Skip to content

Annex A

What is Annex A?

The section of ISO 27001 that contains the reference set of information security controls. The 2022 revision organises 93 controls into four themes: Organisational, People, Physical, and Technological.

Information Security

What the standards actually require on annex a

Requirements naming annex a across 6 standards, quoted from the control text.

Provides guidance on collaboration, communications, and establishment of communication protocols during an incident.

ISO-22320-A · Annex A: Collaboration and communication guidance

Implement Asset Management + Identity and Access Management + Cryptography per MTCS SS 584. Asset Management (ISO 27001 Annex A.8 alignment) - asset inventory (hardware + software + data + virtual + container + serverless) + asset classification + asset owners...

MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe · MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe

The client shall publicly report on a project's Environmental and Social impact assessment process, ESMP and grievance mechanism, and the EPFI shall annually report on its Equator Principles implementation, the number and category of transactions, project sect...

EP4-P10 · Reporting and Transparency

Demonstrate auditor competence across ISMS, risk, controls, sector and audit techniques per Annex A table.

27006-A.1 · Auditor Competence Areas

Keep proper documentation of AI risk impact assessments (per the Annex A template) for audit purposes, and continually review and update them as systems and risks change.

AIGE-HI-4 · Document risk impact assessments
FISMA1 control

FISMA coordination with industry security frameworks. NIST CSF 2.0 (February 2024): voluntary framework + 6 functions (Govern + Identify + Protect + Detect + Respond + Recover);

FISMA-Coord-NIST-CSF-ISO27001-SOC2 · Coordination with NIST CSF 2.0, ISO 27001, SOC 2 and Industry Frameworks

Questions people ask about annex a

What is Annex A?
The section of ISO 27001 that contains the reference set of information security controls. The 2022 revision organises 93 controls into four themes: Organisational, People, Physical, and Technological.
Why is Annex A important for compliance?
Annex A is a key concept in Information Security. Understanding annex a helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Annex A?
Key concepts related to Annex A include ISO 27001. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Annex A?
Annex A appears in the requirement text of ISO 22320:2018, MTCS (Singapore), Equator Principles (EP4, 2020), ISO/IEC 27006:2024, ASEAN Guide on AI Governance and Ethics. Across these standards we have identified 12 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Annex A?
Explore our compliance framework pages to see how annex a applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Annex A applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.