ISO 27001:2022 Annex A Controls
93 controls with practical Microsoft 365 implementation guidance. Each control page explains what it requires, how to implement it, and what auditors verify.
ISO 27001:2022 defines 93 Annex A controls across four categories. Generic guides describe these controls in theory. We implement them in practice — inside your Microsoft 365 tenant — and prove they're working with automated evidence collection.
What ISO 27001 actually requires
Context, leadership, planning, support, operations, performance evaluation, and improvement — the seven clauses that define how your ISMS operates. These are mandatory, not optional.
Organisational (37), People (8), Physical (14), and Technological (34) controls. You select which apply via your Statement of Applicability — then prove each one works.
Scope statement, risk assessment methodology, risk treatment plan, Statement of Applicability, information security policy, and 10 more. We generate these from your actual M365 configuration.
37 Organisational Controls
8 People Controls
14 Physical Controls
34 Technological Controls
Uncover your ISO 27001 gaps
Our free assessment evaluates your M365 configuration against all 93 controls and identifies gaps before your auditor does.
Find Your Control Gaps