We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ISO/IEC 27001:2022 · Annex A theme 4 of 4 · 34 controls

Annex A.8: Technological Controls

The engineering theme: 34 controls from endpoint protection to secure coding. Eight of the eleven controls new in 2022 live here — configuration management, information deletion, data masking, DLP, activity monitoring, web filtering and secure coding — which is why 2013-era ISMS documentation fails a 2022 audit without real uplift.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series

The controls that decide your audit

A.8.2–8.3
Privileged access & information access restriction

Privileged rights restricted and managed; access to information limited per the access-control policy — least privilege, provable.

A.8.8
Technical vulnerability management

Vulnerabilities identified, exposure evaluated, and remediated with measured timelines — scans plus SLA evidence.

A.8.9
Configuration management (new 2022)

Configurations — including security configurations — established, documented, implemented, monitored and reviewed. Hardening baselines with drift detection.

A.8.10
Information deletion (new 2022)

Information deleted when no longer required — the control that pairs with DPDP s.8(7) erasure duties for Indian entities.

A.8.11–8.12
Data masking & DLP (new 2022)

Masking per policy for sensitive data; data-leakage prevention applied to systems and channels carrying sensitive information.

A.8.15–8.16
Logging & monitoring (8.16 new 2022)

Logs produced, protected and analysed; networks/systems/applications monitored for anomalous behaviour with response.

A.8.23
Web filtering (new 2022)

Access to external websites managed to reduce exposure to malicious content.

A.8.25–8.31
Secure development lifecycle

Secure SDLC rules, requirements, architecture/engineering principles, secure coding (8.28 new), testing and environment separation.

A.8.32
Change management

Changes to information processing facilities follow the change-management procedure — with samples that prove it.

Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.

Where audits actually fail

2013 documentation lightly renamed

The 2022 additions (8.9–8.12, 8.16, 8.23, 8.28) need implemented controls, not a re-mapped SoA. Auditors open with the new controls precisely because paper migrations fail there.

Vulnerability scans without remediation SLAs

A.8.8 evidence is the full loop: scan → risk evaluation → fix within defined timelines → verification. A folder of PDFs is half a control.

DLP bought, monitor-only, alerts unread

A.8.12 asks for detection AND prevention/response on real channels — sampled alerts with disposition beat a licence invoice.

No deletion evidence

A.8.10 requires demonstrable deletion when data is no longer required — retention schedule plus executed deletion records; "we keep everything" is now a nonconformity.

Evidence an auditor accepts

  • PAM records and privileged-account reviews (A.8.2)
  • Hardening baselines with drift/compliance reports (A.8.9)
  • Vulnerability-management loop: scans, SLAs, remediation, verification (A.8.8)
  • DLP policy, channel coverage and sampled alert dispositions (A.8.12)
  • Monitoring use-cases, alert samples and response records (A.8.16)
  • Secure-coding standard, code-review/SAST evidence, environment separation (A.8.28/8.31)
  • Retention schedule + executed deletion records (A.8.10)

Annex A.8 FAQ

Which Annex A controls are new in ISO 27001:2022?

Eleven: threat intelligence (5.7), cloud services (5.23), ICT readiness for BC (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), DLP (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28).

Is the 2013 version still auditable?

No — the transition period ended 31 October 2025; certification audits now run against ISO/IEC 27001:2022.

Does A.8 require specific tools?

The standard mandates outcomes, not products — but for controls like DLP, monitoring and configuration management, auditors expect tooling-scale evidence in any non-trivial environment.

Physical (A.7)

Annex A.8 in your ISMS

We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.