# ISO 27001 Controls: A Guide to Implementing Annex A Controls

## TL;DR

|     |
| --- |
| ISO 27001 controls (Annex A) are security measures (policies, processes, technical controls) used to manage risks and build an ISMS. |
| You don’t implement all controls—you select relevant ones based on your risk assessment and Statement of Applicability (SoA). |
| Controls are grouped into key domains (e.g., access control, cryptography, asset management, incident response, vendor risk) covering end-to-end security. |
| Clauses (4–10) are mandatory, while controls define _how_ you meet them—together enabling audit readiness and certification. |

ISO 27001 is an international standard that outlines various clauses and controls that organizations can implement for effectively building an Information Security Management System (ISMS).

The ISO 27001 clauses and controls are utilized by organizations to manage security risks and achieve ISMS certification. The controls are detailed in Annex A, and organizations should choose and deploy the relevant controls. These controls will help mitigate the identified security risks, establishing a robust framework.

## **What are ISO 27001 Controls?**

ISO 27001 controls are the measures that organizations must take by way of policies, processes, and procedures to meet the security requirements of the framework. ISO 27001 lists its 114 controls in Annex A which are divided into 14 domains.

ISO 27001 Annex A is like a Table of Contents that lists all the security controls under ISO. Organizations can pick and choose the appropriate controls and decide how they deploy them based on their risk assessment and risk treatment plan.

## **Who is responsible for implementing ISO 27001 Annex A controls?**

Infosec Officer (or team) is responsible for the implementation of controls and the organization’s compliance with ISO 27001 standard, the fundamental responsibility of implementing the Annex A controls vests on all the employees. Employees are the first line of defense in a security attack; therefore, it is a shared responsibility.

Management buy-in is critical here. Therefore, the entire process of ISO 27001 implementation rests equally on management review and approval of policies and procedures at every decisive step.

## **How many ISO 27001 clauses and controls are there?**

ISO 27001 includes 11 core clauses that define the requirements for an Information Security Management System (ISMS), supported by 93 security controls in Annex A. These controls are grouped into four categories: organizational, people, physical, and technological. For AI-first companies, these controls extend beyond IT to address data governance, access management, and operational risks across automated and human systems.

There are a total of 114 controls in the ISO 27001 Annex A that are divided into 14 domains. The 114 controls in general come under different functions i.e. organizational issues, human resources, information technology, physical security, and legal issues.

## **What are the 14 domains under ISO 27001 list of controls?**

ISO 27001 Controls List comprises 14 domains, each centered on specific security functions within the organization.

### 1\. Information Security Policies – Annex A5

As per the List of ISO 27001 controls, it determines if your organization has policies to provide management direction and support for information security. The organization needs to document relevant infosec policies and ensure they are approved by the management, published and communicated for staff awareness and reviewed periodically.

### 2\. Organisation of Information Security – Annex A6

If A5 was about setting up the [information security policies](https://sprinto.com/blog/information-security-policy/?ref=iso-con-blog) and processes, A6 is about ensuring how the policies are implemented in the organization. The Annex provides a framework for assigning security roles across the organization such that no one drops the ball while implementing and running the ISMS. It also covers mobile devices and remote working.

### 3\. Human Resources Security – Annex A7

Much like the human resources function, the controls in this domain are centered on information security through the three phases of employees’ journey in an organization – before employment, during employment, and on termination/change of employment.

### 4\. Asset Management – Annex A8

ISO 27001 Annex A controls in this domain help identify organizational assets (associated with information management) and define appropriate protection responsibilities.

### 5\. Access Control – Annex A9

An important facet of data security is controlling access to information, and this domain defines the controls to do just that. Access control, in essence, is user management that defines controls for the administration of login credentials, user privileges, access rights, and password management systems, to name a few.

### 6\. Cryptography – Annex A10

Your organization should have a documented policy on cryptographic controls and key management processes. The objective of this domain is to ensure the confidentiality, integrity, and availability of information are protected throughout.

### 7\. Physical and Environmental Security – Annex A11

The control objectives for this domain focus on protecting your organization’s physical premises and preventing loss, damage, theft, or compromise of its assets and operations.

### 8\. Operational Security – Annex A12

Comprising seven sub-domains, the controls listed here pertain to operational procedures, defenses against malware, backups, logging & monitoring, change management, patch management, vulnerability management, and penetration tests, and more.

### 9\. Communications Security – Annex A13

Network security, segregation of networks, secure transfer of information, confidentiality, and non-disclosure agreements are some of the critical controls in this domain.

### 10\. System Acquisition, Development, and Maintenance – Annex A14

The first objective of A14 is to ensure that information security is integral to information systems across the entire lifecycle.

### 11\. Supplier Relationships – Annex A15

Vendor risk management is critical to managing your organization’s information security management system. The ISO 27001 controls here protect your organization’s assets accessible to the suppliers.

### 12\. Information Security Incident Management – Annex A16

This domain deals with controls that define the roles and responsibilities of employees when things go wrong (aka, there is a security breach).

### 13\. Information Security Aspects of Business Continuity Management – Annex A17

Information security is critical.

### 14\. Compliance – Annex A18

The last domain ensures organizations identify the relevant and applicable laws and regulations, such as intellectual property rights, privacy, and protection of personally identifiable information, and how they abide by them.
