The right question when starting an ISO 27001 implementation is not «which control comes next?» but «which control removes the most risk per hour invested?». That distinction usually decides whether the management system takes hold or ends up as a folder of documents nobody opens.
The reason is practical. The first months determine whether the board keeps funding the programme. A control that cuts risk visibly and leaves clean evidence for the auditor buys you room for everything else; one that burns three weeks of meetings with no perceptible effect spends that room instead.
At a glance
- Annex A is a catalogue you select from on the basis of risk, not a checklist to be completed end to end.
- Four controls account for most of the early risk reduction: access control, asset inventory, verified backups and prioritised patching.
- The test is not only how much risk a control removes but what evidence it leaves behind: what cannot be demonstrated does not count at audit.
Annex A is not a to-do list
It helps to clear up a common misunderstanding first. The 2022 edition of ISO/IEC 27001 reorganised Annex A into 93 controls across four themes: 37 organisational, 8 people, 14 physical and 34 technological. The previous 2013 edition listed 114 controls across 14 domains, and the reduction reflects consolidation rather than any softening of requirements.
What matters for anyone starting out is that those 93 controls are not a syllabus to be covered in full. The standard requires you to select applicable controls from your risk assessment and to justify, in the statement of applicability, both what you include and what you leave out. Your risk sets the order, not the numbering of the annex.
With that settled, the operational question becomes manageable. Of the 93, which ones pay back first?
1. Access control: MFA and least privilege
This is the one that delivers most in the least time. Turning on phishing-resistant multi-factor authentication and applying least privilege cuts off the use of stolen credentials and limits how far an intruder can travel once inside.
Start where it hurts most: administrative accounts, remote access, email and the applications the business actually runs on. You do not need to cover the whole organisation in the first month to feel the effect.
The evidence it produces is among the cleanest you will get: MFA coverage reports, permission reviews with a date and an owner, and joiner-mover-leaver records. An auditor can verify it in minutes.
The usual mistake is rolling out MFA and considering the job done, leaving service accounts and supplier access outside the scope — precisely the ones nobody reviews.
2. Asset inventory and information classification
You cannot protect — or scope a management system around — what you do not know exists. A minimum viable inventory covering endpoints, cloud services, sensitive data and a named owner for each underpins nearly every other control.
It pays back early because it prevents wasted work. Without it, organisations end up applying expensive controls to irrelevant assets while something critical stays uncovered. At audit, the inventory is the first thing requested to check that the declared scope matches reality.
The usual mistake is chasing a perfect inventory. An incomplete one that is current and has owners beats an exhaustive spreadsheet from eight months ago.
3. Verified backups and a restore plan
The value is not in having backups but in restoring quickly when something breaks. Immutable isolated backups, with recovery time and recovery point objectives agreed with the business and proven through a real restore drill, are the control that most often decides whether an incident is an inconvenience or a crisis.
This is where the word «evidence» becomes literal. «We have backups» is not evidence. A record of a tested restore, with date, scope and elapsed time, is.
The usual mistake is restoring a single file and extrapolating. Recovering a document does not demonstrate that you can bring a whole service back.
4. Risk-based vulnerability management
The fourth control has gained weight because of a real shift in how attackers get in. For years stolen credentials were the most common initial access vector; according to Verizon's Data Breach Investigations Report for 2026, vulnerability exploitation has overtaken them for the first time, with edge devices and VPNs driving the change.
The practical consequence is that patching in CVSS order is no longer enough. Prioritise by real exploitation and exposure: what is reachable from outside, what is genuinely being exploited, and what supports a critical process. It is the approach we set out in how to prioritise exploitable vulnerabilities with KEV, EPSS and SSVC, and it sits naturally inside a continuous vulnerability management programme.
Round it off with patch management on agreed windows and with the removal of unsupported software, usually the cheapest debt to clear and the one that looks worst in an audit.
What can wait
Knowing what to postpone matters as much as knowing where to begin. Lengthy policies written before there are controls to back them up age badly and have to be rewritten. Exhaustive document classification, with no inventory in place, is a theoretical exercise. And sophisticated maturity metrics, with no data to feed them, consume time that would pay back far better in any of the four controls above.
None of this is wasted in a mature management system. It simply is not where you start.
Sequencing the rest
With those four running you have cut real risk and generated early evidence, which is exactly what you need for the board to back the rest of the journey. From there the natural order tends to be incident response, awareness and supplier management, because all three build on what you have already put in place.
If you want the full route mapped out, we set it out in the ISO 27001 implementation process, and to find the next gaps it helps to run through an IT security audit checklist.
ISO 27001 works best when the implementation sequence follows real risk rather than the numbering of the annex. The four controls above are not the whole standard and do not pretend to be, but they are what gives the rest a chance of succeeding. If you want help sequencing an implementation, you can see how we approach ISO 27001 certification.