Annex A of ISO 27001:2022 includes 93 controls grouped under four themes:

Organizational Controls (37)
People Controls (8)
Physical Controls (14)
Technological Controls (34)

Annex A controls must be selected based on your business’s risk profile. The controls that you include or exclude are documented with reasons in the Statement of Applicability. 

As of 2022, Annex A contained 114 controls but this was revised when ISO 27001:2022 was rolled out. The reduction is a result of a merging, renaming, and reclassification exercise. Furthermore, 11 new controls have been introduced to cover modern security concerns.

ISO 27001 Controls: A Guide to Implementing Annex A Controls

ISO 27001 Asset Management: Safeguard Your Information Assets

ISO 27001:2022 Annex A: The New Security Controls

The Sprinto advantage

From automating compliance checklists to monitoring security controls in real-time and more, Sprinto does the heavy lifting for you to get you compliant. ISO 27001 isn’t a one-time exercise. It requires constant monitoring and improvement to ensure you stay compliant. Sprinto doesn’t just help you pass the audit it helps you stay continuously compliant and add more compliances to your kitty with very little additional lift.
hub-iso-dark
Sprinto: Your ally for all things compliance, risk, governance
support-team