Thirty-four controls covering endpoints, access, cryptography, logging, network security, secure development and vulnerability management.
A.8 carries the most controls and the most new requirements from the 2022 revision — threat intelligence, data masking, data leakage prevention, monitoring activities and secure coding all landed or firmed up here. These controls are tested against system state rather than policy text, so the evidence is configuration exports, tickets, scan output and console screenshots showing enforcement in the live environment. A documented standard with no corresponding configuration evidence is the most common finding in this theme.
There are 34 controls in the A.8 Technological Controls theme, of which 7 are new in the 2022 revision. Annex A defines 93 controls in total across four themes: Organisational (37), People (8), Physical (14) and Technological (34).
No. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify any exclusion in the Statement of Applicability — it does not require you to apply all 93. What auditors test is whether the justification is risk-based and documented, not whether the count is high.
The 2013 edition organised 114 controls into 14 domains (A.5–A.18). The 2022 revision restructured them into 93 controls across four themes, merging 57 and introducing 11 new ones. Each control page below lists its 2013 predecessors so you can re-point existing evidence during transition.