What are the ISO 27001 Annex A control categories?
ISO 27001 Annex A controls give organisations a structured reference set for reducing information security risk. The current ISO/IEC 27001:2022 standard contains 93 Annex A controls arranged under four headings: organisational, people, physical and technological. These headings help businesses view security as a company-wide responsibility rather than an issue that belongs only to the IT team.
Each heading brings related controls together. Organisational controls cover governance, policies, suppliers, incidents, assets and legal duties. People controls address staff responsibilities, awareness, confidentiality and remote working. Physical controls protect premises, equipment and working environments. Technological controls focus on devices, systems, networks, applications, access, monitoring and secure development.
Annex A does not tell every organisation to apply every control in exactly the same way. ISO 27001 uses a risk-based approach. The organisation identifies its information security risks, decides how to treat them and compares its chosen measures with Annex A to check that it has not missed a necessary control. The business then records relevant decisions in its Statement of Applicability.
UK Cyber Compliance supports this work through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform helps organisations manage risks, controls, policies, evidence, actions, owners and audit readiness in one place.
Why Annex A uses four clear headings
The four Annex A headings give organisations a balanced view of information security. A company can invest heavily in technology and still face serious risk if staff do not understand their responsibilities, suppliers receive excessive access, offices lack appropriate protection or leaders fail to review security performance.
The structure encourages businesses to consider the whole operating environment. Information passes through people, systems, suppliers, devices, offices, cloud services and business processes. A weakness in any one of those areas can affect confidentiality, integrity or availability.
Confidentiality means that only authorised people and systems can access information. Integrity means information remains accurate, complete and reliable. Availability means authorised users can access information and services when they need them. ISO states that an ISMS protects these three properties through a risk management process.
The Annex A headings also make control ownership clearer. Human resources may own some people controls. Facilities teams may support physical controls. IT and development teams may manage many technological controls. Senior leaders, compliance staff and operational managers often share responsibility for organisational controls.
What is ISO 27001 Certification?
ISO 27001 certification provides independent confirmation that an organisation operates an Information Security Management System that meets ISO/IEC 27001 requirements.
An Information Security Management System, usually shortened to ISMS, gives the organisation a repeatable way to manage information security. It covers scope, leadership, risk assessment, risk treatment, objectives, resources, competence, awareness, operational control, performance evaluation and continual improvement.
Certification does not mean that an organisation will never experience a cyber incident. It shows that the business has created a structured system for identifying risks, choosing controls, assigning ownership, reviewing performance and correcting weaknesses.
ISO develops the standard, but independent certification bodies carry out certification assessments. ISO explains that certification can add credibility by showing that a product, service or management system meets customer expectations.
Annex A supports certification by giving the organisation a recognised control reference. The auditor will expect the business to explain how it selected controls, why each relevant control matters and what evidence shows that the control works.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001, the international standard for information security management systems. It defines requirements for establishing, implementing, maintaining and continually improving an ISMS.
The standard does not focus only on technical protection. ISO describes it as a holistic approach that brings together people, policies and technology. That approach helps an organisation build information security into business processes and management controls.
Risk assessment sits at the centre of the system. The organisation identifies relevant threats and weaknesses, evaluates potential impact and likelihood, assigns risk owners and selects treatment actions. Annex A then acts as a cross-check against the controls the organisation has determined through risk treatment.
This approach makes ISO 27001 suitable for organisations with very different services and operating models. A software provider may focus heavily on secure development and cloud controls. A consultancy may place greater emphasis on staff awareness, client confidentiality and remote working. A manufacturer may need strong physical, supplier and operational resilience controls.
The organisational heading: governance that keeps security moving
The organisational heading contains 37 controls. It is the largest of the four headings because information security needs strong governance, clear responsibilities and dependable business processes.
These controls address areas such as information security policies, roles and responsibilities, segregation of duties, contact with authorities, threat intelligence, security in project management, asset management, acceptable use, information classification, information transfer, supplier relationships, cloud service use, incident management, business continuity, legal obligations, privacy and documented operating procedures.
Policies that guide real decisions
A policy should tell staff and managers what the organisation expects. It should set direction without becoming so complicated that nobody follows it.
For example, an information security policy may describe leadership commitment, security objectives, responsibilities and the organisation’s approach to risk. Supporting policies may cover access, acceptable use, suppliers, incidents, remote working, backup, information classification and other relevant areas.
The organisation should connect each policy to actual processes. A supplier policy should influence supplier approval. An access policy should influence account creation and review. An incident policy should guide reporting, response and learning.
Clear ownership and segregation of duties
Security tasks need named owners. Risks, controls, policies, systems, suppliers and improvement actions can lose momentum when nobody knows who should act.
Segregation of duties reduces the chance that one person can complete a sensitive process without suitable oversight. A finance payment process, for example, may separate request, approval and release responsibilities. An IT process may separate system administration from independent review.
Small businesses can apply this principle proportionately. They may use management approval, external review or recorded checks where staffing limits make full separation difficult.
Asset management and information classification
The organisation needs to know which information, systems and services it relies on. Asset records help teams identify owners, locations, dependencies and protection needs.
Information classification helps staff handle information according to sensitivity and business value. Public marketing material requires different protection from customer records, employee files, credentials, legal documents or security configurations.
Classification should support practical actions. The business may restrict access, apply encryption, control sharing, define retention or require secure disposal based on the information involved.
Supplier and cloud service security
Most businesses depend on external providers. Cloud platforms, managed IT services, software vendors, payroll systems, hosting companies and professional advisers may access or process important information.
Organisational controls help the business assess supplier risk, define contractual expectations, monitor service performance and manage changes or termination.
The organisation remains responsible for understanding the risk even when a supplier performs the activity. A cloud provider may secure its infrastructure, while the customer still controls user accounts, permissions, configurations and data handling.
Incident management and resilience
An effective ISMS gives staff a clear route for reporting security events. The organisation then assesses, responds, communicates and learns from incidents.
Current UK Government research found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. Only 25 per cent had a formal incident response plan, while 38 per cent experienced phishing. These figures show why governance and preparation matter.
Incident records can reveal repeated weaknesses and support corrective action. Business continuity and ICT readiness controls also help the organisation protect information and restore essential services during disruption.
The people heading: turning staff into a security strength
The people heading contains eight controls. These controls recognise that employees, contractors and other users play a direct role in protecting information.
The controls cover screening, employment terms, information security awareness, disciplinary processes, responsibilities after employment changes, confidentiality agreements, remote working and reporting information security events.
Security starts before the first working day
Appropriate screening helps an organisation understand whether a candidate or contractor is suitable for a role that involves sensitive information or privileged access.
The level of screening should match the role, legal requirements and risk. A person who manages core infrastructure may need a different review from someone with limited access to public information.
Employment terms should explain information security duties. Staff need to understand confidentiality, acceptable behaviour, use of company systems, reporting expectations and responsibilities when employment ends.
Awareness that changes behaviour
Awareness should help people recognise and respond to real threats. Training can cover phishing, password security, multi-factor authentication, information handling, remote working, social engineering and incident reporting.
One annual course rarely creates a strong security culture by itself. Regular reminders, realistic examples, manager support and simple reporting routes usually make awareness more useful.
The Government survey found that people or training changes were the most common preventive action taken by businesses after a breach or attack. This supports the value of ongoing awareness as part of a wider control system.
Joiners, role changes and leavers
Access should follow a person’s role. New starters need approved access, people who change roles need permission reviews and leavers need prompt account removal.
The business should also recover devices, keys, passes and information when someone leaves. Confidentiality responsibilities may continue after employment ends.
A reliable process reduces forgotten accounts and excessive access. It also creates clear evidence for an auditor.
Remote working and event reporting
Remote working can expose information through home networks, shared spaces, personal devices, travel and physical document handling.
The organisation should define approved working methods, device expectations, access controls and reporting routes. Staff need to know what to do if they lose a device, send information to the wrong person or receive a suspicious message.
A blame-free reporting culture helps the organisation respond earlier. Staff should feel able to report mistakes and concerns without hiding them.
The physical heading: protecting places, devices and equipment
The physical heading contains 14 controls. These controls address security boundaries, entry, offices, monitoring, environmental threats, secure areas, clear desk practices, equipment placement, assets used away from premises, storage media, utilities, cabling, maintenance and secure disposal or reuse.
Secure boundaries and controlled entry
A physical security boundary separates protected areas from public or less trusted spaces. Offices may use doors, reception controls, badges, locks, alarms or visitor processes.
The organisation should match controls to risk. A small office may need a straightforward entry process, while a data centre or sensitive facility requires stronger measures.
Visitors should receive appropriate supervision. Staff should challenge unknown people carefully and report lost access passes promptly.
Equipment protection inside and outside the office
Device placement can reduce theft, damage and unauthorised viewing. Screens should not expose sensitive information to passers-by. Network equipment may need locked cabinets or restricted rooms.
Laptops and mobile devices used away from the office need physical protection as well as technical controls. Staff should avoid leaving them unattended in vehicles or public places.
The clear desk and clear screen control supports confidentiality by reducing exposed documents, removable media and unlocked sessions.
Environmental threats and supporting utilities
Fire, water, heat, power loss and other environmental events can damage equipment and interrupt services.
The organisation should consider which services need power protection, monitoring, resilient connectivity or alternative arrangements. The chosen measures should follow business impact and risk.
Physical resilience also connects with availability. A technically secure system offers little value if the organisation cannot access it during an avoidable physical disruption.
Media, maintenance and secure disposal
Storage media may contain sensitive information long after staff stop using it. The business should control media through its full life cycle, including use, movement, storage, reuse and disposal.
Maintenance providers may gain physical or technical access to equipment. The organisation should authorise and supervise work where appropriate.
Secure disposal prevents data recovery from retired devices. The business should keep records when risk or contractual duties require them.
The technological heading: controls across systems and networks
The technological heading contains 34 controls. These controls address endpoint devices, privileged access, information access, source code, authentication, capacity, malware, vulnerabilities, configuration, deletion, data masking, data leakage prevention, backup, redundancy, logging, monitoring, networks, web filtering, cryptography, secure development, testing and change management.
Endpoint devices and access control
Laptops, desktops, phones, tablets and servers often provide direct access to business information. The organisation should protect devices through secure configurations, supported software, access control and monitoring.
Privileged access needs particular care. Administrator accounts can make major changes, so the business should limit them, protect them strongly and review their use.
Secure authentication may involve strong unique passwords, multi-factor authentication, passkeys or other appropriate methods.
Malware, vulnerabilities and configuration
Malware protection helps prevent malicious code from running or causing damage. The organisation should choose measures that match its systems and risk.
Vulnerability management involves identifying relevant weaknesses, evaluating exposure and applying suitable treatment. This requires ownership and reliable information from vendors, scanners, suppliers and internal teams.
Configuration management helps keep systems in an approved state. Standard settings, recorded changes and regular reviews can reduce security drift.
Backup, redundancy and service availability
Backup protects information when deletion, corruption, ransomware or system failure occurs. The organisation should define what gets backed up, how often backups run, how long it retains them and how it protects them.
Testing matters. A successful backup job does not prove that the business can restore the information when needed.
Redundancy can support availability when business impact justifies it. The organisation may use alternative systems, connections, locations or providers for critical services.
Logging and monitoring
Logs record significant activity. Monitoring helps the organisation identify unusual behaviour, failed access, configuration changes, malware alerts and other potential problems.
The organisation should decide what to log, how long to retain records, who reviews alerts and how teams escalate concerns.
Time synchronisation supports accurate investigation because systems need consistent timestamps.
Network and cryptographic protection
Network controls help protect communication between devices, services and external parties. Segmentation can limit movement if an attacker compromises part of the environment.
Cryptography can protect information at rest and in transit. The organisation should manage keys, approved methods and responsibilities rather than applying encryption without governance.
Web filtering and network monitoring may also reduce exposure to malicious destinations and unwanted activity.
Secure development and change
Organisations that create software need controls across requirements, architecture, coding, testing, deployment and maintenance.
Security requirements should enter the process early. Developers need suitable guidance, source code access should remain controlled and testing should avoid exposing sensitive production information.
Change management helps teams evaluate risk before altering systems. Emergency changes also need recording and later review.
Who needs iso 27001 certification
ISO 27001 certification can benefit any organisation that handles valuable or sensitive information and needs to demonstrate reliable security management.
Technology companies, managed service providers, software firms, consultancies, accountants, legal practices, healthcare suppliers, recruitment businesses, charities, manufacturers and public sector suppliers may all find it useful.
Customer expectations often create the strongest reason. A client may require evidence that its supplier manages risk across staff, systems, premises, suppliers and business processes.
ISO notes that organisations of any scale and from any sector can use the standard. The risk management process can adapt as the organisation grows or changes.
Small businesses do not need unnecessary bureaucracy. They need clear scope, relevant controls, named owners, dependable evidence and ongoing review.
ISO 27001 Certification Levels
ISO 27001 does not award bronze, silver, gold or other achievement bands. An organisation either holds certification for its stated ISMS scope or it does not.
Businesses do move through preparation stages. A company may start with a gap review, define scope, assess risks, choose controls, create the Statement of Applicability, gather evidence, complete internal audit and hold management review.
Maturity can continue to improve after certification. Better monitoring, clearer metrics, stronger automation and broader scope can all develop over time.
The certificate itself does not describe a maturity rank. Customers should review the certification scope, issuing body and current status.
How the Certification Works
The organisation first defines its ISMS scope and business context. It identifies interested parties, customer needs, legal obligations, services, systems, suppliers and information assets.
Risk assessment then identifies threats, weaknesses, likelihood and potential impact. The business chooses treatment actions and determines the controls it needs.
The organisation compares those controls with Annex A to confirm that it has not missed a necessary measure. It records the control position in the Statement of Applicability.
Next, the business operates the ISMS and gathers evidence. Internal audit checks whether arrangements meet requirements and work effectively. Management review gives leaders a formal opportunity to assess results, risks, resources and improvements.
An external certification body normally completes a readiness assessment followed by a deeper implementation assessment. The certification body can issue a certificate when the organisation meets the requirements.
Ongoing reviews help confirm that the ISMS remains active and suitable as the organisation changes.
The Statement of Applicability connects all four headings
The Statement of Applicability records the controls the organisation has determined are necessary, why it has included them, whether it has implemented them and why it has excluded any Annex A controls.
The document should align with risk assessment and risk treatment. It can also record owners, evidence, status, policy links and review notes.
A strong Statement of Applicability gives leaders and auditors a clear view across all four headings. It shows how organisational, people, physical and technological measures work together.
The organisation should update the document when risks, suppliers, systems, services or legal obligations change.
Evidence turns a control into something credible
A control description alone does not prove implementation. Evidence shows that the organisation follows its process.
Organisational evidence may include policy approvals, supplier reviews, risk records, incident logs and management minutes.
People evidence may include screening records, training attendance, confidentiality agreements, access changes and reported events.
Physical evidence may include visitor logs, access records, maintenance reports, disposal certificates and office checks.
Technological evidence may include configurations, system reports, logs, scan results, backup tests, access reviews and change records.
The organisation should keep evidence proportionate and useful. Producing documents with no operational purpose adds work without improving security.
Common mistakes when organising Annex A controls
One common mistake involves treating the four headings as separate projects. Controls often depend on one another.
For example, access security may require an organisational policy, staff awareness, physical device protection and technological authentication.
Another mistake involves assigning all controls to IT. Many controls need input from leadership, human resources, operations, procurement, facilities, legal advisers and service owners.
Some businesses mark controls as implemented without checking evidence. Others copy generic wording that does not reflect their scope or risks.
The organisation should review each control in business language. Ask what risk it addresses, who owns it, how it works and what proves it.
How UK Cyber Compliance supports the four headings
Managing 93 controls through disconnected spreadsheets and folders can create confusion. Owners may miss tasks, evidence may become outdated and leaders may struggle to see progress.
UK Cyber Compliance brings risks, controls, policies, evidence, actions and audit readiness into one platform. Its risk management functions can support identification, scoring, treatment planning, control ownership and management visibility.
Automation can reduce repeated administration and highlight gaps. AI-driven guidance can help users navigate requirements and organise compliance activity.
Human judgement remains essential. The organisation still decides scope, evaluates risk, approves treatment and confirms that controls work.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain support from cyber security consultancies, compliance specialists, managed service providers, internal audit advisers and platform-led providers.
UK Cyber Compliance supports ISO 27001 through an automated and AI-driven platform. As part of UK Cyber Security Group, it combines practical cyber security knowledge with structured compliance workflows.
A capable provider should help the organisation define scope, assess risk, select controls, prepare the Statement of Applicability, organise evidence, complete internal audit preparation and maintain the ISMS.
Good support should leave the business able to understand and operate its own management system. The adviser should explain requirements clearly rather than creating documents that only a consultant can manage.
A practical review across all four headings
Before an external audit, ask the following questions:
Have we considered all 93 Annex A controls?
Do our selected controls follow the risk treatment process?
Does the Statement of Applicability explain inclusion and exclusion decisions?
Have we assigned owners across organisational, people, physical and technological controls?
Does each implemented control have suitable evidence?
Do staff understand the controls that affect their work?
Have supplier responsibilities been defined?
Do physical controls match our offices, remote workers and equipment?
Do technical controls match our current systems and services?
Have internal audit and management review identified gaps?
Have we updated records after business changes?
Can control owners explain how their controls work?
Clear answers show that the organisation uses Annex A as a practical security framework rather than a paperwork exercise.
Four headings, one joined security system
The ISO 27001 Annex A headings help organisations see information security from four connected perspectives.
Organisational controls create governance and repeatable processes. People controls define responsibilities and build awareness. Physical controls protect environments and equipment. Technological controls secure systems, applications and networks.
No single heading can protect the business on its own. Effective security comes from connecting leadership, staff, premises, suppliers, processes and technology through a risk-based ISMS.
UK Cyber Compliance helps organisations manage that connection through an automated and AI-driven platform. By bringing risks, controls, owners, evidence and actions together, the platform supports a clearer route to certification and continual improvement.
For UK businesses, understanding the four Annex A headings provides a strong foundation. It helps teams assign responsibility, focus on relevant risk, prepare credible evidence and build an ISMS that protects real business activity.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

