22/04/2026
👥 The smallest control group in ISO 27001:2022 Annex A – Eight Controls.
(Also, the one that causes the most real‑world breaches)
Annex A, section 6 (People Controls), is easy to underestimate because it doesn’t involve technology. No platforms or tools to configure, no system to audit. Just people and the processes built around them. We’ll explain three of them for you.
People Controls – A6.1 / A6.3 / A6.7.
👉 These controls focus on how risk is introduced or reduced through people.
📋 Screening asks whether background checks are proportionate to the role, recognising that access to sensitive data or system administration carries a different risk profile than a back‑office position.
🧑🏫 Training and awareness focus on the most common attack vector, moving beyond annual tick-the-box training to evidence-based activities like phishing simulations, role-specific training records, and awareness aligned to current threats.
💻 Remote working addresses how information is protected when staff work offsite, including conditional access, MFA by default, managed devices, and secure data transmission — and importantly, being able to prove these controls work, not just document them.
If your people controls are an afterthought in your ISMS build, they won’t be an afterthought in your audit. FCG helps businesses build ISO 27001 systems that reduce regulatory risks and enhance brand trust.