ISO 27001 CONTROLS

Introduction

If ISO 27001 is the rulebook for managing information security, Annex A is the toolbox. It’s the part of the standard that provides a reference set of practical safeguards a business can select and apply, covering everything from locking down access and training people to securing physical spaces and protecting systems to manage the risks the standard asks companies to take seriously.

A lot of people hear “93 controls” and picture an intimidating checklist. It’s really not that. Think about a company storing customer records in the cloud, relying on employee laptops, and working with several third-party providers. A single stolen password or unpatched system could expose sensitive data, and that’s exactly where these controls come in not as a box-ticking exercise, but as a toolbox you use based on what your business actually needs.

Under the ISO/IEC 27001:2022 structure, Annex A contains 93 controls grouped across four themes: organizational, people, physical, and technological. This article walks through what those controls are and how the four themes work together—the foundation for the more detailed articles ahead.

It’s also worth making one distinction clear: Annex A in ISO/IEC 27001 provides the reference set of controls, while ISO/IEC 27002 provides more detailed guidance on how those controls can be implemented.

What are ISO 27001 Controls?

In simple terms, these are safeguards that reduce information security risk. Say a business identifies unauthorized access to customer data as a real concern. It might introduce multi-factor authentication, tighter access restrictions, and employee security training. Together, these measures can lower both the likelihood and potential impact of an incident.

A small design agency faces very different threats from a healthcare provider or a bank. That means implementation should never be treated as a generic template. The organization first needs to understand its risks, then decide which controls are appropriate for managing them.

1. Organizational Controls: The Security Foundation

Organizational controls cover the policies, responsibilities, processes, and governance behind information security. This includes areas such as incident handling, asset management, supplier security, access-related processes, and business continuity.

Imagine an employee discovers that a company account has been compromised. Without a clear response process, nobody knows who to contact, what evidence to preserve, or what action to take first. Valuable time gets lost while the attacker may continue working.

A solid organizational control fixes exactly that. Employees know how to report an incident, the right people know how to investigate it, and the organization has a defined process for responding. That turns security into a repeatable system rather than something left to individual judgment in the moment.

2. People Controls: Security Is Human Behavior

No firewall stops an employee from sharing a password with the wrong person, and no encryption helps if someone sends sensitive data straight to a phishing attacker. This is where screening, security awareness, training, and clear responsibilities come in, along with something people often overlook: offboarding.

If a former employee’s access is never revoked, that’s a real risk sitting wide open. A proper offboarding process helps ensure that accounts, access rights, devices, and other responsibilities are reviewed when someone’s role changes or their employment ends.

The goal isn’t to turn every employee into a cybersecurity expert. It’s to help people recognize a red flag and know what to do about it. Because, in practice, some of the most important information security controls happen long before a security tool ever raises an alert.

3. Physical Controls: Protecting the Real World

Security isn’t only about hackers and software.

A laptop can be stolen. An unauthorized visitor can walk into a restricted office. Sensitive information can be left visible on a desk. Leaving a laptop unlocked in a public space creates a real risk, even if the company’s network is otherwise well protected.

Physical controls help manage these risks through measures such as controlled access to sensitive areas, protection of physical equipment, secure disposal of devices and information, and clear desk and clear screen practices.

These controls are a reminder that information security extends beyond screens and servers. If the physical environment is ignored, strong technical security alone may not be enough.

4. Technological Controls: Protecting Systems and Data

This is the theme most people picture first: access control, malware protection, vulnerability management, monitoring, backups, and other technical safeguards. Take vulnerability management as an example. New weaknesses turn up constantly in operating systems, applications, and third-party software. If nobody is watching for them, attackers eventually may.

A solid approach means more than simply running a scan. It means identifying vulnerabilities, prioritizing them based on actual risk, applying appropriate fixes, and confirming those fixes worked not filing a scan report away and forgetting about it. The same principle applies to access control. Employees should have access to the systems and information they genuinely need, rather than unrestricted access simply because it is convenient. Technological controls are essential, but they work best when combined with strong processes and informed employees.

Controls Aren’t a Checklist

One of the biggest mistakes in ISO 27001 implementation is treating controls as boxes to tick.

Writing a policy doesn’t mean employees follow it. Installing a security tool doesn’t mean it’s configured correctly. Running a vulnerability scan doesn’t help if nobody reviews what it finds or acts on the results.

Real controls stay connected to actual risk:

  • What information needs protection?
  • What threats and vulnerabilities exist?
  • Which controls are appropriate?
  • Are those controls genuinely working?

That’s what turns an information security management system into something useful—not a stack of documents created for an audit, but a process that actively manages risk day to day.

How Greyhound Helps with ISO 27001 Controls?

Choosing the right controls on paper is one thing. Knowing whether they’re actually working is a different question, and that’s where Greyhound can help.

Greyhound helps businesses assess their real security posture through capabilities such as automated security scanning, black-box penetration testing, and evidence-based security assessments. This can help uncover weaknesses across systems, applications, and digital infrastructure the kind of gaps that policies and documentation alone may not reveal.

For example, an organization may have vulnerability management or access-related controls documented as part of its security program. Testing the environment can help identify whether weaknesses still exist in practice and provide evidence of areas that need attention.

Instead of assuming a control is doing its job because it’s written down somewhere, businesses can gain clearer, evidence-backed insight into what’s working and what still needs improvement. That practical visibility can support organizations as they evaluate their security posture and strengthen the controls relevant to their information security risks.

Conclusion

ISO 27001 controls aren’t just a list of requirements. They’re a practical toolbox for protecting information through people, processes, physical security, and technology working together. The key is that the approach is risk-driven, not a template. Understand your own environment, identify what needs protection, assess the risks involved, and apply the controls that genuinely address them. There’s much more ahead, including individual controls, risk assessment, the Statement of Applicability, and continuous improvement. But understanding these four themes is the right place to start.

Because ultimately, the goal isn’t to implement controls just to pass an audit. It’s to build a security system that continues to work when a real risk appears.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *