Ask anyone who's been through ISO 27001 certification what confused them most early on, and there's a good chance they'll mention Annex A. It's often misunderstood as a mandatory checklist, when it's actually something closer to a menu, built to be applied selectively based on your organization's actual risk.