All resources
ISO 27001Annex AChecklist

ISO/IEC 27001:2022 checklist: all 93 Annex A controls

Official source: ISO/IEC 27001:2022

ISO/IEC 27001:2022's 93 Annex A controls across four themes, mapped to the evidence auditors expect and flagged auto vs. manual.

What ISO 27001 requires

ISO 27001 is assessed against 93 controls across 4 themes: Organizational, People, Physical, and Technological. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

The four Annex A themes (93 controls in ISO/IEC 27001:2022) with the key controls in each. Use the table below as your working checklist — 21 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
A.5 — Organizational (37 controls)
A.5.1Policies for information securityManual
A.5.7Threat intelligenceAuto
A.5.19Supplier relationshipsManual
A.5.23Cloud services securityManual
A.5.24Incident management planningManual
A.5.30ICT readiness for business continuityManual
A.6 — People (8 controls)
A.6.1ScreeningManual
A.6.3Awareness, education & trainingManual
A.6.5Responsibilities after terminationManual
A.7 — Physical (14 controls)
A.7.1Physical security perimetersManual
A.7.10Storage mediaManual
A.7.14Secure disposal or re-use of equipmentManual
A.8 — Technological (34 controls)
A.8.1User endpoint devicesAuto
A.8.2Privileged access rightsAuto
A.8.5Secure authentication (MFA)Auto
A.8.8Management of technical vulnerabilitiesAuto
A.8.12Data leakage preventionAuto
A.8.15LoggingAuto
A.8.16Monitoring activitiesAuto
A.8.24Use of cryptographyAuto
A.8.28Secure codingManual

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of ISO 27001 controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Frequently asked questions

How many controls are in ISO/IEC 27001:2022 Annex A?
93 controls, reorganized into 4 themes. The previous 2013 version had 114 controls across 14 domains.

What are the four themes in 27001:2022?
Organizational, People, Physical, and Technological controls. Eleven of the 93 are new in 2022, including threat intelligence and secure coding.

Is ISO 27001 a certification?
Yes. Unlike most frameworks here, ISO/IEC 27001 offers accredited certification — a certification body runs Stage 1 and Stage 2 audits, then annual surveillance audits over a three-year cycle.

Which ISO 27001 controls can be automated?
Most Technological controls — access control, cryptography, logging, configuration, and vulnerability management — can be evidenced continuously with timestamps. Organizational and People controls still need documented policy and process.

Turn this checklist into a live dashboard

SBCMSP tracks every ISO 27001 control continuously across all your clients.