Definition
Statement of Applicability
The Statement of Applicability, or SoA, is the ISO 27001 document that lists every Annex A control, states whether you apply it, and explains why. When you exclude a control, you record the reason; when you include one, you note how you implement it. Auditors treat the SoA as the map of your ISMS, because it links your risk assessment to the specific safeguards you chose. It is one of the few ISO 27001 documents that is mandatory by name, and certification bodies review it closely to confirm your control selection actually matches the risks you identified.
Related services
Keep exploring
← Back to the full glossary