Statement of Applicability (SoA)
SoA – all 93 Annex A controls, justified
使い方: The single most-audited 27001 doc. All 93 Annex A controls must appear; every "No" needs a defensible justification. Keep evidence links fresh or it decays.
プレビュー
Statement of Applicability (SoA)
The signature ISO/IEC 27001 document – mandatory cl.6.1.3 d. Lists ALL Annex A controls (93 in the 2022 revision) with: included/excluded, justification, implementation status. Auditors will walk this table row by row.
| Field | Value |
|---|---|
| Document ID | DOC-ISMS-011 |
| Standard | ISO/IEC 27001:2022 |
| Version | N.N |
| Approved by | Top management |
Control groups (Annex A:2022 structure)
- A.5 Organizational controls (37)
- A.6 People controls (8)
- A.7 Physical controls (14)
- A.8 Technological controls (34)
Applicability matrix
| Control | Title | Applicable? | Justification | Implementation | Evidence / doc ref |
|---|---|---|---|---|---|
| A.5.1 | Policies for information security | Yes | Core ISMS requirement | Implemented | DOC-ISMS-001 |
| A.5.2 | Information security roles | Yes | RACI defined | Implemented | DOC-ISMS-001 §3.2 |
| A.5.3 | Segregation of duties | Yes | Critical ops split | Partial | review NN |
| A.5.7 | Threat intelligence | Yes | Needed for risk ID | Implemented | feed + triage |
| A.5.9 | Inventory of assets | Yes | required | Implemented | DOC-ISMS-012 |
| A.5.10 | Acceptable use | Yes | required | Implemented | POL-AUP-001 |
| A.5.26 | Incident response | Yes | required | Implemented | DOC-ISMS-020 |
| A.5.31 | Legal requirements | Yes | required | Implemented | DOC-ISMS-014 |
| A.5.34 | Privacy & PII | Yes | GDPR scope | Implemented | DPIA process |
| A.6.3 | Awareness & training | Yes | staff handling data | Implemented | training records |
| A.7.4 | Physical monitoring | Partially | office only | Implemented | badge logs |
| A.8.1 | Endpoint protection | Yes | laptops in scope | Implemented | MDM policy |
| A.8.9 | Configuration mgmt | Yes | systems hardening | Partial | baseline doc |
| A.8.15 | Logging | Yes | incident forensics | Implemented | SIEM |
| A.8.16 | Monitoring activities | Yes | detection | Implemented | alerts |
| A.8.24 | Cryptography | Yes | data at rest/transit | Implemented | enc policy |
| ... | (repeat for all 93 controls) |
Justification of exclusions
| Control | Why excluded |
|---|---|
| A.N.N | Reason – must be defensible to auditor |
Approval & linkage
- Justification references risk treatment plan (DOC-ISMS-013)
- Approved by management – date + signature
- Reviewed at least annually and after incidents