Skip to content
Log inRegister

Annex A Controls Explained

Dr. Abeer Alshammari · Published 7/29/2026

IntermediateProfessionalsCISOs
ThemeApprox. controlsCovers
A.5 Organizational37Policies, roles, supplier relationships, incident management, BCP
A.6 People8Screening, terms of employment, awareness training, disciplinary process
A.7 Physical14Secure areas, equipment protection, clear desk/screen, media disposal
A.8 Technological34Access control, cryptography, logging, malware protection, secure development

Controls are selected, not mandated wholesale

An organization does not implement all 93 controls automatically -- it selects applicable controls based on its risk assessment (Clause 6), documents that selection and rationale in the Statement of Applicability, and justifies exclusions. A control can be legitimately excluded if it does not apply to the organization's context (for example, physical media disposal controls for a fully cloud-native company with no physical media).

Common misconception

Annex A is a reference control catalog, not a checklist to implement item by item without judgment. Auditors expect to see the risk-based reasoning behind each inclusion and exclusion, not just a completed checkbox list.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights