ISO/IEC 27001 is the leading international standard for building and certifying an Information Security Management System (ISMS) — a risk-based program for managing information security, not just a checklist of technical controls.
The current (2022) revision organizes its Annex A controls into four themes — organizational, people, physical, and technological — covering 93 controls in total. Certification is issued by an accredited certification body after a two-stage audit, and is maintained through annual surveillance audits across a three-year certification cycle.
Annex A controls
ISO/IEC
ISO/IEC 27001:2022, Annex A