ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Controls - Organizational Controls (A.5 – 37 controls)

2. ISO 27001 Annex A Controls – Organizational Controls (A.5 – 37 controls)

ISO/IEC 27001 Annex A serves as the practical checklist of information security safeguards—known as controls—that an organization can implement to manage cyber and data security risks.

While Clauses 4 through 10 of ISO 27001 define the governance requirements for an Information Security Management System (ISMS), Annex A provides the specific operational measures used to protect the confidentiality, integrity, and availability of information.

Image 1

Under the ISO/IEC 27001 framework, the controls are structured across four operational themes comprising 93 controls in total:

  • Organizational Controls (A.5 – 37 controls): High-level operational practices, including security policies, asset management, access governance, threat intelligence, and cloud service security.
  • People Controls (A.6 – 8 controls): Human resource safety measures, such as background checks, security awareness training, remote work guidelines, and offboarding procedures.
  • Physical Controls (A.7 – 14 controls): Measures protecting physical spaces and equipment, including perimeter security, entry controls, clear desk/screen policies, and equipment maintenance.
  • Technological Controls (A.8 – 34 controls): Technical defenses, such as data encryption, network security, secure coding practices, vulnerability management, and log monitoring.

Organizations select relevant Annex A controls based on their internal risk assessment, documenting which controls are applied (and justifying any exclusions) within their formal Statement of Applicability (SoA)

Articles

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *