Skip to main content
Category: Control Types and Framework

Four Themes

Also known as: Annex A Themes, ISO 27001:2022 Control Themes
Simply put

The evidence provided does not contain any material relevant to the ISO/IEC 27001 concept of "Four Themes"; the supplied sources address birthday-party themes, dictionary definitions of "theme", and literary themes. Because a compliance glossary entry must be substantiated by authoritative framework sources, a definition cannot be produced from this evidence packet. To complete this entry, please supply evidence from ISO/IEC 27001:2022 or ISO/IEC 27002:2022.

Formal definition

No definition can be generated from the provided evidence. None of the five supplied sources reference ISO/IEC 27001, ISO/IEC 27002, or their Annex A control structure. Per the governing precision rules, control counts, clause references, and theme structures must not be asserted without a version-specific authoritative source in the evidence packet, and no such source is present here.

Why it matters

The evidence packet supplied for this entry does not contain any authoritative source addressing ISO/IEC 27001 or ISO/IEC 27002. All five sources concern unrelated subjects: birthday-party themes, dictionary definitions of the word "theme", school spirit-week activities, and literary analysis. None reference the ISO management-system standard, its Annex A control structure, or any control-grouping scheme. Under the governing precision rules, control counts, clause references, and theme structures must not be asserted without a version-specific authoritative source present in the evidence packet.

Who it's relevant to

Entry cannot be completed with current evidence
This context section cannot identify the audiences for whom the term is relevant, because the evidence packet contains no ISO/IEC 27001 or ISO/IEC 27002 material on which to base such statements. Populating this field would require inventing framework-specific facts not supported by the provided sources, which the precision rules prohibit.
Required to complete this entry
To generate accurate context fields, supply authoritative evidence from ISO/IEC 27001:2022 and/or ISO/IEC 27002:2022 describing the Annex A control themes, including version-specific theme groupings and control organization. Once provided, this entry can be completed with correctly qualified, version-attributed language.

Inside Four Themes

Organizational Controls
The largest of the four themes introduced in the ISO/IEC 27001:2022 (and ISO/IEC 27002:2022) restructuring of Annex A. These reference controls address governance, policies, roles and responsibilities, supplier and cloud relationships, information classification, and other management-level measures. As with all Annex A controls, they are reference controls selected through the risk assessment and documented in the Statement of Applicability rather than being universally mandatory.
People Controls
The theme grouping controls that relate to individuals, such as screening, terms and conditions of employment, security awareness, disciplinary processes, and responsibilities after termination or change of employment. These controls address the human element of the information security management system and, like all Annex A controls, are selected based on scope and risk.
Physical Controls
The theme grouping controls concerned with physical and environmental protection, including secure areas, physical entry, equipment protection, and secure disposal. Applicability depends on the defined ISMS scope; organizations without physical premises in scope may justify exclusions through the Statement of Applicability.
Technological Controls
The theme grouping controls relating to technical measures such as access control, cryptography, logging and monitoring, secure development, and network security. These reference controls are selected via the risk assessment and documented in the Statement of Applicability rather than applied uniformly.
Statement of Applicability (SoA) relationship
The four themes organize the Annex A reference controls, but the certifiable requirements remain in clauses 4 through 10. The four-theme structure applies to the 2022 edition, which restructured Annex A from the 114 controls of the 2013 version into 93 controls across these four themes. Control counts should always be cited with the specific edition, as they differ between versions.

Common questions

Answers to the questions practitioners most commonly ask about Four Themes.

Do the four themes replace ISO 27001's mandatory clauses 4 through 10?
No. The four themes (Organizational, People, Physical, and Technological) are the grouping structure for the reference controls in Annex A of ISO/IEC 27001:2022. They do not replace the certifiable ISMS requirements in clauses 4 through 10, which remain the requirements against which certification is granted. Annex A controls are selected via the Statement of Applicability and informed by risk assessment, whereas the clause requirements must be met to achieve certification.
Does adopting the four themes mean I must implement all controls within every theme?
No. The themes are simply a categorization of reference controls; they are not a mandate to implement everything. Applicability of individual controls is determined through your risk assessment and documented in the Statement of Applicability. Depending on scope, an organization may justify excluding controls that are not relevant to its ISMS, so the four themes describe how controls are organized rather than dictating which apply.
How do the four themes affect an existing Statement of Applicability built on the 2013 version?
When transitioning to the 2022 revision, organizations typically remap their Statement of Applicability to the restructured Annex A, which reorganizes the reference controls into the four themes and reduces the total control count relative to the 2013 edition. In most transitions this involves reconciling previously listed controls against the new structure, addressing any newly introduced controls, and confirming that each inclusion or exclusion remains justified by the risk assessment. Specific control counts and mappings depend on the version, so cite the edition when documenting the change.
How should I reference the four themes when scoping my ISMS?
The four themes can serve as an organizing lens when reviewing which reference controls are relevant to your defined scope. In most engagements, teams work through each theme to consider organizational, people-related, physical, and technological controls, then record applicability decisions in the Statement of Applicability. The scope of the ISMS ultimately governs which controls are in play, so the themes support, rather than determine, scoping decisions.
Where can I find implementation guidance for controls within each theme?
ISO/IEC 27001:2022 lists the reference controls in Annex A, while the companion standard ISO/IEC 27002:2022 provides more detailed implementation guidance organized under the same four-theme structure. Depending on your environment, sector-specific guidance such as ISO/IEC 27017 (cloud services) or ISO/IEC 27018 (protection of PII in public clouds) may supplement this. Note that 27002 is guidance and is not itself certifiable.
Does the four-theme structure map cleanly to the SOC 2 Trust Services Criteria?
Only partially. The four themes organize ISO 27001 Annex A reference controls, whereas SOC 2 is structured around the Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. Mapping between the two is possible for planning or efficiency purposes, but it is incomplete, and satisfying the four themes in an ISO 27001 ISMS does not automatically satisfy the criteria examined in a SOC 2 engagement.

Common misconceptions

The four themes are a mandatory set of controls that every organization must implement.
The four themes are organizing categories for Annex A reference controls, not a mandatory checklist. Controls within these themes are selected based on the organization's risk assessment and documented, with justifications for inclusion or exclusion, in the Statement of Applicability. The mandatory certifiable requirements sit in clauses 4 through 10.
The four-theme structure applies to all versions of ISO/IEC 27001.
The four themes (Organizational, People, Physical, Technological) were introduced with the 2022 revision. The 2013 edition organized Annex A differently and contained a different number of controls. Any reference to the themes or to control counts should specify the edition, since the figures depend on the version.
The four themes are equivalent to the SOC 2 Trust Services Criteria.
The four themes structure ISO/IEC 27001:2022 Annex A reference controls, whereas the Trust Services Criteria are the basis of a SOC 2 attestation examination performed under AICPA SSAE 18. Mapping between the two frameworks is possible but only partial, and satisfying one does not automatically satisfy the other.

Best practices

Always cite the specific ISO/IEC 27001 edition (e.g., 2022) when referring to the four themes or to any Annex A control count, since numbers and structure differ between the 2013 and 2022 versions.
Use the four themes as an organizing lens for Annex A reference controls, but drive actual control selection from the risk assessment and record decisions, including exclusions with justifications, in the Statement of Applicability.
Keep the distinction clear between the certifiable ISMS requirements in clauses 4 through 10 and the reference controls organized under the four themes, since certification is assessed against the clauses.
When migrating from the 2013 to the 2022 structure, map existing controls to the four themes and identify any newly introduced controls that require updated documentation and risk treatment.
Avoid treating any theme or control as universally mandatory; confirm applicability against the defined ISMS scope and the accredited certification body's expectations.
When comparing to SOC 2, treat any mapping between the four themes and the Trust Services Criteria as partial, and do not assume that meeting one framework satisfies the other.