ISO 27001 is a globally recognized standard for information security management systems (ISMS). It provides businesses of all sizes and public organizations with a structured framework for systematically managing and continuously improving information security—and for demonstrating this through independent certification.
Annex A of ISO 27001 provides a comprehensive list of 93 security-specific controls and their protection objectives. These help organizations address identified information security risks and effectively implement the standard’s requirements. The controls are based on the guidelines of ISO/IEC 27002 and form a central foundation for a risk-based ISMS.
Note: The statements referred to as “controls” in Annex A of ISO 27001 are actually individual objectives (controls). They describe what a standard-compliant outcome of appropriate (individual) controls should look like.