Skip to main content

Proof of competence

Practical ISO/IEC 27001 resources

ISO 27001 Annex A Control Implementation Library

A growing collection of practical implementation guides for all 93 Annex A controls in ISO/IEC 27001:2022. Use the library to move from control titles to concrete actions, evidence and audit-ready practices.

93controls in total
4control themes
2022current structure
Practicalimplementation focus

How to use this library

Choose the theme and control relevant to your risks, scope and Statement of Applicability. Each guide will explain the control's purpose in plain language and provide implementation steps, examples, suggested documentation, possible evidence, useful metrics and common mistakes.

All 93 practical guides are now available. Select a control below to open its implementation guide.

Annex A

Organizational controls

37 controls
ControlTopicGuide
5.1Policies for information securityOpen guide →
5.2Information security roles and responsibilitiesOpen guide →
5.3Segregation of dutiesOpen guide →
5.4Management responsibilitiesOpen guide →
5.5Contact with authoritiesOpen guide →
5.6Contact with special interest groupsOpen guide →
5.7Threat intelligenceOpen guide →
5.8Information security in project managementOpen guide →
5.9Inventory of information and other associated assetsOpen guide →
5.10Acceptable use of information and other associated assetsOpen guide →
5.11Return of assetsOpen guide →
5.12Classification of informationOpen guide →
5.13Labelling of informationOpen guide →
5.14Information transferOpen guide →
5.15Access controlOpen guide →
5.16Identity managementOpen guide →
5.17Authentication informationOpen guide →
5.18Access rightsOpen guide →
5.19Information security in supplier relationshipsOpen guide →
5.20Addressing information security within supplier agreementsOpen guide →
5.21Managing information security in the ICT supply chainOpen guide →
5.22Monitoring, review and change management of supplier servicesOpen guide →
5.23Information security for use of cloud servicesOpen guide →
5.24Information security incident management planning and preparationOpen guide →
5.25Assessment and decision on information security eventsOpen guide →
5.26Response to information security incidentsOpen guide →
5.27Learning from information security incidentsOpen guide →
5.28Collection of evidenceOpen guide →
5.29Information security during disruptionOpen guide →
5.30ICT readiness for business continuityOpen guide →
5.31Legal, statutory, regulatory and contractual requirementsOpen guide →
5.32Intellectual property rightsOpen guide →
5.33Protection of recordsOpen guide →
5.34Privacy and protection of personally identifiable information (PII)Open guide →
5.35Independent review of information securityOpen guide →
5.36Compliance with policies, rules and standards for information securityOpen guide →
5.37Documented operating proceduresOpen guide →

Annex A

People controls

8 controls

Annex A

Physical controls

14 controls

Annex A

Technological controls

34 controls
ControlTopicGuide
8.1User endpoint devicesOpen guide →
8.2Privileged access rightsOpen guide →
8.3Information access restrictionOpen guide →
8.4Access to source codeOpen guide →
8.5Secure authenticationOpen guide →
8.6Capacity managementOpen guide →
8.7Protection against malwareOpen guide →
8.8Management of technical vulnerabilitiesOpen guide →
8.9Configuration managementOpen guide →
8.10Information deletionOpen guide →
8.11Data maskingOpen guide →
8.12Data leakage preventionOpen guide →
8.13Information backupOpen guide →
8.14Redundancy of information processing facilitiesOpen guide →
8.15LoggingOpen guide →
8.16Monitoring activitiesOpen guide →
8.17Clock synchronizationOpen guide →
8.18Use of privileged utility programsOpen guide →
8.19Installation of software on operational systemsOpen guide →
8.20Network securityOpen guide →
8.21Security of network servicesOpen guide →
8.22Segregation of networksOpen guide →
8.23Web filteringOpen guide →
8.24Use of cryptographyOpen guide →
8.25Secure development life cycleOpen guide →
8.26Application security requirementsOpen guide →
8.27Secure system architecture and engineering principlesOpen guide →
8.28Secure codingOpen guide →
8.29Security testing in development and acceptanceOpen guide →
8.30Outsourced developmentOpen guide →
8.31Separation of development, test and production environmentsOpen guide →
8.32Change managementOpen guide →
8.33Test informationOpen guide →
8.34Protection of information systems during audit testingOpen guide →
Important: Annex A is a reference set of information security controls. Your organization should select, justify and tailor controls based on its risk assessment, legal and contractual requirements, and ISMS context. This independent learning resource is not affiliated with or endorsed by ISO.

Practical ISO/IEC 27001 resources

ISO 27001 Annex A Control Implementation Library

A growing collection of practical implementation guides for all 93 Annex A controls in ISO/IEC 27001:2022. Use the library to move from control titles to concrete actions, evidence and audit-ready practices.

93controls in total
4control themes
2022current structure
Practicalimplementation focus

How to use this library

Choose the theme and control relevant to your risks, scope and Statement of Applicability. Each guide will explain the control's purpose in plain language and provide implementation steps, examples, suggested documentation, possible evidence, useful metrics and common mistakes.

The first guides are currently being prepared. Links will be added directly to the control rows as they are published.

Annex A

Organizational controls

37 controls
ControlTopicGuide
5.1Policies for information securityPlanned
5.2Information security roles and responsibilitiesPlanned
5.3Segregation of dutiesPlanned
5.4Management responsibilitiesPlanned
5.5Contact with authoritiesPlanned
5.6Contact with special interest groupsPlanned
5.7Threat intelligencePlanned
5.8Information security in project managementPlanned
5.9Inventory of information and other associated assetsPlanned
5.10Acceptable use of information and other associated assetsPlanned
5.11Return of assetsPlanned
5.12Classification of informationPlanned
5.13Labelling of informationPlanned
5.14Information transferPlanned
5.15Access controlPlanned
5.16Identity managementPlanned
5.17Authentication informationPlanned
5.18Access rightsPlanned
5.19Information security in supplier relationshipsPlanned
5.20Addressing information security within supplier agreementsPlanned
5.21Managing information security in the ICT supply chainPlanned
5.22Monitoring, review and change management of supplier servicesPlanned
5.23Information security for use of cloud servicesPlanned
5.24Information security incident management planning and preparationPlanned
5.25Assessment and decision on information security eventsPlanned
5.26Response to information security incidentsPlanned
5.27Learning from information security incidentsPlanned
5.28Collection of evidencePlanned
5.29Information security during disruptionPlanned
5.30ICT readiness for business continuityPlanned
5.31Legal, statutory, regulatory and contractual requirementsPlanned
5.32Intellectual property rightsPlanned
5.33Protection of recordsPlanned
5.34Privacy and protection of personally identifiable information (PII)Planned
5.35Independent review of information securityPlanned
5.36Compliance with policies, rules and standards for information securityPlanned
5.37Documented operating proceduresPlanned

Annex A

People controls

8 controls
ControlTopicGuide
6.1ScreeningPlanned
6.2Terms and conditions of employmentPlanned
6.3Information security awareness, education and trainingPlanned
6.4Disciplinary processPlanned
6.5Responsibilities after termination or change of employmentPlanned
6.6Confidentiality or non-disclosure agreementsPlanned
6.7Remote workingPlanned
6.8Information security event reportingPlanned

Annex A

Physical controls

14 controls
ControlTopicGuide
7.1Physical security perimetersPlanned
7.2Physical entryPlanned
7.3Securing offices, rooms and facilitiesPlanned
7.4Physical security monitoringPlanned
7.5Protecting against physical and environmental threatsPlanned
7.6Working in secure areasPlanned
7.7Clear desk and clear screenPlanned
7.8Equipment siting and protectionPlanned
7.9Security of assets off-premisesPlanned
7.10Storage mediaPlanned
7.11Supporting utilitiesPlanned
7.12Cabling securityPlanned
7.13Equipment maintenancePlanned
7.14Secure disposal or re-use of equipmentPlanned

Annex A

Technological controls

34 controls
ControlTopicGuide
8.1User endpoint devicesPlanned
8.2Privileged access rightsPlanned
8.3Information access restrictionPlanned
8.4Access to source codePlanned
8.5Secure authenticationPlanned
8.6Capacity managementPlanned
8.7Protection against malwarePlanned
8.8Management of technical vulnerabilitiesPlanned
8.9Configuration managementPlanned
8.10Information deletionPlanned
8.11Data maskingPlanned
8.12Data leakage preventionPlanned
8.13Information backupPlanned
8.14Redundancy of information processing facilitiesPlanned
8.15LoggingPlanned
8.16Monitoring activitiesPlanned
8.17Clock synchronizationPlanned
8.18Use of privileged utility programsPlanned
8.19Installation of software on operational systemsPlanned
8.20Network securityPlanned
8.21Security of network servicesPlanned
8.22Segregation of networksPlanned
8.23Web filteringPlanned
8.24Use of cryptographyPlanned
8.25Secure development life cyclePlanned
8.26Application security requirementsPlanned
8.27Secure system architecture and engineering principlesPlanned
8.28Secure codingPlanned
8.29Security testing in development and acceptancePlanned
8.30Outsourced developmentPlanned
8.31Separation of development, test and production environmentsPlanned
8.32Change managementPlanned
8.33Test informationPlanned
8.34Protection of information systems during audit testingPlanned
Important: Annex A is a reference set of information security controls. Your organization should select, justify and tailor controls based on its risk assessment, legal and contractual requirements, and ISMS context. This independent learning resource is not affiliated with or endorsed by ISO.