Regulatory & compliance⏱ ~1 minNOSEDKFIEU

SoA

The document listing which of ISO 27001's security controls an organisation actually applies - and justifying every one that has been excluded.

The SoA (Statement of Applicability) is a mandatory document under ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. - the standard requires it explicitly as part of risk treatment. ISO/IEC 27001The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used.:2022 defines 93 security controls in Annex A across four themes: organisational, people, physical and technological. The SoA walks through all 93 and answers three questions for each: is it applied, why, and if not - why not. The point is that exclusions must be justified. An organisation may leave out controls for physical access to its own data centres if it operates none, but it cannot silently skip the control. This makes the SoA the single most informative document in a certified management system: the certificate says an organisation is certified, the SoA says exactly what the certification covers.

SecurityDocumentation