ISO 27001 implementation library

ISO 27001 Annex A control guides

Turn priority Annex A topics into proportionate implementation steps, useful evidence and audit-ready operating examples.

Browse by control category

Category 6

People controls

8 controls in the reference set, with dedicated implementation, evidence and audit guidance.

Explore people controls →

Category 7

Physical controls

14 controls in the reference set, with dedicated implementation, evidence and audit guidance.

Explore physical controls →

Annex A implementation guides

Control 5.1

Policies for information security

Set coherent, approved direction for information security and keep supporting policies aligned with business, risk and compliance needs.

Read the full guide →

Control 5.2

Information security roles and responsibilities

Allocate clear accountability and authority for security decisions and recurring activities.

Read the full guide →

Control 5.3

Segregation of duties

Reduce opportunities for error, misuse or concealment by separating incompatible responsibilities or applying compensating oversight.

Read the full guide →

Control 5.4

Management responsibilities

Ensure managers actively reinforce security expectations within the teams and processes they direct.

Read the full guide →

Control 5.5

Contact with authorities

Maintain usable routes for regulatory, law-enforcement and emergency contact when events or obligations require coordination.

Read the full guide →

Control 5.6

Contact with special interest groups

Use trusted professional and industry communities to stay informed about relevant security developments and good practice.

Read the full guide →

Control 5.7

Threat intelligence

Collect and evaluate relevant threat information so risk, monitoring and protective decisions reflect the current environment.

Read the full guide →

Control 5.8

Information security in project management

Integrate security risk and control decisions into project governance from initiation through delivery and closure.

Read the full guide →

Control 5.9

Inventory of information and other associated assets

Maintain a reliable view of information and supporting assets that need protection, including clear ownership and lifecycle accountability.

Read the full guide →

Control 5.10

Acceptable use of information and other associated assets

Set practical expectations for how people may use and protect information, devices, services and facilities.

Read the full guide →

Control 5.11

Return of assets

Recover organizational assets and information when roles, contracts or relationships change or end.

Read the full guide →

Control 5.12

Classification of information

Apply consistent sensitivity and handling decisions to information based on business value, obligations and impact.

Read the full guide →

Control 5.13

Labelling of information

Communicate classification or handling needs in a usable form so people and systems can apply the right protections.

Read the full guide →

Control 5.14

Information transfer

Protect information while it is shared internally or externally through approved channels and accountable arrangements.

Read the full guide →

Control 5.15

Access control

Set risk-based principles for granting, using, reviewing and removing physical and logical access.

Read the full guide →

Control 5.16

Identity management

Manage identities consistently across creation, verification, change, suspension and removal.

Read the full guide →

Control 5.17

Authentication information

Issue, protect, reset and retire credentials and authentication secrets through controlled processes.

Read the full guide →

Control 5.18

Access rights

Approve, provision, review and remove access rights according to role, need and changing employment or supplier status.

Read the full guide →

Control 5.19

Information security in supplier relationships

Identify and manage security risk arising from suppliers and the services, information or systems they support.

Read the full guide →

Control 5.20

Addressing information security within supplier agreements

Translate supplier risk and service expectations into clear, enforceable security terms and responsibilities.

Read the full guide →

Control 5.21

Managing information security in the ICT supply chain

Extend supplier assurance to relevant technology dependencies, subcontractors, components and lifecycle risks.

Read the full guide →

Control 5.22

Monitoring, review and change management of supplier services

Review supplier security performance and control material service changes throughout the relationship.

Read the full guide →

Control 5.23

Information security for use of cloud services

Govern cloud selection, use, shared responsibilities, changes and exit according to information-security risk.

Read the full guide →

Control 5.24

Information security incident management planning and preparation

Prepare roles, playbooks, communication and resources before security incidents occur.

Read the full guide →

Control 5.25

Assessment and decision on information security events

Triage reported events consistently and decide whether escalation, response or other handling is required.

Read the full guide →

Control 5.26

Response to information security incidents

Coordinate containment, investigation, communication, recovery and accountable decision-making during incidents.

Read the full guide →

Control 5.27

Learning from information security incidents

Turn incident evidence into improvements to risks, controls, detection and response capability.

Read the full guide →

Control 5.28

Collection of evidence

Preserve reliable evidence when events may require investigation, disciplinary, contractual or legal action.

Read the full guide →

Control 5.29

Information security during disruption

Maintain essential security protections and risk decisions while normal operating arrangements are disrupted.

Read the full guide →

Control 5.30

ICT readiness for business continuity

Prepare and test technology recovery capability that supports prioritized business continuity needs.

Read the full guide →

Control 5.31

Legal, statutory, regulatory and contractual requirements

Identify, maintain and translate applicable obligations into owned security and compliance activities.

Read the full guide →

Control 5.32

Intellectual property rights

Protect and use intellectual property in accordance with ownership, licence and contractual conditions.

Read the full guide →

Control 5.33

Protection of records

Preserve records against loss, alteration, unauthorized access and premature disposal for required retention periods.

Read the full guide →

Control 5.34

Privacy and protection of PII

Apply privacy and personal-information protections that reflect applicable obligations, purposes and risk.

Read the full guide →

Control 5.35

Independent review of information security

Obtain objective review of whether security governance and arrangements remain suitable and effective.

Read the full guide →

Control 5.36

Compliance with policies, rules and standards for information security

Evaluate whether security requirements are followed and address deviations through accountable action.

Read the full guide →

Control 5.37

Documented operating procedures

Provide current, usable instructions where consistent security operation depends on repeatable execution.

Read the full guide →

Control 6.1

Screening

Apply proportionate pre-engagement checks for roles with access to sensitive information, systems or facilities.

Read the full guide →

Control 6.2

Terms and conditions of employment

Embed relevant security responsibilities and expectations into employment or engagement terms.

Read the full guide →

Control 6.3

Information security awareness, education and training

Build role-relevant understanding and capability, then evaluate whether learning changes behaviour and performance.

Read the full guide →

Control 6.4

Disciplinary process

Use a fair, communicated process for addressing deliberate or negligent breaches of security expectations.

Read the full guide →

Control 6.5

Responsibilities after termination or change of employment

Manage continuing obligations, access, assets and knowledge when a person changes role or leaves.

Read the full guide →

Control 6.6

Confidentiality or non-disclosure agreements

Use suitable confidentiality commitments that reflect information sensitivity, roles, jurisdictions and relationship lifecycle.

Read the full guide →

Control 6.7

Remote working

Protect information and services when work occurs away from controlled organizational locations.

Read the full guide →

Control 6.8

Information security event reporting

Give personnel simple, trusted routes for promptly reporting suspected events, weaknesses or unusual activity.

Read the full guide →

Control 7.1

Physical security perimeters

Define and protect physical boundaries around information, people and supporting assets according to risk.

Read the full guide →

Control 7.2

Physical entry

Authorize, record and review entry to controlled areas while managing visitors and access credentials.

Read the full guide →

Control 7.3

Securing offices, rooms and facilities

Apply proportionate protection to workplaces and facilities, including shared and outsourced locations.

Read the full guide →

Control 7.4

Physical security monitoring

Detect and review unauthorized or suspicious physical activity using proportionate monitoring and response.

Read the full guide →

Control 7.5

Protecting against physical and environmental threats

Reduce harm from fire, water, temperature, power, civil disruption and other relevant environmental hazards.

Read the full guide →

Control 7.6

Working in secure areas

Set behaviour and supervision expectations for people working within sensitive physical areas.

Read the full guide →

Control 7.7

Clear desk and clear screen

Reduce accidental exposure of sensitive information in offices, shared spaces and remote-work environments.

Read the full guide →

Control 7.8

Equipment siting and protection

Position and protect equipment against unauthorized access, observation, damage and environmental exposure.

Read the full guide →

Control 7.9

Security of assets off-premises

Protect devices, media and information when used, transported or stored outside organizational premises.

Read the full guide →

Control 7.10

Storage media

Control removable and other storage media through authorization, handling, transport, reuse and disposal.

Read the full guide →

Control 7.11

Supporting utilities

Protect information-processing facilities from loss or instability of power, cooling, communications and other utilities.

Read the full guide →

Control 7.12

Cabling security

Protect power and communications cabling from interception, interference and damage.

Read the full guide →

Control 7.13

Equipment maintenance

Maintain equipment safely and reliably while controlling access, information exposure and service records.

Read the full guide →

Control 7.14

Secure disposal or re-use of equipment

Remove or protect information before equipment is disposed of, returned, reassigned or reused.

Read the full guide →

Control 8.1

User endpoint devices

Apply managed security baselines and lifecycle controls to endpoints that access organizational information and services.

Read the full guide →

Control 8.2

Privileged access rights

Restrict, approve, monitor and review powerful access separately from routine user access.

Read the full guide →

Control 8.3

Information access restriction

Enforce access boundaries according to business need, classification and approved authorization rules.

Read the full guide →

Control 8.4

Access to source code

Limit and monitor source-code access to protect integrity, confidentiality and controlled change.

Read the full guide →

Control 8.5

Secure authentication

Use authentication mechanisms and operating practices proportionate to account, system and transaction risk.

Read the full guide →

Control 8.6

Capacity management

Monitor and plan capacity so services remain reliable and security controls continue to operate under expected demand.

Read the full guide →

Control 8.7

Protection against malware

Combine preventive, detective and recovery measures to reduce malware execution and impact.

Read the full guide →

Control 8.8

Management of technical vulnerabilities

Identify relevant technical vulnerabilities, determine exposure and drive risk-based remediation and exception decisions.

Read the full guide →

Control 8.9

Configuration management

Define, deploy and monitor secure configuration baselines across relevant technology.

Read the full guide →

Control 8.10

Information deletion

Delete information when authorized and no longer needed, including relevant copies and service-provider locations.

Read the full guide →

Control 8.11

Data masking

Reduce exposure of sensitive data by obscuring values where full detail is unnecessary.

Read the full guide →

Control 8.12

Data leakage prevention

Detect and reduce unauthorized movement or disclosure of sensitive information across people, endpoints and services.

Read the full guide →

Control 8.13

Information backup

Create protected, recoverable copies aligned with business recovery and information-retention needs.

Read the full guide →

Control 8.14

Redundancy of information processing facilities

Use proportionate redundancy to meet service availability and recovery needs.

Read the full guide →

Control 8.15

Logging

Generate, protect and retain useful event records that support detection, investigation and accountability.

Read the full guide →

Control 8.16

Monitoring activities

Review systems, networks and user activity for anomalies and indicators requiring investigation or response.

Read the full guide →

Control 8.17

Clock synchronization

Maintain consistent time sources so records, alerts and investigations can be correlated reliably.

Read the full guide →

Control 8.18

Use of privileged utility programs

Restrict and monitor powerful utilities that can bypass normal system or application controls.

Read the full guide →

Control 8.19

Installation of software on operational systems

Authorize and control software installation to protect stability, licensing and security baselines.

Read the full guide →

Control 8.20

Networks security

Design, configure and operate networks to protect information flows and connected services.

Read the full guide →

Control 8.21

Security of network services

Define and monitor security expectations for network services, whether internal, outsourced or cloud-delivered.

Read the full guide →

Control 8.22

Segregation of networks

Separate networks, users and services where segmentation reduces exposure or limits movement.

Read the full guide →

Control 8.23

Web filtering

Reduce exposure to malicious or prohibited web content through risk-based filtering and exception handling.

Read the full guide →

Control 8.24

Use of cryptography

Govern cryptographic use, algorithms, certificates and keys according to information and service risk.

Read the full guide →

Control 8.25

Secure development life cycle

Embed security activities, ownership and assurance throughout development and acquisition.

Read the full guide →

Control 8.26

Application security requirements

Define testable security and privacy requirements before applications are designed, acquired or changed.

Read the full guide →

Control 8.27

Secure system architecture and engineering principles

Apply documented security principles and risk decisions to system architecture and engineering.

Read the full guide →

Control 8.28

Secure coding

Use coding standards, developer practices and review techniques that prevent common weaknesses.

Read the full guide →

Control 8.29

Security testing in development and acceptance

Test security requirements and risk scenarios before release and after material change.

Read the full guide →

Control 8.30

Outsourced development

Apply security requirements, oversight and acceptance criteria when development is performed externally.

Read the full guide →

Control 8.31

Separation of development, test and production environments

Separate environments and control movement between them to reduce unauthorized change and data exposure.

Read the full guide →

Control 8.32

Change management

Assess, authorize, test, implement and review technology changes through controlled workflows.

Read the full guide →

Control 8.33

Test information

Select, protect and remove test information so testing does not create unnecessary exposure.

Read the full guide →

Control 8.34

Protection of information systems during audit testing

Plan and control audit testing so assurance activity does not disrupt systems or expose sensitive information.

Read the full guide →

Browse the complete Annex A reference set

The free interactive lookup covers all 93 controls and connects related clauses, evidence and implementation prompts.

Open the Annex A Control Lookup →