with other management system standards. 114 controls in 14 categories.
2017
Corrigenda Consolidated
ISO/IEC 27001:2013/Cor 1:2014 and Cor 2:2015 consolidated into the standard. Minor corrections and clarifications.
February 2022
ISO/IEC 27002:2022 Published
Revised control guidance published with restructured controls: 4 themes, 93 controls (down from 114), and 11 new controls for modern threats.
October 2022
ISO/IEC 27001:2022 Published
Updated Annex A aligned with ISO 27002:2022. 93 controls in 4 themes (Organizational, People, Physical, Technological). Minor clause updates.
April 2024
Transition Deadline Extended
IAF (International Accreditation Forum) confirms transition deadline: organizations must transition from 2013 to 2022 by 31 October 2025.
31 October 2025
Transition Deadline
All certifications must be to ISO/IEC 27001:2022. Certificates to the 2013 version will no longer be valid after this date.
Ongoing
ISO 27002 Implementation Guidance
ISO/IEC 27002:2022 provides detailed implementation guidance for each of the 93 Annex A controls. Use it alongside ISO 27001 for control implementation.

Compliance Checklist

Track your ISO 27001 compliance progress. Checkmarks are saved locally in your browser.

Phase 1: Context & Planning

  • Organizational context understood and documented (Clause 4.1)
  • Interested parties and their requirements identified (Clause 4.2)
  • ISMS scope defined and documented (Clause 4.3)
  • Information security policy established and approved by top management (Clause 5.2)
  • Information security roles and responsibilities assigned (Clause 5.3)
  • Risk assessment methodology defined and documented (Clause 6.1.2)
  • Risk criteria established (acceptance criteria, assessment criteria)
  • Information security objectives defined at relevant functions and levels (Clause 6.2)

Phase 2: Risk Assessment & Treatment

  • Asset inventory completed (information assets, supporting assets)
  • Risk assessment performed identifying threats, vulnerabilities, and impacts
  • Risk treatment plan developed (mitigate, accept, transfer, avoid)
  • Annex A controls selected and justified
  • Statement of Applicability (SoA) documented
  • Controls excluded are justified in the SoA
  • Residual risks formally accepted by risk owners

Phase 3: Implementation

  • All selected Annex A controls implemented
  • Organizational controls (A.5) documented and operational
  • People controls (A.6) including training and awareness active
  • Physical controls (A.7) implemented and tested
  • Technological controls (A.8) deployed and configured
  • Documented information (policies, procedures, records) maintained
  • Competence requirements defined and training conducted (Clause 7.2)
  • Communication processes established (Clause 7.4)

Phase 4: Monitoring & Improvement

  • Monitoring and measurement processes defined (Clause 9.1)
  • Internal audit programme established and conducted (Clause 9.2)
  • Management review conducted at planned intervals (Clause 9.3)
  • Nonconformities documented and corrective actions taken (Clause 10.1)
  • Continual improvement process operational (Clause 10.2)
  • Certification audit (Stage 1 & 2) scheduled or completed

Who Uses ISO 27001

ISO 27001 is used across all sectors worldwide. Adoption is driven by regulatory requirements, customer expectations, and the need for structured information security management.

Regulatory & Contractual Drivers

ContextRequirementNotes
NIS2 ComplianceRecognized implementation standard for Art. 21 measures~70–80% NIS2 coverage
DORA ComplianceStrong alignment with ICT risk management requirementsSupplements DORA implementation
BSI IT-GrundschutzISO 27001 auf Basis von IT-Grundschutz (BSI certification path)Enhanced certification in DACH
GDPR (Art. 32)Demonstrates appropriate technical and organizational measuresEvidence for data protection
SOC 2Significant overlap with SOC 2 Type II trust service criteriaComplementary certifications
Customer RequirementsFrequently required in RFPs, especially B2B and enterpriseMarket differentiator

Common Adoption by Sector

SectorDriversNotes
Technology & SaaSCustomer assurance, enterprise sales, SOC 2 complementMost commonly certified sector
Financial ServicesRegulatory expectations, DORA alignmentOften combined with PCI DSS
HealthcareHIPAA alignment, patient data protectionMaps to HIPAA Security Rule
Government & DefenseNational security requirements, supply chainOften required for government contracts
TelecommunicationsNIS2 applicability, customer trustCritical infrastructure sector
ManufacturingSupply chain requirements, OT securityIncreasingly adopted for Industry 4.0
Professional ServicesClient requirements, competitive advantageConsulting, legal, accounting firms

ISO 27000 Family & Related Standards

ISO 27001 is part of a broader family of standards providing guidance on specific aspects of information security management.

Core Standards

ISO/IEC 27000

Overview and vocabulary (free download)
  • Provides the overview of the ISMS family of standards
  • Defines terms used throughout the 27000 series
  • Available free from ISO

ISO/IEC 27001:2022

ISMS requirements (certification standard)
  • The certification standard — specifies requirements
  • Includes Annex A with 93 reference controls
  • Mandatory for certification

ISO/IEC 27002:2022

Code of practice for controls (implementation guidance)
  • Detailed implementation guidance for each of the 93 controls
  • Not a certification standard — provides guidance
  • Essential companion to 27001

ISO/IEC 27003

ISMS implementation guidance
  • Guidance on ISMS implementation from planning to operation
  • Covers clauses 4–10 in detail

ISO/IEC 27004

Monitoring, measurement, analysis and evaluation
  • Guidance on information security performance evaluation
  • Supports Clause 9 requirements

ISO/IEC 27005

Information security risk management
  • Detailed guidance on risk management process
  • Supports Clause 6 and 8 requirements

Sector-Specific Extensions

ISO/IEC 27017

Cloud security controls
  • Additional controls and guidance for cloud services
  • Supplements A.5.23 (cloud services)

ISO/IEC 27018

PII protection in public clouds
  • Protection of personally identifiable information in cloud environments
  • Supports GDPR compliance for cloud processors

ISO/IEC 27701

Privacy information management (GDPR extension)
  • Extension to 27001 for privacy management (PIMS)
  • Maps to GDPR requirements

ISO/IEC 27019

Energy sector security
  • Controls for the energy utility industry
  • Addresses OT/SCADA environments

ISO 27799

Health informatics security
  • Guidance for healthcare sector ISMS implementation
  • Addresses patient data protection

Certification & Business Impact

Understanding the business context, certification process, and impact of ISO 27001.

Certification Bodies

Accredited third-party auditors
  • Accredited by national accreditation bodies (e.g., UKAS in UK, DAkkS in Germany, SAS in Switzerland)
  • Audits follow ISO/IEC 17021 (management system certification) and ISO/IEC 27006 (ISMS audit requirements)
  • Certification is valid for 3 years with annual surveillance audits
  • Auditor competence is regulated and verified

Business Benefits

Why organizations certify
  • Market access: required by many enterprise customers and in RFPs
  • Regulatory compliance evidence: supports NIS2, DORA, GDPR
  • Insurance premium reductions: demonstrable security maturity
  • Competitive differentiation: trusted certification globally recognized
  • Structured risk management: systematic approach to security

Cost of Non-Certification

Business risks
  • Loss of business opportunities (RFP requirements)
  • Increased regulatory scrutiny (especially under NIS2)
  • Higher insurance premiums
  • Competitive disadvantage in B2B markets
  • Not having ISO 27001 increasingly seen as a red flag by enterprise buyers

Transition from 2013 to 2022

Deadline: 31 October 2025
  • All existing certifications must transition by 31 October 2025
  • Key changes: 11 new controls added
  • Restructured Annex A: 4 themes instead of 14 categories
  • Updated terminology and control attributes
  • SoA must be updated to reflect new control structure

External Resources & References

Curated links to official documents, guidance, and tools. All links open in a new tab.

Official Standards

Official

ISO/IEC 27001:2022 — Information security management systems

The official ISO 27001:2022 standard. Available for purchase from ISO and national standards bodies.

Primary Source
Official

ISO/IEC 27002:2022 — Information security controls

Implementation guidance for the 93 Annex A controls. Essential companion to 27001.

Implementation Guide
Official

ISO/IEC 27000:2018 — Overview and vocabulary (free)

Free download providing the overview and vocabulary for the entire ISO 27000 family.

Free Resource

Authority & Guidance

Authority

ENISA — NIS2 to ISO 27001 Mapping

ENISA guidance mapping NIS2 Art. 21 measures to ISO 27001 controls. Essential for multi-framework compliance.

NIS2 Mapping
Authority

BSI — IT-Grundschutz to ISO 27001 Mapping

BSI's IT-Grundschutz provides a comprehensive mapping to ISO 27001, used extensively in DACH region.

BSI DACH
Authority

ISO 27001 Annex A Controls Guide

Official ISO guidance on the 93 Annex A controls and their implementation.

Controls

Tools & Practical Resources

Tool

OpenCRE — Common Requirements Enumeration

Map ISO 27001 controls to other standards (NIS2, NIST CSF, CIS Controls, OWASP). Excellent for crosswalk analysis.

Mapping
Tool

ISMS.online

Cloud platform for ISO 27001 ISMS management, SoA tracking, and audit preparation.

SaaS
Tool

Vanta / Drata — Compliance Automation

Automated compliance platforms for ISO 27001, SOC 2, and other frameworks. Continuous monitoring and evidence collection.

Automation
Tool

MITRE ATT&CK Framework

Use for threat-informed control selection. Map ATT&CK techniques to ISO 27001 controls for risk-based prioritization.

Threat Intel

Community & Industry Bodies

Community

ISO — International Organization for Standardization

The official standards body. Source of truth for all ISO/IEC 27000 family standards.

Standards Body
Community

ISACA — COBIT Alignment

ISACA provides COBIT-to-ISO 27001 mapping and governance frameworks for information security.

Governance
Community

(ISC)² Community

Global cybersecurity professional community. CISSP and other certifications align well with ISO 27001 knowledge domains.

Professional
Community

ISMS Forum

Non-profit association promoting information security. Forums, conferences, and best practice sharing.

Community

Title