“The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.”ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, Introducere, 0.1 «General»
Annex A is the consequence of the risk assessment, not the starting point of the implementation.
An ISMS — information security management system — is not a list of controls but the machinery that decides which controls are needed, puts them to work and checks whether they still fit. The standard says so directly in its introduction: the system preserves the confidentiality, integrity and availability of information by applying a risk management process. The Annex A controls, 93 of them, grouped in the 2022 edition into four themes — organisational, people, physical, technological — are the consequence of the risk assessment, not the starting point. The auditable requirements are clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, improvement. That structure is shared by every management system standard written since 2012, which has a practical upshot: ISO 9001, ISO 22301 or ISO/IEC 42001 for artificial intelligence use the same framing clauses. An organisation already running one of them adds the second scheme without rebuilding its policy, internal audit or management review.
Why it matters Whoever starts with Annex A builds a task list; whoever starts with clauses 4 to 10 builds the system the certification body will audit.