Annex A of ISO/IEC 27001:2022 lists 93 controls grouped into four themes. In the risk treatment process, what is the correct status of Annex A?
- A.A mandatory list from which all controls must be implemented. Clause 6.1.3 treats this as a nonconformity finding during the initial certification audit rather than as routine ISMS operation.
- B.A reference set of controls used to check that no necessary control has been omitted
- C.A replacement for the risk assessment
- D.A prohibited list that organizations may not consult
Why B is correct
Annex A serves as a reference catalogue. Organizations determine necessary controls from the risk treatment and then compare against Annex A to ensure completeness; not every Annex A control must be implemented.
Know someone studying for ISO 27001? Send them this one.