Can I use Annex A as an information security controls checklist?

Many organisations use the controls listed in Annex A as a menu or checklist of best practice controls to be implemented in order to provide a level of information security.  

However, URM recommends that your risk assessment is used to determine which controls are relevant, as some of them may not be applicable to your organisation.  

We would also recommend that you don’t use Annex A in isolation as ISO 27002 provides very good additional guidance on how controls should be implemented.  

It should also be noted that following your risk assessment, you may identify risks that cannon be adequately mitigated using the supplied controls.  The standard provides the flexibility to permit the creation or introduction of additional controls from other sources which you may wish to implement to address unique risks.

The webinar 'was very engaging and informative - thank you!
Contact the ISO 27001 Experts Today

ISO 27001 Clause 4.2, Understanding the Needs and Expectations of Interested Parties

Published on
2 Oct
2026

URM's blog examines ISO 27001:2022 Clause 4.2, covering interested parties, their requirements and how these are addressed through the ISMS.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
22/9/2026
What Are the Critical Steps When Implementing an Effective Information Security Management System?

URM assisted over 500 organisations achieve ISO 27001 certification, here are the critical steps when implementing an effective information security system.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
22/9/2026
ISO 27001 Clause 4.1 - Understanding the Organisation and its Context

URM's blog explores ISO 27001 Clause 4.1 & how to identify organisational context, assess internal/external issues, and support effective ISMS decision-making.

Read more
Thumbnail of the Blog Illustration
Internal Audit
Published on
20/9/2026
Internal Auditing of Management Systems

URM’s blog explains how to plan and execute effective and conformant internal audits of management systems at each stage of the internal audit process.

Read more
"
I am pleased to recognise the work of the URM internal auditor we have worked. Throughout all the audits carried out, he has consistently demonstrated professionalism, diligence, and a commitment to excellence in every task undertaken. Thanks to his efforts, we have achieved a very successful first stage ISO 27001:2022 certification audit, with zero findings noted, which has positioned us on track for the second stage audit and for long-term success.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.