Annex A Controls Explained
Dr. Abeer Alshammari · Published 7/29/2026
| Theme | Approx. controls | Covers |
|---|---|---|
| A.5 Organizational | 37 | Policies, roles, supplier relationships, incident management, BCP |
| A.6 People | 8 | Screening, terms of employment, awareness training, disciplinary process |
| A.7 Physical | 14 | Secure areas, equipment protection, clear desk/screen, media disposal |
| A.8 Technological | 34 | Access control, cryptography, logging, malware protection, secure development |
Controls are selected, not mandated wholesale
An organization does not implement all 93 controls automatically -- it selects applicable controls based on its risk assessment (Clause 6), documents that selection and rationale in the Statement of Applicability, and justifies exclusions. A control can be legitimately excluded if it does not apply to the organization's context (for example, physical media disposal controls for a fully cloud-native company with no physical media).
Annex A is a reference control catalog, not a checklist to implement item by item without judgment. Auditors expect to see the risk-based reasoning behind each inclusion and exclusion, not just a completed checkbox list.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon