# Statement of Applicability (SoA)

> **The signature ISO/IEC 27001 document** – mandatory cl.6.1.3 d.
> Lists ALL Annex A controls (93 in the 2022 revision) with:
> included/excluded, justification, implementation status. Auditors
> will walk this table row by row.

| Field | Value |
|-------|-------|
| Document ID | DOC-ISMS-011 |
| Standard | ISO/IEC 27001:2022 |
| Version | N.N |
| Approved by | Top management |

## Control groups (Annex A:2022 structure)

- A.5 Organizational controls (37)
- A.6 People controls (8)
- A.7 Physical controls (14)
- A.8 Technological controls (34)

## Applicability matrix

| Control | Title | Applicable? | Justification | Implementation | Evidence / doc ref |
|---------|-------|-------------|---------------|----------------|---------------------|
| A.5.1 | Policies for information security | Yes | Core ISMS requirement | Implemented | DOC-ISMS-001 |
| A.5.2 | Information security roles | Yes | RACI defined | Implemented | DOC-ISMS-001 §3.2 |
| A.5.3 | Segregation of duties | Yes | Critical ops split | Partial | review NN |
| A.5.7 | Threat intelligence | Yes | Needed for risk ID | Implemented | feed + triage |
| A.5.9 | Inventory of assets | Yes | required | Implemented | DOC-ISMS-012 |
| A.5.10 | Acceptable use | Yes | required | Implemented | POL-AUP-001 |
| A.5.26 | Incident response | Yes | required | Implemented | DOC-ISMS-020 |
| A.5.31 | Legal requirements | Yes | required | Implemented | DOC-ISMS-014 |
| A.5.34 | Privacy & PII | Yes | GDPR scope | Implemented | DPIA process |
| A.6.3 | Awareness & training | Yes | staff handling data | Implemented | training records |
| A.7.4 | Physical monitoring | Partially | office only | Implemented | badge logs |
| A.8.1 | Endpoint protection | Yes | laptops in scope | Implemented | MDM policy |
| A.8.9 | Configuration mgmt | Yes | systems hardening | Partial | baseline doc |
| A.8.15 | Logging | Yes | incident forensics | Implemented | SIEM |
| A.8.16 | Monitoring activities | Yes | detection | Implemented | alerts |
| A.8.24 | Cryptography | Yes | data at rest/transit | Implemented | enc policy |
| ... | *(repeat for all 93 controls)* | | | | |

## Justification of exclusions

| Control | Why excluded |
|---------|--------------|
| A.N.N | Reason – must be defensible to auditor |

## Approval & linkage

- Justification references risk treatment plan (DOC-ISMS-013)
- Approved by management – date + signature
- Reviewed at least annually and after incidents
