
- October 1 2026
-
Amar Khadake
ISO 27001:2022: Understanding the 11 New Annex A Controls
Information security threats are evolving rapidly. Cloud adoption, remote work, cyberattacks, data privacy requirements, supply-chain risks, and increasing dependence on digital infrastructure have changed the way organizations need to manage information security.
To address these changing risks, ISO/IEC 27001:2022 introduced significant updates to the Information Security Management System (ISMS), including 11 new controls in Annex A. It updated Annex A for a cloud-first, data-intensive environment in which security teams must manage external threat information, recover technology during disruption, control sensitive data across its lifecycle, and build security into software development.
What Changed in ISO 27001:2022?
ISO/IEC 27001 defines requirements for an information security management system, or ISMS. ISO describes the standard as a risk-management framework intended to preserve the confidentiality, integrity, and availability of information.
ISO/IEC 27001:2022 reorganized the Annex A controls into four themes:
- Organizational controls – 37 controls
- People controls – 8 controls
- Physical controls – 14 controls
- Technological controls – 34 controls
This results in a total of 93 controls instead of 114, largely because related controls were consolidated rather than simply removed.
The 2022 edition also introduced 11 completely new controls designed to address modern operational and technology risks.
The 11 New ISO 27001:2022 Controls
These controls are not automatically mandatory. ISO/IEC 27001 uses a risk-based approach. An organization determines the controls needed to treat its information security risks, compares those controls with Annex A to check that no necessary control has been omitted, and records applicability and justification in its Statement of Applicability.
The newly introduced controls are:
Control | Control Name | Primary Focus |
A.5.7 | Threat Intelligence | Identifying and analyzing security threats |
A.5.23 | Cloud Security Controls | Managing cloud security risks |
A.5.30 | ICT Readiness for Business Continuity | Maintaining technology readiness during disruptions |
A.7.4 | Physical Security Monitoring | Monitoring physical locations |
A.8.9 | Configuration Management | Maintaining secure system configurations |
A.8.10 | Information Deletion | Securely deleting information |
A.8.11 | Data Masking | Protecting sensitive information |
A.8.12 | Data Leakage Prevention | Preventing unauthorized data disclosure |
A.8.16 | Monitoring Activities | Detecting and responding to suspicious activities |
A.8.23 | Web Filtering | Controlling access to malicious or inappropriate websites |
A.8.28 | Secure Coding | Integrating security into software development |
Let’s examine each control in more detail.
1. A.5.7 – Threat Intelligence
Organizations need to understand the cybersecurity threats that could affect their information, systems, applications, and business operations.
A.5.7 – Threat Intelligence focuses on collecting and analyzing information about existing and emerging threats.This proactive control helps an organisation anticipate attacks and adjust defenses accordingly.
Threat intelligence can include malware and ransomware threats, phishing attacks, industry-specific threats, and relevant security advisories.
Organizations should develop a threat intelligence process to collect and analyze threat data and Integrate this intel into your risk assessment process and incident response plan.
2. A.5.23 – Information Security for Use of Cloud Services
Cloud services have become an integral part of modern IT environments. Organizations often use services such as Cloud infrastructure, SaaS applications, Cloud storage, Cloud database, and cloud collaboration platforms.
A.5.23 requires organizations to address information security throughout the lifecycle of cloud services. With cloud services virtually universal, this control was added to address cloud-specific risks. It requires organisations to specify security requirements for cloud usage, implement appropriate controls, and monitor compliance in cloud environments.
Organizations should develop a cloud security policy or guidelines. Key aspects should include : evaluating cloud providers for security requirements, configuring cloud services securely, monitoring cloud resources for unusual activity, and planning for data backup and exit strategies.
3. A.5.30 – ICT Readiness for Business Continuity
Business continuity objectives only work when technology can support them. This control links business impact analysis to ICT recovery capability, including people, applications, infrastructure, communications, suppliers, and security controls needed during disruption.
A.5.30 focuses on ensuring that ICT capabilities support business continuity requirements.
Organizations should develop an ICT continuity plan and:
- Translate business impact requirements into recovery objectives and technical designs.
- Document dependencies, alternate communications, recovery roles, and supplier commitments.
- Test restoration, failover, access, monitoring, and communications through exercises appropriate to the risk.
- Record results, unresolved gaps, owners, and target dates for improvement.
4. A.7.4 – Physical Security Monitoring
Physical monitoring should reflect the sensitivity of the site and the information or equipment inside it. Traditional physical security controls such as locks and access cards may not be sufficient on their own.
A.7.4 focuses on monitoring physical premises to detect unauthorized physical access or suspicious activity.
Organizations may use measures like CCTV cameras, access-control systems, security alarms, visitor monitoring and physical intrusion detection.
Monitoring should be appropriate to the organization’s security requirements and should also cover safety systems like smoke detectors for fire, because environmental incidents can threaten information and operations too. Privacy, employment, and surveillance laws should be considered that can affect how monitoring is designed and retained.
5. A.8.9 – Configuration Management
Poor system configurations can create significant security vulnerabilities. Misconfiguration is among the top paths attackers use to gain unauthorized access.
A.8.9 control requires organizations to establish and maintain secure configurations for all the systems.The purpose of this control is to apply baseline security measures and to prevent insecure setups in security settings.
Configuration management can include operating systems, servers, databases, network devices,cloud infrastructures and applications.
Organizations should:
- Create risk-based baselines for all the systems.
- Control changes through approved workflows and restrict who can modify production settings.
- Detect drift using automated assessment where practical, then investigate and remediate exceptions.
- Review baselines after significant changes, incidents, new threats, and vendor guidance updates.
6. A.8.10 – Information Deletion
Organizations often retain information longer than necessary. Unnecessary data increases the potential impact of a security incident and may create privacy and regulatory risks.
A.8.10 focuses on securely deleting information when it is no longer required.
Organizations should consider deletion requirements for production systems, databases, cloud storage, employee devices, backups, and applications, while accounting for legal holds, technical limitations, and evidence needs.
Deletion procedures should ensure that information cannot be improperly recovered where secure deletion is required and log all deletion actions for audit purposes.
7. A.8.11 – Data Masking
Sensitive information should not always be exposed in its original form.
A.8.11 introduces data masking as a security control for protecting sensitive information. Data masking reduces exposure by replacing, obscuring, tokenizing, or otherwise transforming sensitive values. It is especially relevant when developers, testers, analysts, or support teams do not need to see the original data.
The organization should determine what information needs masking based on its risk assessment and information classification.
8. A.8.12 – Data Leakage Prevention
Data leakage can occur through emails, cloud storage, USB devices, messaging applications, unauthorised file sharing and personal devices.
A.8.12 focuses on preventing unauthorized disclosure or transfer of sensitive information.
Organizations should:
- Prioritize sensitive data and high-risk transfer paths instead of trying to monitor everything at once.
- Define detect, warn, block, quarantine, and exception actions according to business context.
- Establish alert triage, investigation, privacy safeguards, and escalation responsibilities.
- Measure false positives, repeat causes, coverage gaps, and time to contain confirmed events.
9. A.8.16 – Monitoring Activities
Security monitoring helps organizations detect abnormal or potentially malicious activity.
A.8.16 focuses on monitoring systems, networks, applications, and other relevant activities. Simply collecting logs isn’t enough- active monitoring is crucial for early threat detection. This control greatly enhances an organisation’s ability to respond to incidents before they escalate.
Monitoring can help identify unauthorized access, failed login attempts, privilege escalation, malware activity, and unusual network traffic.
Organizations may deploy intrusion detection systems on network perimeters to detect suspicious activity. Organisations may also use SIEM platforms, network and application monitoring, security logs, and automated alerts.
Monitoring requirements should be based on organizational risks and security objectives.
10. A.8.23 – Web Filtering
Employees can unintentionally access malicious or inappropriate websites that expose the organization to security risks.
A.8.23 focuses on controlling access to external websites to reduce exposure to malware, phishing, malicious downloads, fraudulent websites, and other inappropriate content. A defensible implementation balances security, business need, privacy, and acceptable-use requirements.
Organizations may implement DNS filtering, secure web gateways, browser controls, URL filtering, and endpoint security solutions.
11. A.8.28 – Secure Coding
Software vulnerabilities can introduce significant security risks.
A.8.28 focuses on incorporating secure coding principles into software development. Secure coding moves security closer to the point where vulnerabilities are created. It should cover the languages, frameworks, APIs, infrastructure code, and development models an organization actually uses.
Organizations should consider practices such as:
- Input validation
- Authentication and authorization
- Secure error handling
- Protection against injection attacks
- Secrets management
- Secure dependency management
- Code review
- Security testing
A Note on the 2024 Climate Action Amendment
ISO/IEC 27001:2022 has one published amendment. The amendment addresses climate-action changes in the management-system context. It does not add another set of Annex A security controls.
Organizations should determine whether climate change is a relevant external issue for the ISMS and consider whether interested parties have related requirements. Relevance depends on context. Examples might include climate-related disruption to facilities, power, telecommunications, cooling, cloud regions, logistics, or critical suppliers. The assessment and resulting actions should be proportionate and documented where relevant.
Why Were These Controls Introduced?
The new controls reflect the changing technology and threat landscape.
Several areas received particular attention:
Cloud Computing – Organizations increasingly depend on cloud services, requiring stronger processes for cloud security and lifecycle management.
Threat Intelligence – Cybersecurity teams need timely information about emerging threats and vulnerabilities.
Data Protection – Data masking, information deletion, and data leakage prevention address the growing importance of protecting sensitive information.
Monitoring – Modern attacks can be difficult to detect without continuous monitoring of systems and activities.
Secure Development – As organizations increasingly develop and deploy software, security needs to be integrated into the development lifecycle.
Business Continuity – Technology has become critical to business operations, making ICT readiness an essential part of resilience.
What Should Organizations Do?
Organizations transitioning to ISO/IEC 27001:2022 should not simply add the 11 controls to their documentation.
Instead, they should determine whether each control is applicable based on their risk assessment, organizational context, and Statement of Applicability (SoA).
How a GRC Platform Can Help
Managing the new ISO 27001:2022 controls through spreadsheets, emails, shared folders, and manually maintained documents can become difficult as the organization grows.
A GRC platform such as ComplyPhi can centralize activities associated with the ISMS.
Organizations can use a GRC platform to:
- Map controls to policies and compliance requirements
- Maintain a centralized risk register
- Assign control ownership
- Schedule compliance activities
- Collect and organize evidence
- Manage vendor assessments
- Track policy approvals
- Monitor control status
- Identify evidence gaps
- Maintain audit trails
- Track remediation activities
- Monitor compliance progress
Conclusion
The 11 new controls in ISO/IEC 27001:2022 reflect important developments in modern information security. However, implementing ISO 27001 should not be approached as simply checking off 11 additional controls.
The objective is to understand the organization’s risks, determine which controls are applicable, implement appropriate safeguards, and maintain evidence that demonstrates their effectiveness.
Organizations that integrate these controls into their day-to-day security and governance processes can build an ISMS that is more aligned with their technology environment and evolving security risks.
ISO 27001 compliance is not just about being audit-ready. It is about building a repeatable approach to managing information security every day.