How do I select Annex A controls?
The controls in Annex A provide a basis for an effective ISMS, but you shouldn’t treat them as gospel.
You select information security controls based on your risk assessment. Then, you compare them against Annex A to ensure you’ve covered all your risks.
You may exclude Annex A controls that don’t apply to your organisation. However, you must justify any exclusions in your SoA (Statement of Applicability).
What is the Statement of Applicability in ISO 27001?
The SoA is one of the most important documents in your ISMS.
It lists all Annex A controls, together with:
- Justifications for their inclusion or exclusion; and
- Their implementation status.
If you use controls from other frameworks and/or develop additional controls, you must also list those on your SoA.
The SoA will be a key focus during certification and surveillance audits by your chosen certification body.
The SoA must contain a huge amount of information. It must also be accessible. Many organisations use spreadsheet software, but there’s nothing preventing you from exploring alternative software.
The SoA is one of the most important, comprehensive documents in your ISMS, which you must carefully maintain. You should treat it as documented information, so use version control and review it at regular intervals.
What is the difference between ISO 27002 and Annex A?
ISO 27002 assists with effective ISO 27001 implementation – including Annex A – as it describes each control in more detail. This helps organisations better understand the purpose of the controls and how to implement them.
However, organisations can’t achieve certification against ISO 27002, only ISO 27001. Nevertheless, ISO 27002 is an essential companion to any organisation implementing an ISO 27001 ISMS.
Need help implementing ISO 27001?
We’ve been implementing information security management systems for over 20 years. If you need support with any aspect of your ISO 27001 compliance programme – from an initial gap analysis to ongoing ISMS maintenance and everything in between – we have everything to help you.