Annex A.8: Technological Controls
The engineering theme: 34 controls from endpoint protection to secure coding. Eight of the eleven controls new in 2022 live here — configuration management, information deletion, data masking, DLP, activity monitoring, web filtering and secure coding — which is why 2013-era ISMS documentation fails a 2022 audit without real uplift.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series
The controls that decide your audit
Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.
Where audits actually fail
The 2022 additions (8.9–8.12, 8.16, 8.23, 8.28) need implemented controls, not a re-mapped SoA. Auditors open with the new controls precisely because paper migrations fail there.
A.8.8 evidence is the full loop: scan → risk evaluation → fix within defined timelines → verification. A folder of PDFs is half a control.
A.8.12 asks for detection AND prevention/response on real channels — sampled alerts with disposition beat a licence invoice.
A.8.10 requires demonstrable deletion when data is no longer required — retention schedule plus executed deletion records; "we keep everything" is now a nonconformity.
Evidence an auditor accepts
- PAM records and privileged-account reviews (A.8.2)
- Hardening baselines with drift/compliance reports (A.8.9)
- Vulnerability-management loop: scans, SLAs, remediation, verification (A.8.8)
- DLP policy, channel coverage and sampled alert dispositions (A.8.12)
- Monitoring use-cases, alert samples and response records (A.8.16)
- Secure-coding standard, code-review/SAST evidence, environment separation (A.8.28/8.31)
- Retention schedule + executed deletion records (A.8.10)
Annex A.8 FAQ
Which Annex A controls are new in ISO 27001:2022?
Eleven: threat intelligence (5.7), cloud services (5.23), ICT readiness for BC (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), DLP (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28).
Is the 2013 version still auditable?
No — the transition period ended 31 October 2025; certification audits now run against ISO/IEC 27001:2022.
Does A.8 require specific tools?
The standard mandates outcomes, not products — but for controls like DLP, monitoring and configuration management, auditors expect tooling-scale evidence in any non-trivial environment.
Annex A.8 in your ISMS
We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.
