ISO/IEC 27001:2022 defines four types of controls in Annex A: organizational, people, physical, and technological controls. These control types structure the requirements of an Information Security Management System.