← All insights
ISO 2700102 May 2026·7 min read

Annex A 2022: the seven controls that catch teams out

Threat intelligence, secure development, data masking — where most ISMS programmes need real work, not policy wording.

The 2022 revision to Annex A restructured the control set from 114 controls across 14 domains to 93 controls across four themes. Most of the changes are consolidations or clarifications, but eleven new controls were introduced, and seven of these require genuine capability rather than documentation. Teams that treat the new controls as a wording exercise typically pass Stage 1 certification and then fail Stage 2 when the auditor asks to see the control operating.

The first is A.5.7, threat intelligence. Auditors expect to see evidence that threat intelligence is being collected from relevant sources, analysed for applicability to your organisation, and used to inform security decisions. A subscription to a threat feed is not evidence of a control. A quarterly threat intelligence report that identifies specific threats to your sector and drives changes to detection rules or patching priorities is.

The second is A.5.23, information security for use of cloud services. This is broader than a cloud security policy. Auditors look for evidence that cloud services are procured with security requirements defined in advance, that shared responsibility is documented for each service, and that offboarding procedures actually work. A tabletop exercise that walks through the offboarding of a critical cloud service is the fastest way to identify gaps.

The third is A.5.30, ICT readiness for business continuity. The control expects the ICT continuity requirements to be derived from the business continuity strategy, not defined in isolation by the IT team. If your BCP and your ICT DR plan were written by different teams and have never been reconciled, this control will fail on inspection.

The fourth is A.8.9, configuration management. Auditors want to see baseline configurations for the systems in scope, evidence that deviations are detected, and a process for approving and recording changes. A CMDB that has not been reconciled with reality for six months is worse than no CMDB at all.

The fifth is A.8.10, information deletion. The control requires that information is deleted when no longer required, that deletion methods are appropriate to the sensitivity of the data, and that deletion is evidenced. Most organisations have retention policies; few have working deletion mechanisms across every system in scope. Start with the highest-sensitivity data stores and work outwards.

The sixth is A.8.11, data masking. Where personal data is used in non-production environments, masking or pseudonymisation is expected. Auditors are increasingly asking for a specific inventory of non-production environments and the masking approach used in each. "We use production data with additional access controls" is not an acceptable answer.

The seventh is A.8.28, secure coding. This is the control that most engineering-led organisations underestimate, because they assume their existing code review and testing practices satisfy it. The control expects secure coding standards to be defined, developer training to be evidenced, and vulnerabilities identified in code to be tracked to closure. A dependency-scanning tool without a triage process is not a control.

The pattern across these seven is consistent: the standard has moved from asking whether you have a policy to asking whether the policy is operating. Prepare for certification by walking each control end-to-end with the team that runs it, and by collecting the evidence you would produce if the auditor asked tomorrow.

Companies we've supported

59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai