Skip to content

Statement of Applicability (SoA)

Definition

A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification for each decision, and, for included controls, a reference to implementation evidence. The SoA is the primary audit reference for control coverage.

Standard
ISO/IEC 27001 Annex A
Content
Inclusion or exclusion decision per control with justification
Role
Primary audit reference for control coverage
Required for
ISO/IEC 27001 certification
Linked to
Risk treatment plan and risk register

Common questions

Can an organisation exclude a control simply because it is inconvenient?+

No, exclusion must be justified with a documented rationale, typically that the control is not applicable to the organisation's risk environment or scope. Auditors scrutinise exclusions and will challenge weak or unsupported justifications during certification review.

How does the SoA relate to the risk register?+

Controls are selected in response to risks identified in the risk assessment and recorded in the risk register, so the SoA should trace each included control back to a specific risk treatment decision rather than being drafted independently.

Who typically owns and maintains the Statement of Applicability?+

The information security management system owner or a designated ISMS manager maintains it, updating it whenever the risk assessment, scope, or control implementation changes, since it must stay current for ongoing certification audits.

Related terms

Annex a
The normative annex to ISO/IEC 27001 that lists 93 information security controls across four themes: organisational (37 controls), people (8), physical (14),...
Risk Owner
The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
Continual Improvement
The ISO/IEC 27001 requirement (clause 10) that the organisation must actively improve the suitability, adequacy, and effectiveness of the ISMS over time....
High-Level Structure (HLS)
The common clause framework mandated by ISO for all management system standards. Clauses 4 through 10 of ISO 27001 follow the same...
Information Security Management System (ISMS)
The set of policies, processes, procedures, and controls that an organisation establishes to manage information security risk. ISO 27001 specifies the requirements...
ISMS Scope
The explicit boundaries of the management system: which organisational units, sites, processes, and information assets are covered. Defined under ISO/IEC 27001 clause...
ISO/IEC 27002
A guidance standard (not certifiable) that provides implementation advice for each of the 93 controls in ISO 27001 Annex A. Updated in...
Management Review
The annual governance meeting required under ISO 17025 Clause 8.9, at which laboratory management reviews the aggregated quality performance data (PT results,...
Residual Risk
The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management...
Risk Appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
Risk Register
A structured record of all identified risks, each with its description, inherent risk score, owner, treatment decision, controls selected, residual risk score,...
Risk Treatment
The process of selecting and implementing options to modify risk. ISO/IEC 27005 defines four treatment options: accept, avoid, mitigate (reduce), and transfer...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.