Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideSet Annex A control applicability, record justification and link policies, risk assessments and evidence to demonstrate implementation.
The Statement of Applicability records which ISO 27001 Annex A controls apply, why they apply or do not apply, their implementation status and the evidence that supports the organisation's position.
Open the Statement of Applicability and review each Annex A control. Mark the control Applicable or Not Applicable, then set the implementation status such as Not Started or In Progress.
Select approved policies or completed risk assessments that demonstrate how the organisation addresses the control. This creates traceability across Document, Risk and Compliance Management.
Check totals for applicable, not applicable, in-progress and not-started controls. Review controls with no evidence or incomplete justification and assign the work to an accountable owner.
Provide a meaningful justification before saving.
Confirm that the policy has completed the required approval or publication state and that you can access it.