Annex A sits at the back of the ISO 27001 standard as a reference set — the controls its authors expect most organizations to at least consider. The 2022 revision reorganized it into 93 controls across four themes: organizational (policies, supplier management, incident handling), people (screening, training, disciplinary process), physical (facilities, equipment, media), and technological (access control, logging, encryption, secure development). Treating the catalog as a to-do list is the classic beginner mistake; it’s a menu your risk assessment orders from.
Selection runs through risk treatment. You identify risks to the information your ISMS protects, choose how to treat each one, and map those treatments to Annex A controls — adding controls from other sources when the catalog doesn’t cover a risk. Every control then lands in the Statement of Applicability as applicable or excluded, with a justification. Auditors read exclusions skeptically, so “not relevant to how we operate” needs to be demonstrably true.
Annex A names each control in a sentence or two; the how-to detail lives in ISO 27002, the companion standard that expands every control with implementation guidance. Startups pursuing certification usually find the hard part isn’t understanding the catalog — it’s standing up the operating routines behind each applicable control. That build, from first risk assessment to certificate, is what ISO 27001 for startups walks through.