Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 control assessment explained

ISO 27001 Control Assessment: A Clear Annex A Scoring Guide

An ISO 27001 control assessment is the part of any ISMS evaluation that scores the 93 Annex A controls of ISO/IEC 27001:2022 one by one: is the control applicable, is it implemented, is it operating as documented, and can that be shown. It is the largest single block of work in a self-assessment, a gap assessment or an internal audit, and it is the block auditors spend most of stage 2 on. The 2022 edition made it easier in one respect — 93 controls in four themes rather than 114 in fourteen — and richer in another, because ISO 27002:2022 gave every control five attributes that let the assessment be sliced by control type, security property or cybersecurity function. This guide explains how to score each control, what evidence each theme typically needs, how to use the attributes, and the controls that most often score lower than their owners expect.

ISO 27001 control assessment: 93 Annex A controls in 4 themes, 5 attributes each
The control assessment scores applicability, implementation and evidence for every Annex A control, and the 27002 attributes let the results be viewed by function.

What the ISO 27001 control assessment covers

The ISO 27001 control assessment covers Annex A of ISO 27001:2022, which lists 93 controls: A.5 organizational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). Eleven are new in 2022 — threat intelligence (A.5.7), cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23) and secure coding (A.8.28) — and they are where organizations that transitioned by renaming their 2013 documents score worst. The controls are not mandatory individually: clause 6.1.3 requires the organization to compare its risk-treatment controls against Annex A, produce a Statement of Applicability listing the necessary controls with justification for inclusion and exclusion, and state whether each is implemented. The control assessment is the evidence behind that last column.

Scoring each control in the ISO 27001 control assessment

The ISO 27001 control assessment asks three questions per control, answered in order:

Question Possible answers What settles it
1. Is it applicable? Applicable / Not applicable with justification The risk assessment; whether the asset or activity the control addresses exists in scope. A.7 physical controls are not N/A because the office is small; A.8.28 secure coding is N/A only if no software is developed in scope.
2. Is it implemented? 0 Not implemented · 1 Planned · 2 Partial · 3 Implemented · 4 Implemented and verified Documented approach plus operating evidence for the period; verified means monitored and reviewed with results
3. What is the evidence? A named document, record, report or configuration The assessor’s reference, not the owner’s assurance

The score attaches to the control as the organization defined it. ISO 27002:2022 gives implementation guidance, not requirements; the organization’s own policy sets what “implemented” means for A.8.15 logging in its environment, and the assessment scores against that. A control with no organizational definition cannot score above 1, because there is nothing to be implemented against. Our guide to the ISO 27001 self-assessment covers the five-point scale in detail.

ISO 27001 control assessment evidence by theme

Theme Controls Typical evidence Common weak points
A.5 Organizational 37 Approved policies (A.5.1); roles (A.5.2); asset inventory (A.5.9); classification scheme (A.5.12); supplier agreements and reviews (A.5.19–A.5.22); incident records (A.5.24–A.5.28); SoA and legal register (A.5.31) Threat intelligence (A.5.7) with no process; supplier monitoring never performed; ICT continuity (A.5.30) untested
A.6 People 8 Screening records (A.6.1); contract clauses (A.6.2); training records (A.6.3); disciplinary process (A.6.4); leaver checklist (A.6.5); NDAs (A.6.6); remote working rules (A.6.7); reporting route (A.6.8) Screening not evidenced for contractors; awareness training with no attendance records
A.7 Physical 14 Perimeter and entry controls (A.7.1–A.7.2); physical monitoring (A.7.4); clear desk (A.7.7); equipment siting and maintenance (A.7.8, A.7.13); secure disposal (A.7.14) Physical monitoring (A.7.4) new in 2022 and unaddressed; off-site equipment (A.7.9) for remote staff
A.8 Technological 34 Endpoint standards (A.8.1); privileged access records (A.8.2); MFA configuration (A.8.5); vulnerability scans and patch records (A.8.8); configuration baselines (A.8.9); deletion and masking (A.8.10–A.8.11); DLP (A.8.12); backups tested (A.8.13); logs and monitoring (A.8.15–A.8.16); secure development lifecycle (A.8.25–A.8.29) Monitoring (A.8.16) as an intention; configuration management (A.8.9) undocumented; secure coding (A.8.28) with no standard

Using the ISO 27002 attributes

ISO 27002:2022 tags every control with five attributes, and an assessment that records them can be reported five ways from one dataset:

Attribute Values What the view shows
Control type Preventive, Detective, Corrective Whether the ISMS is all prevention and no detection — a common shape
Information security properties Confidentiality, Integrity, Availability Where availability controls lag confidentiality controls
Cybersecurity concepts Identify, Protect, Detect, Respond, Recover A NIST CSF-style function view for boards that know that model
Operational capabilities 15 values: Governance, Asset management, Information protection, Human resource security, Physical security, System and network security, Application security, Secure configuration, Identity and access management, Threat and vulnerability management, Continuity, Supplier relationships security, Legal and compliance, Information security event management, Information security assurance The view that maps to who owns what
Security domains Governance and ecosystem, Protection, Defence, Resilience The ISO 27002 grouping used in some sector schemes

In an ISO 27001 control assessment the attributes cost nothing to record — they are fixed per control and published in ISO 27002 — and they turn a 93-row register into a management report. An average score by cybersecurity concept, for example, shows whether Detect and Respond are being funded. They also make the control assessment reusable for other frameworks: a NIST CSF 2.0 profile can be populated from the Identify-to-Recover view directly.

Controls that score lower than their owners expect

  1. A.5.7 Threat intelligence. Reading vendor blogs is not a process. The control expects collection, analysis and use of threat information, with records that it changed something.
  2. A.5.23 Cloud services. Requires a process for acquiring, using, managing and exiting cloud services, with security requirements in the agreements. Most organizations have the services and none of the process.
  3. A.5.30 ICT readiness for business continuity. Requires ICT continuity planned, implemented, maintained and tested against business continuity objectives. A backup policy does not score above 2.
  4. A.8.9 Configuration management. Documented baselines, enforced and reviewed. Environments built by hand score 1.
  5. A.8.16 Monitoring activities. Networks, systems and applications monitored for anomalous behaviour with action taken. A SIEM nobody looks at is a 2.
  6. A.5.19–A.5.22 Supplier controls. Agreements exist; the monitoring and review the controls require does not. Our guide to supplier security assessment covers what the evidence looks like.

From control assessment to the Statement of Applicability

The control assessment feeds the SoA directly: applicability and justification go into the first two columns, the implementation status into the third, and the evidence reference into the fourth column most organizations add for the auditor. Controls scored below 3 appear in the SoA as “not implemented” or “partially implemented” with a planned date, which is acceptable at stage 1 and rarely at stage 2. Keeping the assessment and the SoA in one register, re-scored on a cycle, gives the ISMS its clause 9.1 measurement for free. The results are presented through the ISO 27001 assessment report.

Frequently asked questions

How many controls does an ISO 27001 control assessment cover?
All 93 Annex A controls of ISO/IEC 27001:2022 — 37 organizational, 8 people, 14 physical, 34 technological — scored for applicability, implementation and evidence.

Are all 93 controls mandatory?
No. Clause 6.1.3 requires each to be considered and the Statement of Applicability to justify inclusion or exclusion. The clause 4–10 requirements are mandatory; the controls are selected through risk treatment.

What are the ISO 27002 attributes?
Five tags per control: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. Recording them lets one assessment be reported by function, by property or by owner.

Which controls are new in 2022?
Eleven: A.5.7, A.5.23, A.5.30, A.7.4, A.8.9, A.8.10, A.8.11, A.8.12, A.8.16, A.8.23 and A.8.28. They are the ones most often scored low by organizations that transitioned by renaming their 2013 documents.

Can a control be scored implemented without a policy?
Rarely. A control needs an organizational definition of what implementation means before it can be assessed as implemented; a practice with no documented approach usually scores 2 at best.

Where this leaves you

Run the ISO 27001 control assessment as three questions per control — applicable, implemented, evidenced — across all 93, tag each with the ISO 27002 attributes, and keep the result in the same register as the Statement of Applicability. Look hardest at the eleven 2022 controls and the six that score low above; that is where the auditor will.

References

More on ISO 27001 assessment

A control-by-control questionnaire across all 93 Annex A controls and the clauses, with automatic scoring, risk analysis and summary dashboards, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.