TL;DR: ISO 27001 Annex A translates information-security intent into 93 controls across governance, people, physical and technology domains, but the article shows implementation still depends on risk assessment, access control, monitoring and audit discipline according to Zluri. For IAM teams, the real test is whether certification work becomes living identity governance rather than a document-led compliance exercise.
At a glance
What this is: This is an analysis of ISO 27001 Annex A that argues the standard’s control model only works when identity governance, access control, monitoring, and certification evidence are operational rather than paper-based.
Why it matters: It matters because IAM, PAM, and NHI teams are often the ones turning ISO 27001 intent into day-to-day control evidence, especially where access reviews, least privilege, and offboarding determine whether the ISMS is credible.
Context
ISO 27001 is a control framework for building and maintaining an information security management system, but its value depends on whether organisations can prove that the controls actually operate as intended. In practice, that moves the burden from policy language to evidence, especially in access control, monitoring, incident handling, and audit readiness.
For identity programmes, the important question is not whether Annex A mentions access management. It is whether joiner-mover-leaver discipline, privileged access control, and review evidence are strong enough to survive an external certification audit and a real incident at the same time.
Key questions
Q: What breaks when ISO 27001 access controls exist on paper but not in daily operations?
A: The ISMS becomes difficult to defend because auditors test effectiveness, not intent. If certificate revocation, access reviews, or role ownership are inconsistent, the organisation cannot prove that selected controls are operating as planned. That gap usually appears first in Clause 8 and Clause 9 evidence, then spreads into corrective action and certification risk.
Q: Why do ISO 27001 controls force identity teams to care about audit evidence?
A: Because the standard is validated through implementation, not declaration. If access reviews, logging, or incident handling cannot produce traceable records, the organisation cannot show that its control set matches the risk treatment plan. That makes evidence part of the control itself, especially for IAM and NHI workflows.
Q: What do organisations get wrong about ISO 27001 and identity governance?
A: They often treat ISO 27001 as a documentation exercise instead of an operational control system. The standard expects the organisation to define scope, assess risk, review access, and correct nonconformities in a repeatable loop. If the loop is weak, the certificate may exist while the control is failing.
Q: How should teams align ISO 27001 with human and non-human access processes?
A: Treat both as governed identity lifecycles with the same evidence expectations. Human users, contractors, service accounts, and applications all need approval records, review cadence, and revocation proof if they are part of the certified ISMS. The exact workflow may differ, but the accountability model should not.
Technical breakdown
Why ISO 27001 depends on evidence, not declarations
ISO 27001 Annex A is structured around controls, but certification depends on more than writing those controls down. Auditors expect the organisation to show that the chosen controls match its risk assessment, that the Statement of Applicability is consistent with actual practice, and that implementation is traceable in operations. That means the standard tests whether security governance is repeatable, not just documented. In identity terms, access approval, review, deprovisioning, and monitoring all have to produce artefacts that survive audit scrutiny. Without that evidence chain, an ISMS can look complete on paper while remaining weak in practice.
Practical implication: tie identity controls to auditable records, not just policy statements.
Access control under ISO 27001 is a governance problem
The article places access control at the centre of ISO 27001 implementation because least privilege, provisioning, deprovisioning, and monitoring all sit inside a governance loop. The challenge is not simply preventing unauthorised access. It is proving that access is granted for a reason, limited to the required scope, and removed when no longer needed. That is why Annex A matters to IAM and NHI programmes alike: the same governance logic applies to employees, contractors, service accounts, and other non-human identities. The control family becomes effective only when lifecycle events and entitlement changes are tracked as business decisions, not ad hoc technical actions.
Practical implication: make access decisions lifecycle-driven so they can be justified during certification and audit.
What changes when continuous monitoring is part of the ISMS
ISO 27001 does not treat monitoring as a side activity. Operational security, incident response, and compliance all depend on the organisation being able to detect suspicious activity, investigate it, and show corrective action. For identity teams, that means logs, access reviews, certification reports, and anomaly handling become part of the ISMS control fabric. The standard’s logic is straightforward: if a control cannot be monitored, it cannot be trusted. This is where many programmes underperform, because they separate governance from telemetry. In reality, the ISMS needs both the decision record and the operational signal.
Practical implication: connect review, logging, and response workflows so control effectiveness can be demonstrated continuously.
NHI Mgmt Group analysis
ISO 27001 exposes the identity governance gap because certification depends on lived control behaviour, not control intent. The article makes clear that Annex A is a control framework, but control existence is not control operation. In identity programmes, that means access governance, review cadence, and offboarding discipline have to produce evidence that auditors can test. The practitioner conclusion is that certification readiness rises or falls on operational proof.
Access control is the point where ISO 27001 becomes an identity programme test. The standard’s access, monitoring, and compliance expectations all depend on whether the organisation can show who has access, why they have it, and when it was removed. That is true for employees, contractors, and non-human identities alike. The practitioner conclusion is that identity lifecycle governance is the control layer that makes Annex A credible.
Continuous evidence, not periodic paperwork, is the real control model here. The article’s emphasis on audit, risk assessment, and implementation demonstrates that governance must be observable over time. A recertification packet that cannot be tied back to provisioning, review, and revocation processes is weak evidence, even if the policy language is strong. The practitioner conclusion is that the ISMS should be built to prove control operation as a normal output of identity processes.
Named concept: identity governance evidence gap. ISO 27001 programmes often fail when the documented control set is stronger than the operational proof behind it. That gap is especially visible in access control, where certification requires repeatable evidence of approval, review, and removal. The practitioner conclusion is that identity teams should treat evidence generation as part of the control, not as an afterthought.
ISO 27001 also aligns NHI governance with human IAM under one audit model. The article’s structure shows that access control, monitoring, and compliance do not stop at human identities. Service accounts and other non-human identities create the same audit expectations, but often with weaker ownership and poorer lifecycle discipline. The practitioner conclusion is that governance teams should review NHI evidence with the same seriousness as human access evidence.
What this signals
Identity governance evidence gap: ISO 27001 programmes often look complete in documentation while remaining fragile in operation. The practical test is whether access changes, reviews, and removals generate artefacts that an auditor or incident responder can trust.
When IAM and NHI teams share the same control model, ISO 27001 stops being a compliance wrapper and becomes an operating discipline. That shifts attention to lifecycle ownership, review frequency, and proof of revocation rather than to policy templates alone.
For practitioners
- Map Annex A controls to identity evidence Translate access control, monitoring, and incident response requirements into evidence-producing IAM and NHI workflows so each control can be audited end to end.
- Make the Statement of Applicability operational Use the Statement of Applicability to tie each selected control to a named process owner, a measurable control activity, and a retrievable artefact.
- Build review and revocation into lifecycle governance Ensure joiner-mover-leaver processes cover user, contractor, and service-account access so removals and privilege changes are evidenced, not assumed.
- Test controls the way an auditor will Run internal checks against access approvals, periodic reviews, logging, and corrective actions to see whether the control can survive certification scrutiny.
Key takeaways
- ISO 27001 is only as strong as the evidence behind it, because documented controls that cannot be demonstrated in practice do not hold up under audit.
- Access control is the most identity-relevant part of the standard, and it depends on provisioning, review, and deprovisioning working as one lifecycle.
- For IAM and NHI teams, the real task is to make certification evidence a normal output of operations, not a separate compliance exercise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access Control | The article centres on access governance as a core ISO 27001 control area. |
| A.5.35 — Independent Review of Information Security | The article stresses certification, audit review, and proof of control operation. | |
| A.5.37 — Documented Operating Procedures | The article repeatedly contrasts documented intent with operational proof. | |
| Recommendation — Map access provisioning, review, and revocation to A.5.15 and retain evidence for audit. Use A.5.35 to test whether implemented controls can be independently verified in practice. Maintain operating procedures that show how identity controls are actually executed and evidenced. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Access rights, entitlements, and authorization evidence are central to the article's governance gap. |
| DE.CM-01 — Networks and systems are monitored to detect cybersecurity events | The article links control credibility to monitoring and ongoing operational verification. | |
| Recommendation — Apply PR.AA-05 to govern entitlement reviews and document every access decision. Use DE.CM-01 to ensure identity activity is monitored and reviewable for anomalies. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article's access, deprovisioning, and lifecycle emphasis maps cleanly to account governance. |
| Recommendation — Treat CIS-5 as the account lifecycle baseline for provisioning, review, and removal. | ||
Key terms
- Statement of Applicability: A Statement of Applicability lists the security controls an organisation has selected, excluded, or adapted for its ISMS. It matters because it forces explicit justification, which makes audit discussions easier and exposes weak control decisions that were previously implied or undocumented.
- Information Security Management System: An information security management system is the operating structure an organisation uses to manage security policies, controls, responsibilities, and evidence. Under ISO 27001, it is the framework auditors assess, but its real strength depends on whether access, logging, and remediation work consistently in practice.
- Access Controls: Access controls are the rules that limit who can see or use data and systems. They may use roles, attributes, authentication strength, and policy checks to reduce exposure. In DLP programmes, access controls help ensure sensitive content is only available to approved users and processes.
- Annex A: Annex A is the control catalogue associated with ISO 27001. It provides the recommended control set organisations can use to support their ISMS, along with the requirement to justify whether each control is applied, excluded, or out of scope.
Deepen your knowledge
Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org