A frequent question from organisations implementing or maintaining ๐๐ฆ๐ข ๐ฎ๐ณ๐ฌ๐ฌ๐ญ:๐ฎ๐ฌ๐ฎ๐ฎ is:
โDo we really need to implement all 93 Annex A controls?โ
๐ง๐ต๐ฒ ๐ฎ๐ป๐๐๐ฒ๐ฟ ๐ถ๐ ๐ป๐ผ.
Annex A is not a mandatory checklist โ itโs a comprehensive catalogue of controls designed to help you treat your specific information security risks. The standard requires you to select only the controls that are relevant to your organisation and to clearly justify every decision (both inclusions and exclusions) in your ๐ฆ๐๐ฎ๐๐ฒ๐บ๐ฒ๐ป๐ ๐ผ๐ณ ๐๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ (๐ฆ๐ผ๐).
From our experience, auditors usually pay close attention to the quality of your justifications rather than the sheer number of controls you apply. Remember, you may also include controls to satisfy contractual obligations or regulatory requirements, even if the associated risk is relatively low.
Hereโs a ๐ฝ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐ฑ-๐๐๐ฒ๐ฝ ๐ฎ๐ฝ๐ฝ๐ฟ๐ผ๐ฎ๐ฐ๐ต to do it effectively:
โ
๐๐ฒ๐ณ๐ถ๐ป๐ฒ ๐๐ผ๐๐ฟ ๐๐ฆ๐ ๐ฆ ๐ฆ๐ฐ๐ผ๐ฝ๐ฒ (๐๐น๐ฎ๐๐๐ฒ ๐ฐ.๐ฏ)
Clearly identify the processes, assets, locations, and third parties covered by your Information Security Management System.
โ
๐ฃ๐ฒ๐ฟ๐ณ๐ผ๐ฟ๐บ ๐ฎ ๐๐ผ๐น๐ถ๐ฑ ๐ฟ๐ถ๐๐ธ ๐ฎ๐๐๐ฒ๐๐๐บ๐ฒ๐ป๐ (๐๐น๐ฎ๐๐๐ฒ ๐ฒ.๐ญ.๐ฎ)
Identify realistic threats and vulnerabilities that could impact the confidentiality, integrity, and availability of your information.
โ
๐๐ฟ๐ฒ๐ฎ๐๐ฒ ๐ฎ ๐ฅ๐ถ๐๐ธ ๐ง๐ฟ๐ฒ๐ฎ๐๐บ๐ฒ๐ป๐ ๐ฃ๐น๐ฎ๐ป (๐๐น๐ฎ๐๐๐ฒ ๐ฒ.๐ญ.๐ฏ)
For each risk, decide how to treat it: mitigate with controls, avoid, transfer, or accept with proper justification and management approval.
โ
๐ ๐ฎ๐ฝ ๐ฟ๐ถ๐๐ธ๐ ๐๐ผ ๐๐ป๐ป๐ฒ๐
๐ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐
The 93 controls are grouped into four themes: Organisational (37), People (8), Physical (14), and Technological (34). Choose controls that directly address your identified risks.
โ
๐๐ผ๐ฐ๐๐บ๐ฒ๐ป๐ ๐ฒ๐๐ฒ๐ฟ๐๐๐ต๐ถ๐ป๐ด ๐ถ๐ป ๐๐ต๐ฒ ๐ฆ๐ผ๐
This mandatory document lists all 93 controls. For each one, clearly state whether it is applicable, provide a risk-based justification, and describe how it is implemented (or why it is excluded).
Trying to implement every control does not automatically make the ISMS stronger.
What matters more is whether the controls make sense for the organisation and are implemented properly.