ISO 27001:2022 Checklist, 93 Controls as Self-Assessment
Introduction
ISO/IEC 27001:2022 restructured the information-security controls fundamentally: from 114 controls in 14 domains in the 2013 edition to 93 controls across 4 themes, Organisational (37), People (8), Physical (14) and Technological (34). This checklist supports organisations preparing for an ISO 27001:2022 audit or migrating an existing ISMS to the new structure. It is designed as a self-assessment: per theme we provide the applicability question, typical evidence artefacts and a maturity hint (Initial / Defined / Effective / Optimised).
What this checklist covers:
- the structural novelties of ISO 27001:2022 versus ISO 27001:2013;
- the transition period and the key migration triggers;
- the 37 organisational controls (Annex A.5);
- the 8 people controls (Annex A.6);
- the 14 physical controls (Annex A.7);
- the 34 technological controls (Annex A.8);
- the Statement of Applicability (SoA) and the treatment of the 11 new controls.
A full treatment of every individual control would fill a book. The checklist focuses, per theme, on the ten controls with the highest non-conformity rate from SIDD audits in 2024-2025 and provides their critical evidence requirements.
Structure and transition ISO 27001:2013 → 2022
The transition period for ISO 27001:2013 certificates ended on 31 October 2025, from that date all active certificates must be issued under the 2022 edition. Companies still certified on a 2013 basis in 2026 hold an expired or transitional certificate that is critically questioned in any customer or authority audit.
Structurally, the 2022 edition has six material novelties:
- 93 controls instead of 114, through consolidation of related controls from the 2013 domains.
- 4 themes (Organisational, People, Physical, Technological) instead of 14 domains.
- 11 new controls, including A.5.7 Threat Intelligence, A.5.23 Information Security for use of Cloud Services, A.5.30 ICT Readiness for Business Continuity, A.7.4 Physical Security Monitoring, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.16 Monitoring Activities, A.8.23 Web Filtering, A.8.28 Secure Coding.
- Attribute tags per control (Control Type, Information Security Properties, Cybersecurity Concepts, Operational Capabilities, Security Domains) for filtering and reporting.
- Stronger focus on threat intelligence and proactive defence.
- Explicit cloud treatment, which for Swiss SMEs running Microsoft 365 / Google Workspace / AWS workloads makes engagement with A.5.23 mandatory.
In migration the Statement of Applicability (SoA) is the central artefact: per control a decision on applicability, with a justification and a reference to the implementing measure.
Organisational controls (Annex A.5, 37 controls)
The organisational controls are the largest group and cover policies, roles, threat intelligence, supplier management, incident management and compliance. The ten most frequent gap candidates from SIDD audits in 2024-2025:
- A.5.1 Policies for information security, InfoSec policy with management approval, annual review and communication. Frequent gap: policy exists, but last-review date older than 2 years.
- A.5.7 Threat intelligence (NEW 2022), establishment of a threat-intelligence process, ideally with NCSC/BACS feed reference and sector-specific ISACs (e.g. FS-ISAC for finance).
- A.5.19-22 Supplier relationships, supplier assessment, contractual security clauses, regular reviews. Frequent gap: DPA in place but no technical assessment of the provider.
- A.5.23 Information security for use of cloud services (NEW 2022), cloud-specific policy, shared-responsibility model documented per provider, cloud configuration standard.
- A.5.24-28 Information security incident management, IRP, classification, escalation, lessons learned. Frequent gap: IRP exists, but tabletop exercise older than 24 months.
- A.5.30 ICT readiness for business continuity (NEW 2022), BC plan with IT component, RTO/RPO defined, tested annually.
- A.5.34 Privacy and protection of PII, explicit interlocking with the DSG records of processing under Art. 12 DSG (see Swiss data protection checklist).
- A.5.36 Compliance with policies, rules and standards, internal audits, self-assessments, maturity metrics.
Evidence standard for each of these controls: policy or procedure, owner, last review date, effectiveness indicator (KPI / metric).
People controls (Annex A.6, 8 controls)
The people controls bundle employee and contract topics, compact but audit-intensive:
- A.6.1 Screening, background checks before employment within the limits of labour law. In Switzerland: criminal-record extract for security-sensitive roles, reference checks, diploma verification.
- A.6.2 Terms and conditions of employment, confidentiality, security and compliance clauses in the employment contract; complement to the confidentiality duty under Art. 321a CO.
- A.6.3 Information security awareness, education and training, a structured awareness programme with frequency, content and a knowledge check (phishing simulations, quizzes, mandatory training completion rates). See our service IT security workshop SME.
- A.6.4 Disciplinary process, a documented escalation and disciplinary process for security violations.
- A.6.5 Responsibilities after termination or change of employment, off-/inboarding process with access revocation, device return, surviving confidentiality duties.
- A.6.7 Remote working (NEW 2022), remote-work policy covering endpoint security, network configuration, physical environment.
- A.6.8 Information security event reporting, a low-barrier reporting channel for staff, with protection against retaliation.
Most frequent gap: A.6.3 with annual mandatory training without phishing simulation and without maturity measurement. Effective training is measurable; pure once-a-year click-through training is not.
Physical controls (Annex A.7, 14 controls)
The physical controls cover sites, access controls and devices. They are leaner for pure cloud organisations but central for on-premise setups, data centres or regulatorily sensitive industries (banks, hospitals). The ten most frequent audit points:
- A.7.1 Physical security perimeters, defined security perimeters with access control, door sensors, alarming.
- A.7.2 Physical entry, visitor management, escort obligation, access log.
- A.7.3 Securing offices, rooms and facilities, clear-desk policy, lockable cabinets, key management.
- A.7.4 Physical security monitoring (NEW 2022), video surveillance in security zones with a retention period in line with data-protection law (typically 7-30 days in CH).
- A.7.5 Protecting against physical and environmental threats, fire-detection system, UPS, climate monitoring in the server room.
- A.7.7 Clear desk and clear screen, desk clearance, automatic screen lock after 5-15 minutes of inactivity.
- A.7.8 Equipment siting and protection, servers / switches in access-protected rooms, cable management.
- A.7.10 Storage media, mobile media inventory, mandatory encryption, destruction procedures.
- A.7.13 Equipment maintenance, maintenance contracts, patch cycles for hardware firmware.
- A.7.14 Secure disposal or re-use of equipment, certified media destruction (e.g. DIN 66399 level H4/H5), certificate archived.
Most frequent gap: A.7.14, old laptops are recycled or donated without documented data wiping; the risk source is systematically underestimated.
Technological controls (Annex A.8, 34 controls)
The technological controls are the largest block and cover the classic InfoSec stack. The ten most frequent gaps from SIDD audits in 2024-2025:
- A.8.2-A.8.3 Privileged access rights / Information access restriction, least privilege, regular access reviews (at least semi-annual), MFA for privileged accounts.
- A.8.5 Secure authentication, MFA for all external access and for administrative accounts; passkey/FIDO2 instead of SMS OTP where possible.
- A.8.7 Protection against malware, Endpoint Detection & Response (EDR), not only classic AV.
- A.8.8 Management of technical vulnerabilities, vulnerability scanning at least monthly, critical findings (CVSS ≥ 9.0) patched within 7 days. See vulnerability scanning.
- A.8.9 Configuration management (NEW 2022), hardened baseline configurations, drift detection.
- A.8.10 Information deletion (NEW 2022), deletion concept per data category with defined retention periods and automated execution.
- A.8.12 Data leakage prevention (NEW 2022), DLP solution for e-mail, cloud storage, endpoints.
- A.8.16 Monitoring activities (NEW 2022), central log management with correlation, SIEM or SaaS equivalent (e.g. Microsoft Sentinel).
- A.8.23 Web filtering (NEW 2022), category-based URL filtering at the endpoint or in the network.
- A.8.25-28 Secure development lifecycle, SDL with threat modelling, code review, pre-release pentest. Pentests via penetration testing.
Anyone who does not actively address the 11 new controls of the 2022 edition has the most common source of major non-conformities in external auditing.
Statement of Applicability and audit preparation
The SoA is the central document for any ISO 27001 audit. Per control of the 93 Annex A controls you must decide: applicable or not; for "applicable" the reference to the implementing procedure / technology; for "not applicable" a substantive justification (typical examples: A.7.9 Security of assets off-premises is only narrowly applicable to pure cloud organisations without employee hardware; A.5.7 Threat Intelligence is always applicable).
Audit-preparation checklist in 8 steps:
- SoA updated against all 93 controls, in particular the 11 new ones.
- Risk assessment under clause 6.1.2 with ≥ 90 days of currency.
- Risk treatment plan with measures, owners, deadlines.
- Management review (clause 9.3) of the last 12 months documented.
- Internal audit (clause 9.2) conducted and followed up.
- Corrective actions from the last audit implemented.
- KPIs / effectiveness measurements per theme.
- ISMS scope cleanly delineated, with reference to legally / regulatorily relevant interfaces (FINMA, DSG, GDPR).
Empirically, preparation of an initial audit takes 6-9 months; a re-certification with migration to the 2022 edition takes 3-4 months if the existing ISMS substance is solid.
How SIDD supports you
SIDD delivers ISO 27001 projects as a combined ISMS build-out / run mandate under ISMS / ISO 27001, from the gap assessment against the 93 controls through SoA drafting and risk treatment to support during certification. For ongoing operational responsibility we take on, where needed, the role of external CISO or ISB (External CISO/ISB) and bundle with technical services such as penetration testing and vulnerability scanning.
Companies wanting an initial gap assessment can request a half-day workshop with our ISO 27001 lead auditor via our contact form, the deliverable is a heatmap of the 93 controls with maturity and a roadmap proposal. For a concrete fixed-price mandate (typically 6-9 months build plus ongoing support) use the quote request. Awareness programmes as part of A.6.3 are bookable separately via IT security workshop SME.
