simpl.
Cybersecurity GRC 21 items

ISO/IEC 27001:2022 Annex A Controls Audit

Internal audit of the ISO/IEC 27001:2022 Annex A controls across the four themes: organizational, people, physical, and technological.

ISO 27001:2022ISO 27002:2022

Free PDF · enter your email to download.

ISMS Clauses (4-10)

  • Is the scope of the ISMS documented, including interfaces and dependencies? *
  • Is there an approved information security policy signed by top management? *
  • Is there a documented risk assessment and risk treatment methodology? *
  • Is a Statement of Applicability (SoA) maintained with justifications for included/excluded controls? *
  • Are internal audits and management reviews conducted on a defined schedule? *

Organizational Controls (A.5)

  • Are information security roles and responsibilities defined and allocated? *
  • Is an inventory of information and other associated assets maintained with owners assigned? *
  • Is information classified according to security needs (confidentiality, integrity, availability)? *
  • Are information security requirements addressed in supplier agreements? *
  • Is threat intelligence collected and analyzed to inform security decisions? *

People Controls (A.6)

  • Is screening performed on candidates before employment, proportionate to risk? *
  • Do personnel receive security awareness, education, and training relevant to their role? *
  • Is a disciplinary process defined for security policy violations? *

Physical Controls (A.7)

  • Are secure areas protected by physical entry controls? *
  • Are equipment and cabling protected against environmental threats and interference? *
  • Is a clear desk and clear screen practice enforced? *

Technological Controls (A.8)

  • Is privileged access management implemented and restricted? *
  • Is protection against malware implemented and maintained? *
  • Is technical vulnerability management performed with defined remediation timelines? *
  • Are logging and monitoring activities implemented for anomaly detection? *
  • Is data masking, encryption, or leakage prevention applied where required? *

Download the full ISO/IEC 27001:2022 Annex A Controls Audit checklist

Get it as a clean, printable PDF — free.