All resources
ISO 27001Annex AChecklist

ISO/IEC 27001:2022 checklist: all 93 Annex A controls

Official source: ISO/IEC 27001:2022

ISO 27001 isn’t a one-time certification — it’s evidence your controls operate continuously. This checklist walks every control an auditor examines, and flags which a platform can automate.

What ISO 27001 requires

ISO 27001 is assessed against 93 controls across 5 families: Organizational, People, Physical, Technological, ISMS evidence. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

The four Annex A themes (93 controls in ISO/IEC 27001:2022) with the key controls in each. Use the table below as your working checklist — 21 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
A.5 — Organizational (37 controls)
A.5.1Policies for information securityManual
A.5.7Threat intelligenceAuto
A.5.19Supplier relationshipsManual
A.5.23Cloud services securityManual
A.5.24Incident management planningManual
A.5.30ICT readiness for business continuityManual
A.6 — People (8 controls)
A.6.1ScreeningManual
A.6.3Awareness, education & trainingManual
A.6.5Responsibilities after terminationManual
A.7 — Physical (14 controls)
A.7.1Physical security perimetersManual
A.7.10Storage mediaManual
A.7.14Secure disposal or re-use of equipmentManual
A.8 — Technological (34 controls)
A.8.1User endpoint devicesAuto
A.8.2Privileged access rightsAuto
A.8.5Secure authentication (MFA)Auto
A.8.8Management of technical vulnerabilitiesAuto
A.8.12Data leakage preventionAuto
A.8.15LoggingAuto
A.8.16Monitoring activitiesAuto
A.8.24Use of cryptographyAuto
A.8.28Secure codingManual

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of ISO 27001 controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Turn this checklist into a live dashboard

SBCMSP tracks every ISO 27001 control continuously across all your clients.