Source: https://en.wikipedia.org/wiki/ISO/IEC_27002
ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and by the International Electrotechnical Commission (IEC), titled Information security, cybersecurity and privacy protection — Information security controls.
Because every organisation is unique, implementing an ISMS must be a purpose fitting whole. This means that choices may be made regarding the control measures to be taken. ISO 27002 offers a total range of measures. Based on your considerations, you can demonstrate why you do not implement certain measures from that total range, equally you can also implement measures that are not named under ISO 27002.
In fact, this is a risk analysis and consideration.
TrustMatters can support you in this.