information

ISO 27001:2022 controls

ISO 27001:2022 controls

Understanding Annex A controls

Understanding ISO 27001 controls is the first step. Implementing and maintaining them effectively requires structure, clarity and ongoing oversight.

Integration with wider management systems

Information security does not operate in isolation. Annex A controls can be integrated with other standards such as ISO 9001, ISO 14001 and ISO 42001 to form a single, coherent management system.

A structured approach to integration allows organisations to:

  • reduce duplication across processes and documentation
  • align risk, governance and audit activity
  • maintain one system across multiple certifications

This is typically supported through integrated delivery and centralised systems such as management system platforms.


Supporting certification and audit readiness

Certification bodies assess whether controls are:

  • appropriately selected based on risk
  • clearly implemented
  • supported by reliable evidence

They also expect to see ongoing review and improvement.

Controls that are embedded into operations are easier to maintain and more reliable during audits, reducing lastminute preparation and audit disruption.

Making controls work in practice

choose 27002:2022 controls

ISO 27002:2022 is a guideline for information security controls, supporting ISO 27001:2022 Annex A by providing further detail and clarification. There are now four domains (Organisational, People, Physical and Technological) instead of the previous 14. At AvISO, we have put together a page on all 93 controls with an explained purpose and implementation guidance.

As part of ISO 27001:2022, Annex A lays out a set of security controls that organisations can use to demonstrate compliance internationally and best practices. In ISO 27001:2022, a Statement of Applicability (SoA) is a document that lists the Annex A controls an organisation will implement to meet the requirements of the standard.This will include a list of the controls that are necessary for your organisation, a statement outlining why the chosen controls have been included and excluded and the confirmation of implementation.

ask a question

Get in touch to discuss how we can support your management system implementation, integration or improvement
Kent: 01892 800476 | London: 02037 458 476 | info@avisoconsultancy.co.uk

By filling out this form, you agree to the terms laid out in our privacy policy
Thank you!
Your submission has been received, one of our team members will be in touch soon.
Oops! Something went wrong while submitting the form.
ISO consultants kent
ASK our AGENT
By clicking “Continue To Site”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts. View our Privacy Policy for more information.