Statement of Applicability (SoA)
Definition
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification for each decision, and, for included controls, a reference to implementation evidence. The SoA is the primary audit reference for control coverage.
- Standard
- ISO/IEC 27001 Annex A
- Content
- Inclusion or exclusion decision per control with justification
- Role
- Primary audit reference for control coverage
- Required for
- ISO/IEC 27001 certification
- Linked to
- Risk treatment plan and risk register
Common questions
Can an organisation exclude a control simply because it is inconvenient?+
No, exclusion must be justified with a documented rationale, typically that the control is not applicable to the organisation's risk environment or scope. Auditors scrutinise exclusions and will challenge weak or unsupported justifications during certification review.
How does the SoA relate to the risk register?+
Controls are selected in response to risks identified in the risk assessment and recorded in the risk register, so the SoA should trace each included control back to a specific risk treatment decision rather than being drafted independently.
Who typically owns and maintains the Statement of Applicability?+
The information security management system owner or a designated ISMS manager maintains it, updating it whenever the risk assessment, scope, or control implementation changes, since it must stay current for ongoing certification audits.
Related terms
- Annex a
- The normative annex to ISO/IEC 27001 that lists 93 information security controls across four themes: organisational (37 controls), people (8), physical (14),...
- Risk Owner
- The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
- Continual Improvement
- The ISO/IEC 27001 requirement (clause 10) that the organisation must actively improve the suitability, adequacy, and effectiveness of the ISMS over time....
- High-Level Structure (HLS)
- The common clause framework mandated by ISO for all management system standards. Clauses 4 through 10 of ISO 27001 follow the same...
- Information Security Management System (ISMS)
- The set of policies, processes, procedures, and controls that an organisation establishes to manage information security risk. ISO 27001 specifies the requirements...
- ISMS Scope
- The explicit boundaries of the management system: which organisational units, sites, processes, and information assets are covered. Defined under ISO/IEC 27001 clause...
- ISO/IEC 27002
- A guidance standard (not certifiable) that provides implementation advice for each of the 93 controls in ISO 27001 Annex A. Updated in...
- Management Review
- The annual governance meeting required under ISO 17025 Clause 8.9, at which laboratory management reviews the aggregated quality performance data (PT results,...
- Residual Risk
- The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Risk Register
- A structured record of all identified risks, each with its description, inherent risk score, owner, treatment decision, controls selected, residual risk score,...
- Risk Treatment
- The process of selecting and implementing options to modify risk. ISO/IEC 27005 defines four treatment options: accept, avoid, mitigate (reduce), and transfer...
Explained in these topics
- Designing and Implementing an ISMS
- ISO/IEC 27001: Standard Structure and RequirementsA mandatory document required by Clause 6.1.3 that lists all 93 Annex A controls, states which are applicable, justifies any that are excluded, and references...
- Risk Treatment and the Risk RegisterA document required by ISO/IEC 27001 that lists all controls from Annex A, records whether each is applicable to the organisation, and references the treatment...