Reference Controls
Reference controls are a catalog of suggested security safeguards that an organization can draw from when building its information security program, rather than a mandatory checklist that every organization must implement in full. In the context of ISO/IEC 27001, organizations select which reference controls apply to them based on their own risk assessment and document those choices, so the set of controls in use varies from one organization to another depending on scope.
Within ISO/IEC 27001, reference controls are the set of control objectives and controls listed in Annex A, which serves as a reference catalog rather than a prescriptive requirement. Applicability is determined through the organization's risk assessment and formalized in the Statement of Applicability (SoA), where each reference control is either selected, justified, or excluded with rationale. The certifiable requirements of the standard reside in clauses 4 through 10 (the ISMS requirements); Annex A functions as a supporting reference informed by risk treatment decisions. The structure and count of reference controls depend on the edition of the standard, as Annex A was restructured in the 2022 revision, so the specific version should be cited when referencing control counts. Because control selection is scope- and risk-dependent, the applicable reference control set differs across organizations and should not be treated as a universal mandate beyond what the standard itself requires.
Why it matters
Reference controls matter because they shift the emphasis of an information security program away from a fixed checklist and toward a risk-driven set of choices. In ISO/IEC 27001, Annex A functions as a catalog of suggested safeguards rather than a mandate to implement everything it lists. This distinction is important for compliance managers and auditors: the question during a certification audit is not whether an organization has deployed every reference control, but whether the controls it selected are justified by its risk assessment and documented appropriately in the Statement of Applicability.
This framing prevents two common failure modes. The first is treating Annex A as an exhaustive requirement and over-implementing controls that do not address the organization's actual risks, which wastes resources without improving security posture. The second is excluding controls without adequate rationale, which can lead to gaps that a certification body may flag as nonconformities. Because the applicable set of reference controls varies from one organization to another based on scope and risk, teams that understand this flexibility can build a program that is both defensible and appropriately tailored.
It is also worth noting the limits of what reference controls represent. Selecting and implementing a control from Annex A demonstrates that a safeguard has been considered and applied, but it does not by itself guarantee freedom from incidents. The certifiable requirements of ISO/IEC 27001 reside in clauses 4 through 10; Annex A supports those requirements as a reference informed by risk treatment decisions, rather than replacing them.
Who it's relevant to
Inside Reference Controls
Common questions
Answers to the questions practitioners most commonly ask about Reference Controls.