Skip to content
ISO 27001

ISO 27001 Domains: How Many There Are and What They Do

·
5 min read
HR on one side, IT on the other?
Manage devices, licenses, and security from one place. Synced with your team’s joiners and leavers. Discover Factorial IT
Written by

ISO 27001 is the international standard for managing information security. When people talk about its domains, they’re referring to the way the standard groups security controls within Annex A. There’s a subtle catch here that trips a lot of people up, because that structure changed with the 2022 revision and the term domain actually belongs to the earlier version.

In this article, you’ll see how many domains the standard used to have, what they’ve turned into, and what each block is for, whether you’re starting from the 2013 version or already working with the 2022 one.

What Are the ISO 27001 Domains?

Domains are the broad categories ISO 27001 uses to organize the security controls in its Annex A. Each domain groups together the controls that tackle the same aspect of information security, like access control, physical security, or supplier relationships.

Their job is to give structure to the Information Security Management System, or ISMS. Instead of juggling a flat list of dozens of scattered controls, your organization works by theme. That makes it easier to divide up responsibilities, assess risk block by block, and confirm nothing slips through the cracks.

One thing’s worth clearing up right away. The word domain comes from the 2013 version of the standard. The 2022 revision completely reorganized Annex A and now talks about themes or categories instead of domains. Plenty of people still use the old term, so throughout this article you’ll see both structures and how they line up.

How Many Domains Does ISO 27001 Have?

The answer depends on which version of the standard you mean.

The 2013 ISO 27001 organized its 114 controls into 14 domains. The 2022 ISO 27001, which is the version in effect today, reorganizes its 93 controls into 4 themes. So when someone asks about the 14 domains, they mean the 2013 structure, and when they’re after the current breakdown, it’s 4 big blocks.

The 2013 ISO 27001 and Its 14 Domains

The 2013 version spread its 114 controls across 14 domains, each one focused on a specific aspect of information security. Here are the 14 domains.

  • Information security policies
  • Organization of information security
  • Human resource security
  • Asset management
  • Access control
  • Cryptography
  • Physical and environmental security
  • Operations security
  • Communications security
  • System acquisition, development and maintenance
  • Supplier relationships
  • Information security incident management
  • Business continuity
  • Compliance

Even though this structure isn’t the official one anymore, it’s still worth knowing. A lot of organizations certified before the transition still use it as a reference, and a good chunk of the documentation out there is built around it.

The 2022 ISO 27001 and Its 4 Themes

The 2022 version chases the same underlying goals, but it reshuffles the 93 controls into just 4 broader themes. Here they are.

  • Organizational controls (37 controls).
  • People controls (8 controls).
  • Physical controls (14 controls).
  • Technological controls (34 controls).

Further down, you’ll see in detail what each of these four themes covers and how they map onto the old domains.

The 4 ISO 27001 Control Themes in 2022

The 2022 version swaps the 14 domains for 4 themes that group the 93 controls in Annex A. Each theme pulls together the controls based on the type of resource or the role responsible. Add up the four blocks and you get the 93 controls in the current Annex A.

  • Organizational controls (37 controls): these are the controls tied to governance, policies, roles, and security planning. This is where things like security policies, risk management, supplier relationships, and incident response live. It’s the largest block, and it usually falls to leadership and department heads.
  • People controls (8 controls): these cover everything around the human factor, from hiring and training staff to each employee’s responsibilities when it comes to information security and remote work.
  • Physical controls (14 controls): these protect the facilities and the media where information is stored or processed. They include access control to the premises, equipment protection, and physical monitoring.
  • Technological controls (34 controls): these bundle the technical measures that protect systems, networks, and data, like encryption, logical access management, backups, web filtering, and secure development.

From 14 Domains to 4 Themes, What Changed in 2022?

The 2022 revision didn’t just rename the domains. It reorganized Annex A from the ground up, with three main changes.

  • From 114 to 93 controls: the total dropped because controls that overlapped or were redundant got merged. What used to be split across several similar controls was simply consolidated into one.
  • Eleven new controls: the standard added 11 controls that didn’t exist in 2013, built to address newer threats and technologies. They cover areas like threat intelligence, cloud services security, ICT readiness for continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
  • Attributes: the 2022 version tags each control so you can classify and filter them in different ways. For example, by control type, security properties, cybersecurity concept, operational capability, or security domain. This helps you fit the controls to your own organization’s context and connect them to other frameworks like NIST or SOC 2.

How Do You Implement the ISO 27001 Domains?

Rolling out the Annex A controls, the so-called domains or themes, follows a clear process that kicks off with risk analysis and doesn’t wrap up at certification. Here are the usual steps for putting them into practice.

1. Build your asset inventory and run a risk analysis

Before you touch a single control, your organization needs to know what it’s protecting and against what. The starting point is an inventory of information assets, meaning the data, systems, equipment, and services that keep the business running. From that inventory, you identify the threats each asset faces and the gaps between where you are and the security you already have in place.

This analysis is the foundation for everything else, because it determines which controls you actually need and in what order of priority. Skip it, and you run the risk of rolling out measures that add nothing while leaving important risks uncovered.

2. Select your controls and write the Statement of Applicability

Based on the risk analysis, your organization decides which Annex A controls it applies and which it leaves out, always with a written justification. That document is called the Statement of Applicability, better known as the SoA, and it’s one of the ones auditors dig into the most.

It’s worth remembering that the standard doesn’t require you to implement all 93 controls. You only apply the ones your risk level justifies, so a solid upfront analysis saves you unnecessary work and red tape down the line.

3. Roll out the measures, train your team, and document everything

Once you’ve picked your controls, it’s go time. You deploy the policies along with the technical and organizational measures, assign an owner to each control, and train the people involved, because plenty of controls only work if people build the right habits.

In parallel, everything gets documented. Every policy, procedure, and decision has to leave a paper trail, since in an audit anything that isn’t documented might as well not exist. Keeping that documentation organized and easy to find is one of the spots where organizations get stuck the most.

This is where an IT management and compliance tool like Factorial IT earns its keep, especially for SMBs without a dedicated security team. Centralizing your asset inventory, your devices and access, and your ISMS documentation in one place cuts out the scattered spreadsheets and lets you walk into the audit with everything current and easy to track down.

4. Audit and improve continuously

Finally, you run periodic internal audits to check the controls are working the way they should, and you fix whatever needs fixing. ISO 27001 runs on continuous improvement, so this cycle of reviewing, adjusting, and measuring again doesn’t end at certification. It repeats over time to keep up with new risks and changes in your organization.