ISO 27001 practical guide
ISO 27001 Statement of Applicability
The Statement of Applicability records the controls needed for the organization’s information-security risk treatment, explains inclusion and exclusion decisions, and states whether those controls are implemented. It is a traceability document: readers should be able to move from risks and requirements to control decisions and current evidence.
- Search intent
- Understand, create and maintain a defensible Statement of Applicability.
- Guide area
- Risk
- Review status
- Practitioner reviewed
What this means in practice
Annex A is a reference set used during treatment, not a universal implementation checklist. Necessary controls can also come from other sources.
The SoA is not the risk register or treatment plan. The register records risks; the plan records actions, ownership and timing; the SoA consolidates control applicability and implementation decisions.
Step-by-step implementation
- Step 1. Complete the risk assessment using approved criteria.
- Step 2. Choose treatment options and identify controls needed to implement them.
- Step 3. Compare necessary controls with Annex A to confirm no relevant control has been overlooked.
- Step 4. Record applicability and a decision-specific rationale for every Annex A control.
- Step 5. Record implementation status, owner and evidence reference.
- Step 6. Reconcile the SoA with risks, the treatment plan, actual control operation and organizational change.
- Step 7. Approve and review it through the organization’s governance process.
What to prepare
- current risk assessment and treatment decisions
- applicable legal, contractual and stakeholder requirements
- complete Annex A decision set
- control owners and implementation status
- evidence references and approved exceptions
Documents, records and evidence
| Area or field | Example | Why it matters |
|---|---|---|
| Control | 5.15 Access control | Stable identifier and usable title |
| Applicable | Yes | Decision rather than inherited template value |
| Rationale | Needed to manage unauthorized-access risks and customer commitments | Specific connection to risk or requirement |
| Status and evidence | Implemented; access standard, approvals and review records | Current state with traceable source |
| Owner | Identity and access manager | Accountable maintenance contact |
SoA, treatment plan and risk register
A risk concerning administrator compromise appears in the risk register. The treatment plan assigns MFA, privileged-access restriction and monitoring actions with owners and dates. The SoA marks relevant Annex A controls applicable, explains why, records current implementation status and points to evidence. These records connect but serve different decisions.
What an auditor will look for
- Complete control-by-control decisions and clear rationales.
- Consistency with assessed risks, obligations and selected treatments.
- Accurate implementation status supported by current evidence.
- Controlled review after scope, risk, supplier or technology change.
An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.
Common mistakes
- Copying generic rationales such as “required by ISO”.
- Marking controls implemented because a policy exists.
- Treating every control as mandatory without risk-based reasoning.
- Allowing the SoA and treatment plan to contradict each other.
Practical checklist
- □ All 93 Annex A controls have an applicability decision.
- □ Inclusion and exclusion rationales are specific and defensible.
- □ Implementation status reflects current operation.
- □ Controls trace to risks, obligations or other treatment needs.
- □ Owners and evidence references are maintainable.
- □ Changes trigger reconciliation and approval.
Frequently asked questions
Are all 93 controls mandatory?
No. Necessary controls follow risk treatment and applicable requirements; the SoA records and justifies Annex A decisions.
Can we use controls outside Annex A?
Yes. Use whatever controls are necessary and retain traceability; Annex A is used as a comparison reference.
Who approves the SoA?
The standard does not prescribe one job title. Assign approval through your governance and risk-acceptance arrangements.
Continue through the practical guide library
Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.