ISO/IEC 27001:2022 Annex A · 34 controls
Technological controls
The controls about the systems themselves: access, cryptography, logging, backup, how software is built and how networks are separated. The largest technical group, and the one where evidence is usually easiest to produce because the systems are already generating it.
- A.8.1Securing laptops, phones and desktops
- A.8.2Restricting administrator access
- A.8.3Limiting what each person can open
- A.8.4Controlling who can reach the source code
- A.8.5Logging in securely
- A.8.6Having enough capacity to keep running
- A.8.7Defending against malware
- A.8.8Finding and fixing known weaknesses
- A.8.9Keeping systems configured the way you intended
- A.8.10Deleting data you no longer need
- A.8.11Hiding data that does not need to be shown
- A.8.12Stopping data leaving where it should not
- A.8.13Backing data up and proving restores work
- A.8.14Spare capacity so a failure is survivable
- A.8.15Recording what happened on your systems
- A.8.16Watching systems for suspicious behaviour
- A.8.17Keeping system clocks aligned
- A.8.18Restricting powerful system tools
- A.8.19Controlling what gets installed in production
- A.8.20Securing the network itself
- A.8.21Agreeing security terms for network services
- A.8.22Keeping networks separated from each other
- A.8.23Filtering access to risky websites
- A.8.24Using encryption properly and managing keys
- A.8.25Security throughout how software gets built
- A.8.26Deciding what an application must do securely
- A.8.27Designing systems on secure principles
- A.8.28Writing code that resists attack
- A.8.29Testing security before anything ships
- A.8.30Overseeing security when others build for you
- A.8.31Keeping build, test and live environments apart
- A.8.32Controlling changes to live systems
- A.8.33Using safe data when testing
- A.8.34Auditing systems without disrupting them
Every control here needs an applicability decision and a justification in your Statement of Applicability, including the ones you exclude. What certification costs, and which clauses StandardOS covers.
Decide all 34 in one pass
StandardOS pre-fills applicability and a draft justification for every Annex A control from a seven-question profile, keeps each draft marked as unreviewed until you have made it yours, and tracks implementation against each one.