A baseline is a minimum set of security controls that an organisation has decided to implement as a standard practice across its systems or for a specific type of asset. While ISO 27001 is a risk-based standard, meaning you choose controls based on your specific risks, the controls listed in Annex A are often considered a baseline set of best practices to consider.
Key Characteristics
- Starting Point: It acts as a foundation. Organisations can start by implementing the Annex A controls and then add or remove controls based on their specific risk assessment.
- Consistency: A baseline ensures a consistent, minimum level of security across all systems, preventing security gaps that might otherwise be overlooked.
- Measurability: It provides a defined standard to measure against, making audits and security reviews more straightforward.
ISO 27001 Context
The ISO 27001 standard requires you to conduct a risk assessment to determine which controls from Annex A are applicable. Your Statement of Applicability (SoA) is where you justify the inclusion or exclusion of these controls, but Annex A still serves as the authoritative baseline for that selection process.