We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ISO/IEC 27001:2022 · 93 controls · 4 themes

Annex A, explained properly

One deep guide per theme: the controls that decide audits, where ISMS programmes actually fail, and the evidence certification auditors accept — written for the 2022 control set that all audits now run against.

Annex A.5 · 37 controls
Organizational Controls

The largest theme — 37 controls covering policy, roles, supplier risk, cloud, incident management and legal co

Annex A.6 · 8 controls
People Controls

Eight controls, one theme: the human layer — screening, terms, awareness, discipline, remote working and repor

Annex A.7 · 14 controls
Physical Controls

Fourteen controls from perimeters to clear desks. The 2022 addition — physical security monitoring — formalise

Annex A.8 · 34 controls
Technological Controls

The engineering theme: 34 controls from endpoint protection to secure coding. Eight of the eleven controls new

Start with the free self-assessment, or go straight to ISO 27001 services.