ISO 27001:2022 Annex A — all 93 controls
A plain-English line on what every control is asking for. Free to read — generate your Statement of Applicability in minutes with StandardOS.
Wondering what the audit itself costs? We show you how to work out your own number — certification bodies do not publish prices, but the audit days are fixed by ISO/IEC 27006.
organizational · 37
- A.5.1Written security policies, approved and kept current
- A.5.2Who is accountable for what in security
- A.5.3Splitting sensitive tasks between different people
- A.5.4What leadership must require of everyone
- A.5.5Knowing who to contact at the authorities
- A.5.6Staying connected to security communities
- A.5.7Gathering and acting on threat information
- A.5.8Building security into every project
- A.5.9Knowing what information and equipment you hold
- A.5.10Rules for using company information and devices
- A.5.11Getting equipment and data back when people leave
- A.5.12Grading information by how sensitive it is
- A.5.13Marking information with its sensitivity
- A.5.14Sending information safely, inside and out
- A.5.15Deciding who may reach which systems and data
- A.5.16Managing accounts and identities over their life
- A.5.17Handling passwords, keys and other secrets
- A.5.18Granting, reviewing and revoking permissions
- A.5.19Managing the risk that suppliers bring
- A.5.20Putting security terms into supplier contracts
- A.5.21Security through the technology supply chain
- A.5.22Keeping watch on suppliers as they change
- A.5.23Using cloud services safely
- A.5.24Being ready before an incident happens
- A.5.25Judging which events are real incidents
- A.5.26Acting on an incident once it is declared
- A.5.27Learning from incidents afterwards
- A.5.28Preserving evidence after an incident
- A.5.29Holding security together during a crisis
- A.5.30Keeping technology running through disruption
- A.5.31Knowing the laws and contracts that bind you
- A.5.32Respecting copyright and software licensing
- A.5.33Keeping records safe for as long as required
- A.5.34Protecting personal data
- A.5.35Having security checked by someone independent
- A.5.36Checking your own rules are actually followed
- A.5.37Writing down how things are actually done
people · 8
- A.6.1Background checks before hiring
- A.6.2Security duties written into employment terms
- A.6.3Training people to work securely
- A.6.4Consequences when the rules are broken
- A.6.5Duties that outlast someone leaving or moving
- A.6.6Confidentiality agreements
- A.6.7Working securely away from the office
- A.6.8Making it easy for staff to report problems
physical · 14
- A.7.1Defining the physical boundary you protect
- A.7.2Controlling who gets through the door
- A.7.3Securing the rooms themselves
- A.7.4Watching the premises for intruders
- A.7.5Guarding against fire, flood and the like
- A.7.6Rules for working inside restricted areas
- A.7.7Leaving nothing sensitive on desks or screens
- A.7.8Placing equipment where it is safe
- A.7.9Protecting equipment taken off site
- A.7.10Handling disks, drives and removable media
- A.7.11Depending safely on power, cooling and water
- A.7.12Protecting power and network cabling
- A.7.13Maintaining equipment so it keeps working
- A.7.14Wiping equipment before disposal or reuse
technological · 34
- A.8.1Securing laptops, phones and desktops
- A.8.2Restricting administrator access
- A.8.3Limiting what each person can open
- A.8.4Controlling who can reach the source code
- A.8.5Logging in securely
- A.8.6Having enough capacity to keep running
- A.8.7Defending against malware
- A.8.8Finding and fixing known weaknesses
- A.8.9Keeping systems configured the way you intended
- A.8.10Deleting data you no longer need
- A.8.11Hiding data that does not need to be shown
- A.8.12Stopping data leaving where it should not
- A.8.13Backing data up and proving restores work
- A.8.14Spare capacity so a failure is survivable
- A.8.15Recording what happened on your systems
- A.8.16Watching systems for suspicious behaviour
- A.8.17Keeping system clocks aligned
- A.8.18Restricting powerful system tools
- A.8.19Controlling what gets installed in production
- A.8.20Securing the network itself
- A.8.21Agreeing security terms for network services
- A.8.22Keeping networks separated from each other
- A.8.23Filtering access to risky websites
- A.8.24Using encryption properly and managing keys
- A.8.25Security throughout how software gets built
- A.8.26Deciding what an application must do securely
- A.8.27Designing systems on secure principles
- A.8.28Writing code that resists attack
- A.8.29Testing security before anything ships
- A.8.30Overseeing security when others build for you
- A.8.31Keeping build, test and live environments apart
- A.8.32Controlling changes to live systems
- A.8.33Using safe data when testing
- A.8.34Auditing systems without disrupting them