What is the Statement of Applicability?
An organization’s Statement of Applicability benchmarks against ISO 27001’s full Annex A control set and includes justification for inclusion or exclusion of each control as part of the organization’s ISMS implementation. In addition, the SoA links an organization’s risk assessment with its risk treatment plan.
The Statement of Applicability is one of the first documents an auditor will review as part of the ISO 27001 audit process. The SoA helps the auditor understand the organization and what controls have been implemented and assessed as part of that organization’s audit.