This section should have a reference to ISO 27001 chapter 6: planning.
There is a spotring rteklation with the Statemnet op Apllicability, and the risk based selection of controls. You can use ISO 27002 and her chapters for grouping controls or you can use other grouopings that are more adapted to your business processes.