How many controls are there in ISO 27001?

Demystifying ISO 27001 Annex A Control Sets

ISO 27001 serves as the universal benchmark for setting up an Information Security Management System (ISMS). At its core, the standard enforces a risk-driven strategy that requires organizations to pinpoint specific security threats and apply appropriate safeguards to neutralize them. Annex A delivers the precise framework for these safeguards, containing 114 individual controls grouped into 14 distinct functional domains. Understanding these categories allows security teams to systematically assess vulnerability gaps, assign clear operational accountability, and build a resilient defense matrix across technical, physical, and human operational layers.

Implementing these 14 control sets transforms complex compliance demands into structured, manageable actions. Organizations evaluate their unique risk environment, select relevant controls through a Statement of Applicability, and deploy policies that protect sensitive assets. From securing network infrastructure and managing vendor access to training employees and preparing for system disruptions, Annex A equips businesses with an adaptable blueprint. Mastering these 14 domains ensures your business maintains data integrity, satisfies legal regulatory requirements, and maintains operational continuity during security incidents.

What Are the Core ISO 27001 Annex A Control Sets?

What Belongs in Organizational and Human Resource Security?

Annex A.5  Information Security Policies (2 Controls)

This domain establishes the foundational direction for corporate security. The controls mandate that leaders draft, approve, publish, and regularly review explicit security policies to align daily practices with organizational goals.

Annex A.6  Organization of Information Security (7 Controls)

This section defines operational roles and responsibilities. It establishes an internal governance framework to manage security tasks while setting strict guidelines for mobile devices and remote work environments.

Annex A.7  Human Resource Security (6 Controls)

This category ensures that employees and contractors understand their security obligations. It covers background checks before employment, security awareness training during employment, and strict offboarding procedures when personnel leave or change roles.

What Controls Protect Assets, Access, and Data Integrity?

Annex A.8  Asset Management (10 Controls)

Organizations must identify all information assets within the ISMS scope and assign clear ownership. This domain mandates systematic data classification and safe media handling to prevent unauthorized exposure, alteration, or destruction.

Annex A.9  Access Control (14 Controls)

This set limits data access strictly to authorized personnel based on business needs. Controls govern user access management, password hygiene, system login restrictions, and application access limits.

Annex A.10  Cryptography (2 Controls)

This domain covers data encryption and key management. The controls ensure organizations implement effective cryptographic measures to maintain data confidentiality, integrity, and availability.

What Measures Secure Physical Spaces and Operational Systems?

Annex A.11  Physical and Environmental Security (15 Controls)

As the largest set in Annex A, these controls prevent unauthorized physical access, damage, or interference to business premises. They also protect physical equipment from loss, theft, hardware failure, or environmental hazards.

Annex A.12  Operations Security (14 Controls)

This category ensures IT processing facilities operate safely day-to-day. It sets standards for operational documentation, malware protection, data backups, system logging, vulnerability management, and audit controls.

Annex A.13  Communications Security (7 Controls)

This domain focuses on protecting information within network infrastructures. Controls safeguard network connections, segregation, and data in transit between internal systems, third parties, and external clients.

What Controls Govern Systems Development and Vendor Relationships?

Annex A.14  System Acquisition, Development, and Maintenance (13 Controls)

Security must remain a core requirement throughout the full technology lifecycle. These controls enforce security specifications for internal software development, public network services, and application support environments.

Annex A.15  Supplier Relationships (5 Controls)

Third-party access introduces significant risk. This set governs contractual agreements with suppliers, ensuring third parties uphold agreed security baselines and service delivery standards when interacting with sensitive data.

What Safeguards Ensure Incident Response and Compliance?

Annex A.16  Information Security Incident Management (7 Controls)

Organizations must prepare for unexpected security events. This domain establishes clear reporting structures, incident assessment protocols, and structured response workflows to manage threats consistently.

Annex A.17  Information Security Aspects of Business Continuity Management (4 Controls)

This set ensures security protections remain operational during disruptions, disasters, or severe system outages. Controls mandate redundant processing capacity and integrated continuity planning.

Annex A.18  Compliance (8 Controls)

This domain helps businesses identify and monitor relevant legal, regulatory, and contractual obligations. Adhering to these controls prevents compliance failures, legal liabilities, and regulatory penalties.

FAQ’s

What is ISO 27001 Annex A?

Annex A is a dedicated section within the ISO 27001 standard that lists 114 specific security controls designed to address operational risks identified during an organizational risk assessment.

Do organizations need to implement all 114 controls?

No, organizations select controls based on their specific risk assessment results and document their choices in a formal Statement of Applicability (SoA).

How do the 14 control sets improve security?

The 14 control sets categorize security responsibilities across physical, technical, organizational, and human domains, giving companies a structured approach to risk management.

How often should an organization review these controls?

Organizations should review their Annex A controls at least annually or whenever significant changes occur in business operations, infrastructure, or regulatory requirements.

Why is vendor security included in Annex A?

Third-party vendors often access critical systems and data, making supplier relationship controls essential for preventing external supply-chain security breaches.