top of page
bg_3.png
bg_3.png

ISO 27001 Annex A Controls Explained Organizational People Physical and Technological Security

6 days ago
9 min read

Annex A is where security planning becomes working practice. It gives organizations a structured set of controls to reduce information security risk, prove accountability, and support ISO 27001 certification.



The current Annex A groups 93 controls into four themes:


Theme

Number of controls

Main purpose

Organizational controls

37

Governance, policy, risk, supplier management, and operating rules

People controls

8

Employee, contractor, and user behavior before, during, and after employment

Physical controls

14

Protection of sites, equipment, entry points, and physical assets

Technological controls

34

Technical protection for systems, networks, data, and applications


These themes help organizations choose controls based on risk. They also make the Statement of Applicability easier to explain to auditors, executives, and customers.


Wide-angle view of a secured data center corridor with locked server cabinets
Annex A covers governance, people, facilities, and technology.

ISO 27001 Annex A Controls - Organizational controls set the rules for security


Organizational controls define how security is governed. They answer basic questions that auditors and customers will ask.


Who owns security? What policies apply? How are risks reviewed? How are suppliers checked? How does the organization respond to incidents?


This is the largest Annex A theme because weak governance creates gaps everywhere else. A company can have strong firewalls and locked doors, but still fail if no one reviews access, signs off risks, or manages third-party exposure.


Key organizational controls often include:


  • Information security policies

  • Information security roles and responsibilities

  • Segregation of duties

  • Management of information security risks

  • Threat intelligence

  • Information security in project management

  • Supplier relationship management

  • Incident management planning

  • Business continuity and ICT readiness

  • Legal, statutory, regulatory, and contractual requirements

  • Records protection

  • Privacy and protection of personally identifiable information


For certification, these controls carry real weight. ISO 27001 requires an organization to understand its risks, decide how to treat them, and keep evidence. Annex A helps translate those decisions into control areas.


Why these controls matter


Organizational controls prevent security from depending on one person’s memory or effort. They create repeatable decisions.


For example, supplier management matters because many incidents begin outside the primary organization. A payroll vendor, cloud service provider, or managed service partner may store or process sensitive data. Without supplier rules, teams may approve vendors without reviewing access, data handling, incident notification duties, or subcontractor use.


Incident management is another strong example. If a ransomware alert appears at 2:00 a.m., staff need a clear process. They need to know who investigates, who isolates systems, who contacts legal counsel, and who communicates with customers if needed. Slow decisions increase damage.


Practical implementation tips


Start with risk, not paperwork. Build controls around the assets and processes that matter most.


Useful steps include:


  • Create a clear information security policy approved by leadership.

  • Assign named owners for risk management, access control, supplier review, and incident response.

  • Keep a risk register with treatment decisions and review dates.

  • Maintain a Statement of Applicability that explains which Annex A controls apply and why.

  • Add security review gates to major projects.

  • Use supplier questionnaires and contract clauses for critical vendors.

  • Run incident response exercises at least on a planned schedule.

  • Keep evidence simple and audit-ready, such as approvals, review logs, training records, and test results.


A startup handling customer payment data may begin with a short supplier review process, a simple incident response plan, and clear access approval rules. As it grows, it can add formal risk committees, vendor tiers, and more detailed continuity testing.


The point is consistency. Controls should match the risk and maturity of the business.


Close-up view of labeled security binders beside a printed risk register in a locked archive room
Good governance depends on records that people can find and trust.

People controls reduce human risk


People controls address one of the most common causes of security failure: human action. That includes honest mistakes, weak onboarding, poor access removal, social engineering, and misuse of information.


This theme applies to employees, contractors, temporary staff, and anyone with access to business information.


Key people controls include:


  • Screening

  • Terms and conditions of employment

  • Information security awareness, education, and training

  • Disciplinary process

  • Responsibilities after termination or change of employment

  • Confidentiality or non-disclosure agreements

  • Remote working

  • Information security event reporting


People controls are not limited to training. Training matters, but it only works when roles, expectations, reporting paths, and exit processes are clear.


Why these controls matter


Many incidents start with routine actions. A user clicks a phishing link. A contractor keeps access after a project ends. A new employee stores customer files in an unapproved location because no one explained the rules.


People controls reduce those risks before they turn into incidents.


Take access removal. If a system administrator leaves the company and their account stays active, the organization has an avoidable exposure. Even if the person has no bad intent, unused accounts can be abused if credentials are stolen.


Confidentiality controls also matter in smaller businesses. A software developer, accountant, or support contractor may see customer records, financial data, or source code. Written confidentiality duties help set legal and operational expectations.


Practical implementation tips


Build people controls into the employee life cycle.


Before employment or engagement:


  • Screen roles based on risk.

  • Define security duties in contracts and role descriptions.

  • Require confidentiality agreements where sensitive information is involved.


During employment:


  • Provide security awareness training at onboarding.

  • Repeat training when risks change.

  • Teach staff how to report suspicious email, lost devices, or accidental data exposure.

  • Use role-based training for administrators, developers, finance staff, and support teams.

  • Keep training records.


At termination or role change:


  • Disable or adjust access quickly.

  • Recover devices, keys, tokens, and access badges.

  • Remind departing staff of confidentiality duties.

  • Review shared accounts, group access, and privileged permissions.


Real-world example: A finance employee receives an email asking for an urgent bank detail change. Because the organization trained staff to verify payment changes through a separate trusted channel, the employee calls the known supplier contact and discovers the request is fraudulent. The control works because training connects to a practical process.


Security awareness should be specific. “Do not click suspicious links” is too broad. Better guidance explains how to identify unusual sender behavior, unexpected attachments, pressure tactics, and requests to bypass normal approval.


Eye-level view of a security awareness wall poster beside a badge return box in a staff entry area
People controls work best when security steps fit daily routines.

Physical controls protect places, equipment, and assets


Physical controls protect information by protecting the spaces and equipment where it lives. They apply to server rooms, storage areas, network closets, records archives, laptops, removable media, and facilities that support critical work.


Digital security fails if someone can walk into a server room, remove a hard drive, photograph sensitive papers, or plug into an exposed network port.


Key physical controls include:


  • Physical security perimeters

  • Physical entry controls

  • Securing offices, rooms, and facilities

  • Physical security monitoring

  • Protection against physical and environmental threats

  • Working in secure areas

  • Clear desk and clear screen practices

  • Equipment siting and protection

  • Security of assets off-premises

  • Storage media handling

  • Supporting utilities

  • Cabling security

  • Equipment maintenance

  • Secure disposal or reuse of equipment


Why these controls matter


Physical incidents cause real information security damage. A stolen laptop may expose customer data. A visitor in an unrestricted area may see confidential records. Fire, water damage, or power failure may take critical systems offline.


Physical controls also support legal and contractual obligations. If an organization claims that customer data is protected, it must control both logical and physical access.


Practical implementation tips


Apply controls based on site risk.


For a small office or shared workspace:


  • Keep networking equipment in locked cabinets.

  • Use visitor sign-in and escort rules.

  • Lock paper records in cabinets or archive rooms.

  • Require screen locking when devices are unattended.

  • Use privacy filters where sensitive work happens in open areas.

  • Define rules for laptops used at home or while traveling.


For facilities that host servers or critical equipment:


  • Use access control on server rooms and network closets.

  • Restrict access to approved personnel.

  • Review access lists on a schedule.

  • Log entry activity.

  • Monitor for fire, water, temperature, and power issues.

  • Protect cabling in public or shared areas.

  • Use secure disposal for drives, backup media, and printed records.


A practical example: An organization stores backup drives in an unlocked cabinet near its server rack. During a risk review, the team classifies those drives as sensitive because they contain full system backups. It moves them to a locked fire-resistant safe, limits access, and records media removal. That simple change reduces theft, tampering, and recovery risk.


Another example involves equipment disposal. When laptops are reassigned, data must be erased using an approved method before reuse. When drives are retired, disposal needs proof, such as a destruction certificate or internal record. This protects the organization if questions arise later.


Physical controls do not need to be expensive. A locked cabinet, entry log, cable management, and clean desk rules can close common gaps.


Low-angle view of a locked network cabinet with sealed cable conduits in a utility room
Physical controls protect the systems that store and move information.

Technological controls secure systems, data, and networks


Technological controls are the technical safeguards used to protect information systems. They cover identity, access, data protection, logging, malware defense, network security, configuration, backup, and secure development.


This is the area many people think of first when they hear information security. It is vital, but it only works when connected to the other themes. A strong technical control still needs ownership, user discipline, and physical protection.


Key technological controls include:


  • User endpoint devices

  • Privileged access rights

  • Information access restriction

  • Access to source code

  • Secure authentication

  • Capacity management

  • Protection against malware

  • Technical vulnerability management

  • Configuration management

  • Information deletion

  • Data masking

  • Data leakage prevention

  • Monitoring activities

  • Clock synchronization

  • Use of cryptography

  • Secure coding

  • Network security

  • Segregation of networks

  • Web filtering

  • Backup

  • Logging

  • Secure system architecture and engineering principles

  • Security testing in development and acceptance


Why these controls matter


Technical controls reduce the chance that attackers, malware, or mistakes will expose information or interrupt operations.


Access control is a clear example. Users should only have the access needed for their role. Privileged accounts need stricter treatment because they can change systems, view sensitive data, or disable controls.


Logging is another example. Without logs, incident response becomes guesswork. Good logs help teams answer basic questions: What happened? Which account was used? Which system changed? When did the activity start?


Vulnerability management also matters. Attackers often target known weaknesses for which patches already exist. A consistent process to identify, assess, and fix vulnerabilities lowers this exposure.


Practical implementation tips


Focus on the controls that reduce the largest risks first.


For identity and access:


  • Require unique user accounts.

  • Use multi-factor authentication for remote access and privileged users.

  • Review user access on a schedule.

  • Remove unused accounts.

  • Separate administrator accounts from daily-use accounts.


For systems and networks:


  • Maintain approved secure configurations.

  • Patch operating systems, applications, and network devices.

  • Segment networks where sensitive systems need higher protection.

  • Restrict inbound and outbound traffic based on business need.

  • Protect endpoints against malware.

  • Monitor security alerts and investigate unusual activity.


For data:


  • Encrypt sensitive data where risk requires it.

  • Back up critical systems and test restoration.

  • Control copying to removable media.

  • Delete information when retention periods end.

  • Mask or reduce sensitive data in test environments.


For applications:


  • Use secure coding rules.

  • Review source code access.

  • Test security before production release.

  • Track and fix application vulnerabilities.

  • Separate development, testing, and production environments.


Real-world example: A company stores customer files in a shared folder. Over time, too many employees gain access. During a review, the team maps user permissions to job roles, removes unnecessary access, and adds approval for future requests. Later, when one account is compromised through phishing, the attacker cannot reach the full customer file store. The access control review limits the damage.


Another example involves backups. A business runs daily backups but never tests a restore. After a server failure, it discovers that a key database was excluded. A better control requires scheduled restore tests and documented results. Backups only count when recovery works.


The ISO 27001 Annex A controls help connect these technical tasks to business risk. That link matters during audits and during real incidents.


Close-up view of a security operations monitor showing system logs in a dark equipment room
Technological controls need monitoring, testing, and regular review.

The practical way to use Annex A


Annex A is not a checklist to copy into policy. It is a control catalog. The right approach is to select and apply controls based on risk, legal duties, customer needs, and business operations.


A sound process looks like this:


  1. Identify information assets and business processes.

  2. Assess risks to confidentiality, integrity, and availability.

  3. Choose risk treatment options.

  4. Select applicable Annex A controls.

  5. Document inclusion and exclusion in the Statement of Applicability.

  6. Implement controls with clear owners.

  7. Keep evidence.

  8. Review and improve controls as the business changes.


This keeps the information security management system practical. It also helps avoid a common mistake: writing policies that do not match how work actually happens.


The four themes work together. Organizational controls define direction. People controls shape behavior. Physical controls protect places and assets. Technological controls defend systems and data.


A certification audit will test that connection. Auditors will look for evidence that controls are selected, implemented, monitored, and improved. Customers will want the same assurance, even if they never read the full standard.


Start with the most important risks. Fix the controls that protect sensitive data, critical systems, legal obligations, and customer commitments. Then build a review cycle that keeps those controls current.


That is the value of Annex A. It turns security from scattered tasks into a managed system.

ISO 27001 Annex A Controls


Comments


bottom of page