ISO 27001 Annex A: technological controls (A.8)
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
A.8 is where the engineering lives: access, crypto, logging, secure development, and network security. It overlaps almost entirely with SOC 2's technical controls.
The technical core
The technological theme (A.8) is the largest source of hands-on engineering work in Annex A: identity and access management, privileged access, authentication, cryptography and key management, logging and monitoring, malware protection, vulnerability management, secure development, and network security controls.
Heavy overlap with other frameworks
Almost everything in A.8 also appears in the SOC 2 Common Criteria and much of it in PCI DSS — MFA, least privilege, encryption, logging, change management, secure SDLC. If you have done (or are doing) SOC 2, you have most of A.8 already; the work is mapping it to the Annex A controls.
Where teams focus
Secure development (code review, dependency and vulnerability management, separation of environments) and access control are usually the biggest lifts, followed by logging/monitoring maturity. These are also where buyers and auditors probe hardest, so they are worth getting genuinely right rather than papering over.
Evidence is configuration
A.8 is evidenced through technical artifacts: access review records, encryption and TLS configuration, log coverage and alerts, change/PR history, and scan/test results. SentinelPanda maps these controls to that evidence and to their SOC 2 and PCI equivalents, so one implementation satisfies all three.