Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideSet Annex A applicability and implementation status, record justification and link Policies, Risks and evidence to the organisation's compliance position.
The Statement of Applicability records which ISO 27001 Annex A Controls apply to the ISMS, why they apply or do not apply, their implementation status and the supporting governance context.
Open the Statement of Applicability and review each Annex A Control. Mark it Applicable or Not Applicable, record the justification and maintain the implementation status such as Not Started, Planned, In Progress or Implemented.
Use explicit links to show the governance context behind the SoA position.
These relationships improve traceability; they do not automatically change the SoA implementation status.
Review applicable and not-applicable totals, implementation status, owners, target dates, missing justification and supporting links. Use the SoA change history or review process to preserve material changes to the compliance position.
When the question is whether a Control is adopted, where it applies operationally, whether it is implemented on an Asset, or whether assessments/tests support effectiveness, open Control Management. Do not use the SoA row as a replacement for those assurance records.
Provide a meaningful justification and complete any other required SoA fields before saving.
Confirm that the document is in an eligible governed state and that your role can access it.
Review the organisation Control in Control Management. SoA status and Control assurance are related but separate records and should be reconciled rather than assumed to be identical.