ISO 27001 Annex A Controls Explained Organizational People Physical and Technological Security
Annex A is where security planning becomes working practice. It gives organizations a structured set of controls to reduce information security risk, prove accountability, and support ISO 27001 certification.
The current Annex A groups 93 controls into four themes:
Theme | Number of controls | Main purpose |
Organizational controls | 37 | Governance, policy, risk, supplier management, and operating rules |
People controls | 8 | Employee, contractor, and user behavior before, during, and after employment |
Physical controls | 14 | Protection of sites, equipment, entry points, and physical assets |
Technological controls | 34 | Technical protection for systems, networks, data, and applications |
These themes help organizations choose controls based on risk. They also make the Statement of Applicability easier to explain to auditors, executives, and customers.

ISO 27001 Annex A Controls - Organizational controls set the rules for security
Organizational controls define how security is governed. They answer basic questions that auditors and customers will ask.
Who owns security? What policies apply? How are risks reviewed? How are suppliers checked? How does the organization respond to incidents?
This is the largest Annex A theme because weak governance creates gaps everywhere else. A company can have strong firewalls and locked doors, but still fail if no one reviews access, signs off risks, or manages third-party exposure.
Key organizational controls often include:
Information security policies
Information security roles and responsibilities
Segregation of duties
Management of information security risks
Threat intelligence
Information security in project management
Supplier relationship management
Incident management planning
Business continuity and ICT readiness
Legal, statutory, regulatory, and contractual requirements
Records protection
Privacy and protection of personally identifiable information
For certification, these controls carry real weight. ISO 27001 requires an organization to understand its risks, decide how to treat them, and keep evidence. Annex A helps translate those decisions into control areas.
Why these controls matter
Organizational controls prevent security from depending on one person’s memory or effort. They create repeatable decisions.
For example, supplier management matters because many incidents begin outside the primary organization. A payroll vendor, cloud service provider, or managed service partner may store or process sensitive data. Without supplier rules, teams may approve vendors without reviewing access, data handling, incident notification duties, or subcontractor use.
Incident management is another strong example. If a ransomware alert appears at 2:00 a.m., staff need a clear process. They need to know who investigates, who isolates systems, who contacts legal counsel, and who communicates with customers if needed. Slow decisions increase damage.
Practical implementation tips
Start with risk, not paperwork. Build controls around the assets and processes that matter most.
Useful steps include:
Create a clear information security policy approved by leadership.
Assign named owners for risk management, access control, supplier review, and incident response.
Keep a risk register with treatment decisions and review dates.
Maintain a Statement of Applicability that explains which Annex A controls apply and why.
Add security review gates to major projects.
Use supplier questionnaires and contract clauses for critical vendors.
Run incident response exercises at least on a planned schedule.
Keep evidence simple and audit-ready, such as approvals, review logs, training records, and test results.
A startup handling customer payment data may begin with a short supplier review process, a simple incident response plan, and clear access approval rules. As it grows, it can add formal risk committees, vendor tiers, and more detailed continuity testing.
The point is consistency. Controls should match the risk and maturity of the business.

People controls reduce human risk
People controls address one of the most common causes of security failure: human action. That includes honest mistakes, weak onboarding, poor access removal, social engineering, and misuse of information.
This theme applies to employees, contractors, temporary staff, and anyone with access to business information.
Key people controls include:
Screening
Terms and conditions of employment
Information security awareness, education, and training
Disciplinary process
Responsibilities after termination or change of employment
Confidentiality or non-disclosure agreements
Remote working
Information security event reporting
People controls are not limited to training. Training matters, but it only works when roles, expectations, reporting paths, and exit processes are clear.
Why these controls matter
Many incidents start with routine actions. A user clicks a phishing link. A contractor keeps access after a project ends. A new employee stores customer files in an unapproved location because no one explained the rules.
People controls reduce those risks before they turn into incidents.
Take access removal. If a system administrator leaves the company and their account stays active, the organization has an avoidable exposure. Even if the person has no bad intent, unused accounts can be abused if credentials are stolen.
Confidentiality controls also matter in smaller businesses. A software developer, accountant, or support contractor may see customer records, financial data, or source code. Written confidentiality duties help set legal and operational expectations.
Practical implementation tips
Build people controls into the employee life cycle.
Before employment or engagement:
Screen roles based on risk.
Define security duties in contracts and role descriptions.
Require confidentiality agreements where sensitive information is involved.
During employment:
Provide security awareness training at onboarding.
Repeat training when risks change.
Teach staff how to report suspicious email, lost devices, or accidental data exposure.
Use role-based training for administrators, developers, finance staff, and support teams.
Keep training records.
At termination or role change:
Disable or adjust access quickly.
Recover devices, keys, tokens, and access badges.
Remind departing staff of confidentiality duties.
Review shared accounts, group access, and privileged permissions.
Real-world example: A finance employee receives an email asking for an urgent bank detail change. Because the organization trained staff to verify payment changes through a separate trusted channel, the employee calls the known supplier contact and discovers the request is fraudulent. The control works because training connects to a practical process.
Security awareness should be specific. “Do not click suspicious links” is too broad. Better guidance explains how to identify unusual sender behavior, unexpected attachments, pressure tactics, and requests to bypass normal approval.

Physical controls protect places, equipment, and assets
Physical controls protect information by protecting the spaces and equipment where it lives. They apply to server rooms, storage areas, network closets, records archives, laptops, removable media, and facilities that support critical work.
Digital security fails if someone can walk into a server room, remove a hard drive, photograph sensitive papers, or plug into an exposed network port.
Key physical controls include:
Physical security perimeters
Physical entry controls
Securing offices, rooms, and facilities
Physical security monitoring
Protection against physical and environmental threats
Working in secure areas
Clear desk and clear screen practices
Equipment siting and protection
Security of assets off-premises
Storage media handling
Supporting utilities
Cabling security
Equipment maintenance
Secure disposal or reuse of equipment
Why these controls matter
Physical incidents cause real information security damage. A stolen laptop may expose customer data. A visitor in an unrestricted area may see confidential records. Fire, water damage, or power failure may take critical systems offline.
Physical controls also support legal and contractual obligations. If an organization claims that customer data is protected, it must control both logical and physical access.
Practical implementation tips
Apply controls based on site risk.
For a small office or shared workspace:
Keep networking equipment in locked cabinets.
Use visitor sign-in and escort rules.
Lock paper records in cabinets or archive rooms.
Require screen locking when devices are unattended.
Use privacy filters where sensitive work happens in open areas.
Define rules for laptops used at home or while traveling.
For facilities that host servers or critical equipment:
Use access control on server rooms and network closets.
Restrict access to approved personnel.
Review access lists on a schedule.
Log entry activity.
Monitor for fire, water, temperature, and power issues.
Protect cabling in public or shared areas.
Use secure disposal for drives, backup media, and printed records.
A practical example: An organization stores backup drives in an unlocked cabinet near its server rack. During a risk review, the team classifies those drives as sensitive because they contain full system backups. It moves them to a locked fire-resistant safe, limits access, and records media removal. That simple change reduces theft, tampering, and recovery risk.
Another example involves equipment disposal. When laptops are reassigned, data must be erased using an approved method before reuse. When drives are retired, disposal needs proof, such as a destruction certificate or internal record. This protects the organization if questions arise later.
Physical controls do not need to be expensive. A locked cabinet, entry log, cable management, and clean desk rules can close common gaps.

Technological controls secure systems, data, and networks
Technological controls are the technical safeguards used to protect information systems. They cover identity, access, data protection, logging, malware defense, network security, configuration, backup, and secure development.
This is the area many people think of first when they hear information security. It is vital, but it only works when connected to the other themes. A strong technical control still needs ownership, user discipline, and physical protection.
Key technological controls include:
User endpoint devices
Privileged access rights
Information access restriction
Access to source code
Secure authentication
Capacity management
Protection against malware
Technical vulnerability management
Configuration management
Information deletion
Data masking
Data leakage prevention
Monitoring activities
Clock synchronization
Use of cryptography
Secure coding
Network security
Segregation of networks
Web filtering
Backup
Logging
Secure system architecture and engineering principles
Security testing in development and acceptance
Why these controls matter
Technical controls reduce the chance that attackers, malware, or mistakes will expose information or interrupt operations.
Access control is a clear example. Users should only have the access needed for their role. Privileged accounts need stricter treatment because they can change systems, view sensitive data, or disable controls.
Logging is another example. Without logs, incident response becomes guesswork. Good logs help teams answer basic questions: What happened? Which account was used? Which system changed? When did the activity start?
Vulnerability management also matters. Attackers often target known weaknesses for which patches already exist. A consistent process to identify, assess, and fix vulnerabilities lowers this exposure.
Practical implementation tips
Focus on the controls that reduce the largest risks first.
For identity and access:
Require unique user accounts.
Use multi-factor authentication for remote access and privileged users.
Review user access on a schedule.
Remove unused accounts.
Separate administrator accounts from daily-use accounts.
For systems and networks:
Maintain approved secure configurations.
Patch operating systems, applications, and network devices.
Segment networks where sensitive systems need higher protection.
Restrict inbound and outbound traffic based on business need.
Protect endpoints against malware.
Monitor security alerts and investigate unusual activity.
For data:
Encrypt sensitive data where risk requires it.
Back up critical systems and test restoration.
Control copying to removable media.
Delete information when retention periods end.
Mask or reduce sensitive data in test environments.
For applications:
Use secure coding rules.
Review source code access.
Test security before production release.
Track and fix application vulnerabilities.
Separate development, testing, and production environments.
Real-world example: A company stores customer files in a shared folder. Over time, too many employees gain access. During a review, the team maps user permissions to job roles, removes unnecessary access, and adds approval for future requests. Later, when one account is compromised through phishing, the attacker cannot reach the full customer file store. The access control review limits the damage.
Another example involves backups. A business runs daily backups but never tests a restore. After a server failure, it discovers that a key database was excluded. A better control requires scheduled restore tests and documented results. Backups only count when recovery works.
The ISO 27001 Annex A controls help connect these technical tasks to business risk. That link matters during audits and during real incidents.

The practical way to use Annex A
Annex A is not a checklist to copy into policy. It is a control catalog. The right approach is to select and apply controls based on risk, legal duties, customer needs, and business operations.
A sound process looks like this:
Identify information assets and business processes.
Assess risks to confidentiality, integrity, and availability.
Choose risk treatment options.
Select applicable Annex A controls.
Document inclusion and exclusion in the Statement of Applicability.
Implement controls with clear owners.
Keep evidence.
Review and improve controls as the business changes.
This keeps the information security management system practical. It also helps avoid a common mistake: writing policies that do not match how work actually happens.
The four themes work together. Organizational controls define direction. People controls shape behavior. Physical controls protect places and assets. Technological controls defend systems and data.
A certification audit will test that connection. Auditors will look for evidence that controls are selected, implemented, monitored, and improved. Customers will want the same assurance, even if they never read the full standard.
Start with the most important risks. Fix the controls that protect sensitive data, critical systems, legal obligations, and customer commitments. Then build a review cycle that keeps those controls current.
That is the value of Annex A. It turns security from scattered tasks into a managed system.
ISO 27001 Annex A Controls



Comments