ISMS.1 Statement of Applicability (SoA)

Version: April 2025
Aligned with: ISO/IEC 27001:2022 (Clause 6.1.3, Annex A)
Applies to: ISMS scope, all applicable ISO 27001 Annex A controls

Purpose
To document the applicability of ISO 27001 Annex A controls, providing justification for inclusion or exclusion based on organizational risk assessment.

1. Statement of Applicability
(Aligned with Clause 6.1.3 – Information security risk treatment)

  • Defines which security controls from ISO 27001 Annex A are applicable to the organization
  • Provides justification for inclusion or exclusion of controls
  • Links controls to identified risks and business requirements
  • Serves as the foundation for the security control implementation plan

2. Control Selection Criteria

  • Risk assessment results and treatment decisions
  • Legal, regulatory, and contractual requirements
  • Business and operational requirements
  • Cost-benefit analysis of control implementation
Direct URL: