Get Demo
↑

The 93 ISO 27001:2022 Controls in 4 Themes: Organizational, People, Physical, Technological

ISO/IEC 27001:2022 Annex A: 93 controls across Organizational (37), People (8), Physical (14).

Published: September 2026 Compliance · ISO 27001 10–14 min read

ISO/IEC 27001:2022 Annex A lists 93 information security controls in four themes, derived from and aligned with ISO/IEC 27002:2022 Clauses 5–8. Use this page as the count/theme hub; deepen with A.5 and A.8 theme guides and selected control explainers.

Locked counts: 37 + 8 + 14 + 34 = 93. These figures come from ISO/IEC 27001:2022 Table A.1 / ISO/IEC 27002:2022 structure (also summarized in IAF MD 26).

Four Themes

Theme
Range
Count
Guide
Organizational
A.5.1–A.5.37
37
People
A.6.1–A.6.8
8
—
Physical
A.7.1–A.7.14
14
—
Technological
A.8.1–A.8.34
34

Spotlight Controls (New / High-Search)

Operationalize ISO 27001:2022 with Continuous Evidence

CyberSilo CSA tracks SoA and mandatory records; ThreatHawk supports logging and monitoring artefacts for technological controls.

Frequently Asked Questions

How many Annex A controls does ISO 27001:2022 have?

93 controls in four themes, aligned with ISO/IEC 27002:2022.

What are the four theme counts?

Organizational 37 (A.5.1–A.5.37), People 8 (A.6.1–A.6.8), Physical 14 (A.7.1–A.7.14), Technological 34 (A.8.1–A.8.34).

Must every control be implemented?

You must produce a Statement of Applicability (6.1.3 d). Controls may be excluded with justification; necessary controls from Annex A must not be omitted inadvertently.

ISO 27001 hub · 93 controls · SoA · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!