Controls
Statement of Applicability: how the SoA becomes a steering document
The SoA connects risks, selected controls, justifications and implementation status. It is more than a ticked-off Annex A list.
8 minute read · Content as of 21.07.2026
Every selection needs a traceable origin
Controls follow from risk treatment, legal and contractual requirements, and internal decisions. Annex A is a reference set for the completeness check, not the only possible source.
Four fields make the SoA auditable
For every Annex A control it should be clear whether it is applicable, why that decision was made, how it is implemented and which evidence supports the status. Exclusions need a defensible justification just as much as inclusions.
- Applicability and reason for the decision
- Implementation status and responsible role
- Reference to control, process or policy
- Evidence and date of the last effectiveness check
Avoid parallel truths
If the risk register, the treatment plan and the SoA are maintained separately, status entries drift apart. Use shared IDs and clear maintenance responsibility. The SoA starter already contains these linking fields.
Sources used
- ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
- ISO/IEC 27002:2022 · ISO · 2022
- ISMS practice patterns · KaitoSec