A.8 34 controls · 7 new in 2022

ISO 27001 Technological Controls (A.8)

Thirty-four controls covering endpoints, access, cryptography, logging, network security, secure development and vulnerability management.

What the Technological Controls theme covers

A.8 carries the most controls and the most new requirements from the 2022 revision — threat intelligence, data masking, data leakage prevention, monitoring activities and secure coding all landed or firmed up here. These controls are tested against system state rather than policy text, so the evidence is configuration exports, tickets, scan output and console screenshots showing enforcement in the live environment. A documented standard with no corresponding configuration evidence is the most common finding in this theme.

All 34 Technological Controls

A.8.1 User end point devices
Protect information stored on, processed by or accessible through user end point devices.
A.8.2 Privileged access rights
Restrict and manage the allocation and use of privileged access rights.
A.8.3 Information access restriction
Restrict access to information and application system functions in accordance with the access control policy.
A.8.4 Access to source code
Manage and restrict access to source code, development tools and software libraries.
A.8.5 Secure authentication
Implement secure authentication technologies and procedures based on information access restrictions and the access control policy.
A.8.6 Capacity management
Monitor, tune and project future capacity requirements to ensure required system performance.
A.8.7 Protection against malware
Implement protection against malware and combine with appropriate user awareness.
A.8.8 Management of technical vulnerabilities
Obtain information about technical vulnerabilities of systems in use, evaluate exposure, and take measures to address the associated risk.
A.8.9 Configuration management New
Establish, document, implement, monitor and review configurations, including security configurations, for hardware, software, services and networks.
A.8.10 Information deletion New
Delete information stored in information systems, devices or other storage media when no longer required.
A.8.11 Data masking New
Use data masking in accordance with the organisation's access control and business/legal requirements.
A.8.12 Data leakage prevention New
Apply data leakage prevention measures to systems, networks and output devices that process, store or transmit sensitive information.
A.8.13 Information backup
Maintain and regularly test backup copies of information, software and systems in accordance with an agreed backup policy.
A.8.14 Redundancy of information processing facilities
Implement information processing facilities with sufficient redundancy to meet availability requirements.
A.8.15 Logging
Produce, store, protect and analyse event logs that record user activities, exceptions, faults and IS events.
A.8.16 Monitoring activities New
Monitor networks, systems and applications for anomalous behaviour and take appropriate actions to evaluate potential IS incidents.
A.8.17 Clock synchronisation
Synchronise the clocks of all relevant information processing systems to approved time sources.
A.8.18 Use of privileged utility programs
Restrict and tightly control use of utility programs that could be capable of overriding system and application controls.
A.8.19 Installation of software on operational systems
Implement procedures to control the installation of software on operational systems.
A.8.20 Networks security
Manage, control and protect the organisation's networks and network devices against threats.
A.8.21 Security of network services
Identify and implement security mechanisms, service levels and management requirements for all network services.
A.8.22 Segregation of networks
Segregate groups of information services, users and information systems within the organisation's networks.
A.8.23 Web filtering New
Manage access to external websites to reduce exposure to malicious content.
A.8.24 Use of cryptography
Define and implement rules for the effective use of cryptography, including cryptographic key management.
A.8.25 Secure development life cycle
Establish and apply rules for the secure development of software and systems.
A.8.26 Application security requirements
Identify, specify and approve information security requirements when developing or acquiring applications.
A.8.27 Secure system architecture and engineering principles
Establish, document, maintain and apply security engineering principles to any information system implementation.
A.8.28 Secure coding New
Apply secure coding principles to software development.
A.8.29 Security testing in development and acceptance
Define and implement security testing processes in the development lifecycle.
A.8.30 Outsourced development
Direct, monitor and review the activities related to outsourced system development.
A.8.31 Separation of development, test and production environments
Identify, document and implement controls to separate development, test and production environments.
A.8.32 Change management
Subject changes to information processing facilities and information systems to change management procedures.
A.8.33 Test information
Ensure that test information is appropriately selected, protected and managed.
A.8.34 Protection of information systems during audit testing
Plan and agree on audit tests and other assurance activities to minimise disruptions to business processes.

Other Annex A themes

A.5 Organisational Controls A.6 People Controls A.7 Physical Controls
Crosswalk to SOC 2 & NIST CSF →
Map these controls across frameworks in the Control Mapper.
Search all 93 controls →
Filter Annex A by keyword, theme or control ID.

Frequently asked questions

How many Technological Controls are there in ISO 27001:2022?

There are 34 controls in the A.8 Technological Controls theme, of which 7 are new in the 2022 revision. Annex A defines 93 controls in total across four themes: Organisational (37), People (8), Physical (14) and Technological (34).

Do I have to implement every Technological Controls control?

No. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify any exclusion in the Statement of Applicability — it does not require you to apply all 93. What auditors test is whether the justification is risk-based and documented, not whether the count is high.

What replaced the ISO 27001:2013 domains?

The 2013 edition organised 114 controls into 14 domains (A.5–A.18). The 2022 revision restructured them into 93 controls across four themes, merging 57 and introducing 11 new ones. Each control page below lists its 2013 predecessors so you can re-point existing evidence during transition.