All 93 controls

ISO/IEC 27001:2022 Annex A · 37 controls

Organizational controls

The controls about how the company runs itself: the policies it sets, who is responsible for what, how it handles suppliers and incidents, and how it keeps operating when something goes wrong. This is the largest of the four groups and the one an auditor opens first, because it is where the management system meets the business.

Every control here needs an applicability decision and a justification in your Statement of Applicability, including the ones you exclude. What certification costs, and which clauses StandardOS covers.

Decide all 37 in one pass

StandardOS pre-fills applicability and a draft justification for every Annex A control from a seven-question profile, keeps each draft marked as unreviewed until you have made it yours, and tracks implementation against each one.