Key Takeaways
1. The ISO 27001 Controls List Contains 93 Controls Organized Into Four Categories: Under ISO/IEC 27001:2022, Annex A includes 93 controls grouped into Organizational, People, Physical, and Technological controls, providing a modernized framework for managing information security risks.
2. ISO 27001 Uses a Risk-Based Approach Rather Than a Checklist Approach: Organizations are not required to implement all 93 ISO 27001 controls. Instead, they must assess risks, determine which controls are applicable, and justify their decisions through the SoA.
3. Effective Control Implementation Supports Both Security and Certification Success: ISO 27001 controls help organizations strengthen governance, reduce cybersecurity risk, improve operational resilience, and demonstrate compliance during certification audits. Success depends on aligning controls with business objectives and maintaining them as part of a broader ISMS.
Organizations pursuing ISO 27001 certification quickly discover that understanding the ISO 27001 controls list is one of the most important—and often most confusing—parts of the compliance journey. Questions such as “How many controls are in ISO 27001?” and “Which controls apply to my organization?” are common among security leaders, compliance professionals, and business executives evaluating the standard.
The answer is not as straightforward as many people expect. ISO 27001 is a risk-based framework, meaning organizations are not required to implement every control in exactly the same way. However, understanding the structure and purpose of the ISO 27001 controls is essential for building an effective Information Security Management System (ISMS) and achieving certification.
In this guide, we’ll break down the ISO 27001 controls list, explain how the controls are organized, and explore what they mean for organizations seeking stronger information security and compliance.
What Are ISO 27001 Controls?
ISO 27001 controls are safeguards designed to manage and reduce information security risks. They provide organizations with a structured set of security measures that can be implemented to protect confidential, sensitive, and critical information assets.
The controls are documented in Annex A of ISO/IEC 27001 and are intended to support the organization’s broader ISMS. While the standard itself establishes requirements for creating and maintaining an ISMS, the controls provide practical ways to address identified risks.
Organizations select and implement controls based on their unique risk environment, regulatory obligations, customer expectations, and business objectives.
How Many Controls Are in ISO 27001?
Under the current ISO/IEC 27001:2022 standard, there are 93 controls included in Annex A. This represents a significant update from the previous ISO/IEC 27001:2013 version, which contained 114 controls across 14 domains.
The 2022 revision streamlined and modernized the controls by consolidating overlapping requirements; removing outdated controls; adding controls for emerging cybersecurity risks; reorganizing controls into a simpler structure; and better aligning with today’s cloud, remote work, and threat environments.
Rather than 14 domains, the current ISO 27001 controls list is organized into four primary themes:
- Organizational Controls (37)
- People Controls (8)
- Physical Controls (14)
- Technological Controls (34)
This new structure makes the controls easier to understand and implement while maintaining the flexibility that organizations need to address unique risks.
Understanding the Four Categories of ISO 27001 Controls
1. Organizational Controls (37 Controls)
Organizational controls establish the governance framework for information security across the business. These controls focus on policies, procedures, accountability, risk management, and oversight.
Examples include:
- Information security policies
- Risk management processes
- Asset management
- Supplier security management
- Business continuity planning
- Incident management
- Compliance obligations
- Threat intelligence activities
These controls create the foundation for a mature information security program by ensuring security responsibilities are clearly defined and consistently managed.
2. People Controls (8 Controls)
Human error remains one of the leading causes of security incidents. People controls help organizations address security risks associated with employees, contractors, and third parties.
Examples include:
- Employee screening
- Terms and conditions of employment
- Security awareness training
- Disciplinary processes
- Responsibilities after termination
- Confidentiality agreements
Strong people controls help create a security-conscious culture and reduce the likelihood of insider threats, accidental disclosures, and social engineering attacks.
3. Physical Controls (14 Controls)
Physical controls focus on protecting facilities, equipment, and physical assets from unauthorized access, damage, or theft.
Examples include:
- Secure facility access
- Physical security monitoring
- Equipment protection
- Environmental controls
- Secure disposal of assets
- Clear desk and clear screen policies
While cybersecurity often receives the most attention, physical security remains a critical component of information protection and regulatory compliance.
4. Technological Controls (34 Controls)
Technological controls are often the most visible portion of the ISO 27001 controls list because they directly address cybersecurity threats and technical safeguards.
Examples include:
- Identity and access management
- Encryption
- Network security
- Secure authentication
- Vulnerability management
- Malware protection
- Logging and monitoring
- Data leakage prevention
- Secure development practices
- Cloud security controls
These controls help organizations defend against modern cyber threats while supporting confidentiality, integrity, and availability of information.
New Controls Introduced in ISO 27001:2022
One of the most notable aspects of the updated ISO 27001 controls list is the introduction of several new controls designed to address modern security challenges.
New controls include:
- Threat intelligence
- Information security for cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
These additions reflect the growing importance of cloud adoption, ransomware defense, privacy protection, and proactive threat management.

Do Organizations Need to Implement All 93 Controls?
No, organizations do not need to implement all 93 ISO 27001 controls.
One of the defining characteristics of ISO 27001 is its risk-based approach. Organizations are expected to evaluate risks and determine which controls are necessary to mitigate those risks effectively. This process occurs through the organization’s risk assessment and risk treatment activities.
For each Annex A control, organizations must determine whether the control is:
- Applicable
- Not applicable
- Already implemented
- Planned for implementation
These decisions are documented within the Statement of Applicability (SoA), a key document reviewed during the ISO 27001 audit process. The SoA explains which controls are selected and why, which controls are excluded as well as the organization’s justification for those exclusions, and overarching control implementation status. This flexibility allows organizations to tailor their security programs while still meeting certification requirements.
How ISO 27001 Controls Support Certification
Many organizations mistakenly assume ISO 27001 certification is simply a checklist exercise focused on implementing controls.
In reality, certification auditors evaluate both the effectiveness of the organization’s ISMS as well as the appropriateness and implementation of selected controls. Successful certification requires demonstrating that:
- Risks are properly identified
- Controls address those risks
- Policies and procedures are documented
- Controls operate effectively
- Continuous improvement processes exist
The controls are important, but they are only one component of a broader management system designed to sustain information security over time.
Common Challenges Organizations Face When Implementing ISO 27001 Controls
Organizations often encounter several obstacles when implementing ISO 27001 controls.
- Overengineering Controls: Many organizations implement controls that are more complex than necessary. Effective controls should align with actual risk levels rather than theoretical best practices.
- Poor Documentation: Even well-implemented controls can create certification challenges if supporting documentation is incomplete or inconsistent.
- Lack of Executive Support: Information security initiatives require leadership commitment, adequate resources, and organizational accountability.
- Misunderstanding Control Applicability: Organizations sometimes assume every control must be implemented, leading to unnecessary effort and increased costs.
- Managing Technical and Administrative Controls Together: ISO 27001 requires coordination between IT, security, legal, HR, operations, and executive leadership teams, which can create implementation challenges without clear governance.
How IS Partners Helps Organizations Navigate ISO 27001 Controls
Understanding the ISO 27001 controls list is only the beginning. Successfully implementing those controls within a risk-based ISMS requires strategic planning, technical expertise, and audit experience.
As an ANAB-accredited ISO/IEC 27001 certification body, IS Partners helps organizations evaluate security risks, implement effective controls, prepare for certification audits, and maintain compliance over time. Our team combines deep technical knowledge with practical business insight to help organizations build security programs that not only satisfy certification requirements but also strengthen overall resilience.
Whether you’re just beginning your ISO 27001 journey or preparing for an upcoming certification audit, IS Partners can help you navigate the complexities of ISO 27001 controls and achieve your compliance goals with confidence. Click here to explore our full list of ISO 27001 compliance and internal audit services.
What Should You Do Next?
Perform an ISO 27001 Gap Assessment Against Annex A Controls: Evaluate your existing security program against the current ISO 27001 controls list to identify which of the 93 controls are already implemented, partially implemented, or missing. This provides a clear baseline for certification readiness and risk management planning.
Conduct a Risk Assessment and Develop an SoA: Since ISO 27001 follows a risk-based approach, organizations should formally assess information security risks and determine which controls are applicable to their environment. Document these decisions in an SoA to support audit readiness and compliance efforts.
Establish a Structured ISMS Governance Program: Assign control owners, document policies and procedures, and implement ongoing monitoring processes to ensure controls remain effective. Strong governance helps organizations maintain compliance, support continuous improvement, and simplify future ISO 27001 audits.








