Skip to main content
Category: Control Types and Framework

People Controls

Also known as: Annex A.6 Controls, ISO 27001 People Controls, A.6 People Controls
Simply put

People Controls are the set of security measures in ISO/IEC 27001 that address the human side of information security, such as employee screening, training, and terms of employment. They aim to reduce risks that arise from how staff and contractors handle data and systems, in part by fostering a culture of security awareness. These controls are one grouping among the reference controls listed in Annex A, and are selected based on an organization's risk assessment rather than being universally mandatory.

Formal definition

In the ISO/IEC 27001:2022 revision, People Controls form one of the four themes into which the 93 Annex A reference controls were reorganized (the others being Organizational, Technological, and Physical controls). This theme, corresponding to ISO/IEC 27002 Clause 6, comprises 8 controls addressing the secure management of human resources, including screening (6.1), terms and conditions of employment (6.2), and related measures across the employment lifecycle. As Annex A reference controls, People Controls are selected and justified through the risk assessment and documented in the Statement of Applicability; they are not inherently required in every ISMS. Note that the four-theme structure and control counts reflect the 2022 edition and differ from the 2013 version, and Annex A controls are distinct from the SOC 2 Trust Services Criteria.

Why it matters

Many information security incidents originate not from technical vulnerabilities but from human behavior, how staff and contractors handle data, credentials, and systems. People Controls in ISO/IEC 27001 address this human dimension directly, targeting risks that purely technological safeguards cannot fully mitigate. By covering the employment lifecycle from screening through terms of employment, this theme helps organizations reduce the likelihood that gaps in awareness, judgment, or accountability lead to compromise.

Beyond individual measures, People Controls contribute to building a security-first culture. Regular awareness training, for example, can help employees recognize and respond appropriately to threats, while clearly defined terms and conditions of employment establish accountability for how personnel interact with information assets. Because these controls are selected and justified through the risk assessment and documented in the Statement of Applicability, they allow an organization to tailor its human-factor safeguards to the specific risks it faces rather than applying a fixed checklist.

It is worth emphasizing that People Controls are Annex A reference controls, not inherently mandatory in every ISMS. Their applicability depends on the outcome of the organization's risk assessment, and their presence in an ISMS reflects a deliberate scoping decision. They also address only the human-factor risks within the defined scope of the ISMS and should be understood as one grouping among the broader set of Organizational, Technological, and Physical controls.

Who it's relevant to

GRC and Compliance Managers
Those responsible for building or maintaining an ISMS need to determine, through the risk assessment, whether and how People Controls apply, and to document those decisions in the Statement of Applicability. Understanding that these controls address human-factor risks helps them scope their program appropriately rather than treating every Annex A control as mandatory.
Human Resources and People Operations Teams
Because People Controls span the employment lifecycle, including screening and terms and conditions of employment, HR functions often own or co-own their implementation. These teams translate control requirements into practical hiring, onboarding, and employment practices that support the organization's security objectives.
Security Awareness and Training Leads
Those managing awareness programs are central to the culture-of-security-awareness goal that People Controls support. Regular training sessions help employees and contractors interact with data and systems in a security-conscious way, addressing risks that technical controls alone cannot cover.
ISO 27001 Auditors and Certification Bodies
Auditors assessing an ISMS review how selected People Controls are justified through the risk assessment, reflected in the Statement of Applicability, and operating in practice. Familiarity with the 2022 four-theme structure and Clause 6 helps them evaluate the human-factor aspects of an organization's security management within the defined scope.

Inside People Controls

People Controls (ISO/IEC 27001:2022 Annex A theme)
One of the four themes into which Annex A reference controls were reorganized in the 2022 revision. The People theme groups controls concerned with the human aspects of information security, such as those relating to personnel and their conduct. The specific controls selected for an organization are determined through risk assessment and documented in the Statement of Applicability, so applicability varies by scope.
Relationship to the four Annex A themes
In the 2022 revision, the reference controls (93 in total across the edition) were restructured into four themes: Organizational, People, Physical, and Technological. People Controls is one of these themes. This structure applies to the 2022 version; the 2013 version organized its 114 controls differently, so the theme grouping should not be attributed to the earlier edition.
Selection via risk assessment and Statement of Applicability
People Controls, like all Annex A reference controls, are not automatically mandatory. They are selected based on the results of the organization's risk assessment and treatment process, and inclusions or exclusions are justified in the Statement of Applicability. The certifiable ISMS requirements themselves reside in clauses 4 through 10, not in Annex A.
Guidance versus requirement
Annex A provides a reference set of controls, while detailed implementation guidance for controls is found in ISO/IEC 27002. ISO 27002 is a supporting guidance standard and is not itself certifiable; certification is against ISO/IEC 27001.

Common questions

Answers to the questions practitioners most commonly ask about People Controls.

Are 'People Controls' a SOC 2 concept or an ISO 27001 concept?
The term 'People Controls' comes specifically from the ISO/IEC 27001:2022 revision, which reorganized Annex A reference controls into four themes, one of which is People Controls. SOC 2 does not use this terminology. SOC 2 addresses personnel-related matters through the Trust Services Criteria, principally the Security category (the Common Criteria), rather than through a distinct 'People Controls' grouping. Because the two frameworks structure these safeguards differently, it is inaccurate to treat 'People Controls' as an interchangeable label across both.
Does implementing every People Control in Annex A make them mandatory for certification?
No. Annex A of ISO/IEC 27001:2022, including the People Controls theme, is a list of reference controls, not a mandatory checklist. The certifiable requirements sit in clauses 4 through 10 (the ISMS requirements). Annex A controls are selected through a risk assessment and documented in the Statement of Applicability, where an organization may justify excluding controls that are not applicable to its scope. Whether a given People Control applies depends on the organization's risk assessment and scope rather than a universal mandate.
How does an organization decide which People Controls to include in its Statement of Applicability?
In most implementations, inclusion is driven by the results of the risk assessment and the defined scope of the ISMS. The organization evaluates which Annex A reference controls address identified risks, then records each control's applicability, along with justification for inclusion or exclusion, in the Statement of Applicability. Because these decisions are scope- and risk-dependent, two organizations may reasonably reach different conclusions about which People Controls apply.
What kinds of activities typically fall under the People Controls theme?
The People Controls theme in ISO/IEC 27001:2022 generally addresses safeguards associated with individuals in their relationship to the organization, such as matters arising before, during, and after employment. Because the specific reference controls and their exact wording depend on the 2022 edition of the standard, organizations should consult the current text and ISO/IEC 27002:2022, which provides implementation guidance, rather than relying on paraphrased summaries when scoping.
How do People Controls relate to ISO/IEC 27002?
ISO/IEC 27002:2022 provides implementation guidance for the Annex A reference controls listed in ISO/IEC 27001:2022, including those grouped under the People Controls theme. ISO 27002 is a guidance document and is not itself certifiable; certification is against ISO 27001. Organizations typically use ISO 27002 to inform how they design and operate the controls they have selected, while the ISMS requirements and the Statement of Applicability remain governed by ISO 27001.
Can evidence for People Controls be reused for a SOC 2 examination?
Some underlying evidence may be relevant to both frameworks, since personnel-related safeguards appear in each, but mapping between ISO 27001 and SOC 2 is partial and satisfying one does not automatically satisfy the other. A SOC 2 examination evaluates controls against the applicable Trust Services Criteria and, for a Type II, their operating effectiveness over a defined review period, whereas ISO 27001 assesses the ISMS and selected Annex A controls. Depending on scope and the assessor or auditor, evidence supporting People Controls may support certain SOC 2 criteria, but it should be evaluated against each framework's own requirements rather than assumed to transfer.

Common misconceptions

All People Controls in Annex A must be implemented to achieve ISO 27001 certification.
Annex A controls, including those in the People theme, are reference controls selected through risk assessment. Inclusions and exclusions are justified in the Statement of Applicability, so applicability depends on scope and risk rather than being universally mandatory.
The People Controls theme has always been part of the ISO 27001 Annex A structure.
The organization of Annex A into four themes, including People Controls, reflects the 2022 revision. The 2013 version arranged its controls differently and did not use this four-theme structure. The version should be specified whenever citing the theme or control counts.
People Controls in ISO 27001 are equivalent to a corresponding category in the SOC 2 Trust Services Criteria.
The ISO 27001 Annex A themes and the SOC 2 Trust Services Criteria are distinct frameworks and should not be conflated. Mapping between them is possible but partial, and addressing People Controls under ISO 27001 does not automatically satisfy any SOC 2 criterion.

Best practices

Drive the selection of People Controls from your documented risk assessment and treatment process, and record each inclusion or exclusion with justification in the Statement of Applicability.
Always specify the ISO/IEC 27001 edition (e.g., 2022) when referencing the People Controls theme, since the theme structure and control counts differ between versions.
Consult ISO/IEC 27002 for implementation guidance on the controls selected, while remembering that certification is assessed against ISO/IEC 27001 clauses 4 through 10.
Keep the People theme distinct from the SOC 2 Trust Services Criteria in documentation and communications; treat any framework mapping as partial rather than equivalent.
Review the applicability of People Controls whenever the ISMS scope changes, as relevance depends on scope and identified risks rather than a fixed universal set.
Ensure that evidence supporting People Controls aligns with the defined ISMS scope, recognizing that certification covers only that scope.