Skip to main content
Category: Control Types and Framework

Technological Controls

Also known as: Technology Controls, Annex A Technological Controls
Simply put

Technological Controls are one of the four groupings used to organize the reference security controls listed in Annex A of the ISO/IEC 27001:2022 revision. As the name suggests, this theme covers safeguards that are implemented mainly through technology, such as protections applied to systems, networks, and data. An organization selects which of these controls apply to it based on its risk assessment and documents those choices in its Statement of Applicability.

Formal definition

In the ISO/IEC 27001:2022 revision, Annex A restructured its reference controls into four themes, of which Technological Controls is one; the other themes address organizational, people, and physical measures. This grouping replaced the prior categorization used in the ISO/IEC 27001:2013 version, and the total control count changed with the revision, so the applicable theme structure and control counts depend on the edition cited. Annex A controls, including those in the Technological Controls theme, are reference controls that are not universally mandatory; they are selected via the Statement of Applicability and informed by the organization's risk assessment, with the certifiable ISMS requirements themselves residing in clauses 4 through 10 rather than in Annex A. Implementation guidance for these reference controls is elaborated separately in ISO/IEC 27002, and certification against ISO 27001 covers only the defined scope of the ISMS. This theme is specific to ISO 27001 and should not be conflated with the SOC 2 Trust Services Criteria.

Why it matters

Technological Controls matter because they organize the technology-based safeguards that most organizations rely on to protect their systems, networks, and data. In the ISO/IEC 27001:2022 revision, Annex A groups its reference controls into four themes, and the Technological Controls theme brings together the measures that are implemented mainly through technology rather than through policy, personnel, or physical means. Understanding this grouping helps organizations reason about their technical safeguards in a structured way when deciding which controls apply to them.

This theme carries particular weight during scoping and certification because Annex A controls are reference controls rather than a universally mandatory checklist. Which Technological Controls apply is determined by the organization's risk assessment and documented in the Statement of Applicability, meaning two organizations certified against ISO 27001 may implement very different sets of technological safeguards depending on their scope and risk profile. It is also important to remember that certification against ISO 27001 covers only the defined scope of the ISMS, so the presence of a Technological Controls theme does not by itself guarantee any specific technical outcome.

Because the structure and control counts changed between the ISO/IEC 27001:2013 and 2022 editions, practitioners should specify which version they are citing when discussing this theme. The theme is also specific to ISO 27001 and should not be conflated with the SOC 2 Trust Services Criteria; the two frameworks organize controls differently, and mapping between them is only partial.

Who it's relevant to

Security engineers and IT teams
These practitioners typically implement the safeguards captured under the Technological Controls theme, which cover technology-based protections applied to systems, networks, and data. They often refer to ISO/IEC 27002 for detailed implementation guidance on any reference controls the organization has selected.
ISMS managers and GRC professionals
Those responsible for the information security management system use the Technological Controls theme when performing risk assessments and completing the Statement of Applicability, where the choice of which reference controls apply is documented. They also need to specify whether they are working from the 2013 or 2022 edition, since the theme structure and control counts differ between versions.
ISO 27001 certification auditors
Auditors from accredited certification bodies review how an organization has selected and applied Annex A reference controls, including those in the Technological Controls theme, against its documented risk assessment and Statement of Applicability. They assess these choices within the certifiable ISMS requirements found in clauses 4 through 10 and only for the defined scope of the ISMS.
Compliance teams managing multiple frameworks
Professionals who work across ISO 27001 and SOC 2 should note that the Technological Controls theme is specific to ISO 27001 and is distinct from the SOC 2 Trust Services Criteria. Mapping between the two frameworks is possible but only partial, and satisfying one does not automatically satisfy the other.

Inside Technological Controls

Annex A Technological Controls theme
In the ISO/IEC 27001:2022 revision, Annex A reference controls were reorganized into four themes, one of which groups technology-oriented controls. This theme is one part of the restructured Annex A, which contains 93 controls in the 2022 version compared with 114 controls organized differently in the 2013 version.
Reference controls, not requirements
Technological controls in Annex A are reference controls that inform an organization's risk treatment. They are selected via the Statement of Applicability and informed by the risk assessment, rather than being certifiable requirements in themselves. The certifiable ISMS requirements reside in clauses 4 through 10.
Selection through the Statement of Applicability
Whether a given technological control applies depends on the organization's scope and risk assessment. The Statement of Applicability documents which Annex A controls are included or excluded and the justification, so the applicable set of technological controls varies by organization.
Relationship to ISO 27002
ISO 27002 provides implementation guidance for the controls referenced in Annex A, including the technological controls. Annex A lists the controls at a summary level, while ISO 27002 offers more detailed guidance; ISO 27002 is guidance and is not itself certifiable.

Common questions

Answers to the questions practitioners most commonly ask about Technological Controls.

Are the technological controls in ISO 27001 Annex A mandatory for certification?
No. Annex A controls, including those grouped under the technological theme in the 2022 revision, are reference controls rather than a mandatory checklist. Organizations select applicable controls through a risk assessment and document their choices, along with any exclusions and justifications, in the Statement of Applicability. The certifiable requirements are found in clauses 4 through 10. Whether a specific technological control applies depends on the defined scope of the ISMS and the results of the risk assessment.
Does implementing technological controls for SOC 2 mean I am also satisfying ISO 27001's technological controls?
Not automatically. SOC 2 evaluates controls against the Trust Services Criteria (with Security, the Common Criteria, always required and other categories selected by scope), while ISO 27001 evaluates an information security management system against clauses 4 through 10 and reference controls selected via the Statement of Applicability. Mapping between the two is possible but partial, and satisfying one framework does not guarantee satisfying the other. The frameworks differ in structure, evidence expectations, and how outcomes are expressed, a SOC 2 report versus an ISO 27001 certificate.
How do I decide which technological controls to include in my ISO 27001 Statement of Applicability?
Selection is typically informed by the risk assessment performed against the defined scope of the ISMS. Controls are chosen to address identified risks, and any Annex A reference controls that are excluded should be justified in the Statement of Applicability. In most engagements the applicable controls, their implementation status, and the rationale for inclusion or exclusion are documented so the certification body can evaluate them. The appropriate set depends on your scope, risk profile, and applicable requirements rather than a universal list.
What kind of evidence supports technological controls in a SOC 2 Type II examination?
A SOC 2 Type II examination assesses both the suitability of design and the operating effectiveness of controls over a defined review period, so evidence typically needs to demonstrate that controls operated consistently across that period rather than only at a point in time. The specific evidence expected depends on the auditor, the scope, and the applicable Trust Services Criteria. Keep in mind that the resulting report attests only to the controls and period covered and does not guarantee freedom from breaches.
Should technological controls be documented differently for SOC 2 versus ISO 27001?
The two frameworks organize documentation differently. For ISO 27001, applicable controls and their justifications are typically captured in the Statement of Applicability and supported by ISMS documentation tied to clauses 4 through 10. For SOC 2, controls are described in relation to the Trust Services Criteria within the scope of the examination. Because mapping between the frameworks is only partial, organizations pursuing both often maintain documentation that can support each set of expectations rather than assuming a single format satisfies both.
How does the version of ISO 27001 affect how I structure technological controls?
The version matters because Annex A was restructured in the 2022 revision, which grouped controls into four themes and changed the total count from the 2013 edition. When referencing control counts or the technological grouping, specify the edition, since precise numbers depend on the version in use. The applicable controls for your ISMS should reflect the edition you are certifying against and be selected through your risk assessment and Statement of Applicability.

Common misconceptions

Implementing all the technological controls in Annex A is mandatory to achieve ISO 27001 certification.
Annex A controls, including the technological theme, are reference controls selected via the Statement of Applicability and informed by the risk assessment. Controls may be excluded with justification depending on scope; the certifiable requirements are in clauses 4 through 10, not the Annex A list itself.
The ISO 27001 technological controls are equivalent to the SOC 2 Trust Services Criteria.
These belong to different frameworks. ISO 27001 Annex A technological controls are reference controls under a management system standard, while the Trust Services Criteria (with Security as the required Common Criteria and Availability, Processing Integrity, Confidentiality, and Privacy as optional) underpin a SOC 2 attestation examination. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
The number of technological controls is fixed across ISO 27001 editions.
Annex A was restructured in the 2022 revision into 93 controls across four themes, compared with 114 controls in the 2013 version. Because control counts and organization depend on the edition, the version should always be specified when citing numbers.

Best practices

Base the selection of technological controls on the risk assessment and document each inclusion or exclusion, with justification, in the Statement of Applicability.
Specify which edition of ISO/IEC 27001 you are working against (for example, the 2022 revision with 93 controls in four themes), since control organization and counts differ by version.
Use ISO 27002 as implementation guidance for the referenced technological controls, while keeping in mind that ISO 27002 is guidance and is not itself certifiable.
Align technological controls with the certifiable ISMS requirements in clauses 4 through 10, rather than treating the Annex A list as the sole basis for the management system.
Where an ISO 27001 ISMS coexists with a SOC 2 examination, map technological controls to the relevant Trust Services Criteria only as a partial exercise, recognizing that meeting one framework does not automatically satisfy the other.
Review the applicability and effectiveness of selected technological controls periodically, since the appropriate set depends on scope and evolving risk rather than a fixed universal list.