Terminology Index

Glossary

2953 terms

Open concept maps
S
32

Statement of Applicability

A core ISO 27001 document listing which controls from the standard apply, which don't, and why, the bridge between risk assessment and selected controls in the ISMS.

The Statement of Applicability (SoA) is a defining ISO 27001 artifact: a structured list of every Annex A (or current control set) control, marked applicable or not, with justification, status, and references to implementation. Auditors read it as a tour of the ISMS's control posture. Building and maintaining it is one of the GRC-analyst's central ISO tasks. As a frameworks-and-mapping topic, the SoA exemplifies how a framework formalizes the link between risks and chosen controls.

Introduced in: Security Frameworks and Control Mapping

Examples

  • Listing every Annex A control as applicable or not in the SoA.
  • Providing justification and status for each control in the SoA.
  • Walking an ISO auditor through the SoA as a tour of the ISMS.