ISO/IEC 27001:2022 · Annex A
The ISO 27001 controls list: all 93 Annex A controls
A plain-language line on what every control is asking for. Free to read. Generate your Statement of Applicability in minutes with StandardOS.
Wondering what the audit itself costs? We show you how to work out your own number. Certification bodies do not publish prices, but the audit days are fixed by ISO/IEC 27006.
Organizational
· 37- A.5.1Written security policies, approved and kept current
- A.5.2Who is accountable for what in security
- A.5.3Splitting sensitive tasks between different people
- A.5.4What leadership must require of everyone
- A.5.5Knowing who to contact at the authorities
- A.5.6Staying connected to security communities
- A.5.7Gathering and acting on threat information
- A.5.8Building security into every project
- A.5.9Knowing what information and equipment you hold
- A.5.10Rules for using company information and devices
- A.5.11Getting equipment and data back when people leave
- A.5.12Grading information by how sensitive it is
- A.5.13Marking information with its sensitivity
- A.5.14Sending information safely, inside and out
- A.5.15Deciding who may reach which systems and data
- A.5.16Managing accounts and identities over their life
- A.5.17Handling passwords, keys and other secrets
- A.5.18Granting, reviewing and revoking permissions
- A.5.19Managing the risk that suppliers bring
- A.5.20Putting security terms into supplier contracts
- A.5.21Security through the technology supply chain
- A.5.22Keeping watch on suppliers as they change
- A.5.23Using cloud services safely
- A.5.24Being ready before an incident happens
- A.5.25Judging which events are real incidents
- A.5.26Acting on an incident once it is declared
- A.5.27Learning from incidents afterwards
- A.5.28Preserving evidence after an incident
- A.5.29Holding security together during a crisis
- A.5.30Keeping technology running through disruption
- A.5.31Knowing the laws and contracts that bind you
- A.5.32Respecting copyright and software licensing
- A.5.33Keeping records safe for as long as required
- A.5.34Protecting personal data
- A.5.35Having security checked by someone independent
- A.5.36Checking your own rules are actually followed
- A.5.37Writing down how things are actually done
People
· 8- A.6.1Background checks before hiring
- A.6.2Security duties written into employment terms
- A.6.3Training people to work securely
- A.6.4Consequences when the rules are broken
- A.6.5Duties that outlast someone leaving or moving
- A.6.6Confidentiality agreements
- A.6.7Working securely away from the office
- A.6.8Making it easy for staff to report problems
Physical
· 14- A.7.1Defining the physical boundary you protect
- A.7.2Controlling who gets through the door
- A.7.3Securing the rooms themselves
- A.7.4Watching the premises for intruders
- A.7.5Guarding against fire, flood and the like
- A.7.6Rules for working inside restricted areas
- A.7.7Leaving nothing sensitive on desks or screens
- A.7.8Placing equipment where it is safe
- A.7.9Protecting equipment taken off site
- A.7.10Handling disks, drives and removable media
- A.7.11Depending safely on power, cooling and water
- A.7.12Protecting power and network cabling
- A.7.13Maintaining equipment so it keeps working
- A.7.14Wiping equipment before disposal or reuse
Technological
· 34- A.8.1Securing laptops, phones and desktops
- A.8.2Restricting administrator access
- A.8.3Limiting what each person can open
- A.8.4Controlling who can reach the source code
- A.8.5Logging in securely
- A.8.6Having enough capacity to keep running
- A.8.7Defending against malware
- A.8.8Finding and fixing known weaknesses
- A.8.9Keeping systems configured the way you intended
- A.8.10Deleting data you no longer need
- A.8.11Hiding data that does not need to be shown
- A.8.12Stopping data leaving where it should not
- A.8.13Backing data up and proving restores work
- A.8.14Spare capacity so a failure is survivable
- A.8.15Recording what happened on your systems
- A.8.16Watching systems for suspicious behaviour
- A.8.17Keeping system clocks aligned
- A.8.18Restricting powerful system tools
- A.8.19Controlling what gets installed in production
- A.8.20Securing the network itself
- A.8.21Agreeing security terms for network services
- A.8.22Keeping networks separated from each other
- A.8.23Filtering access to risky websites
- A.8.24Using encryption properly and managing keys
- A.8.25Security throughout how software gets built
- A.8.26Deciding what an application must do securely
- A.8.27Designing systems on secure principles
- A.8.28Writing code that resists attack
- A.8.29Testing security before anything ships
- A.8.30Overseeing security when others build for you
- A.8.31Keeping build, test and live environments apart
- A.8.32Controlling changes to live systems
- A.8.33Using safe data when testing
- A.8.34Auditing systems without disrupting them
Turn all 93 into a Statement of Applicability
Answer seven questions about your organization and StandardOS decides applicability for every control above, drafts a justification that stays marked as a draft until you have made it yours, and tracks implementation from there.