All 93 controls

ISO/IEC 27001:2022 Annex A · 34 controls

Technological controls

The controls about the systems themselves: access, cryptography, logging, backup, how software is built and how networks are separated. The largest technical group, and the one where evidence is usually easiest to produce because the systems are already generating it.

Every control here needs an applicability decision and a justification in your Statement of Applicability, including the ones you exclude. What certification costs, and which clauses StandardOS covers.

Decide all 34 in one pass

StandardOS pre-fills applicability and a draft justification for every Annex A control from a seven-question profile, keeps each draft marked as unreviewed until you have made it yours, and tracks implementation against each one.