markdowneditor

Statement of Applicability (SoA)

SoA – all 93 Annex A controls, justified

ISO & Tuân thủChuẩnstatementapplicability
Mở trong editorTải .md

Cách dùng: The single most-audited 27001 doc. All 93 Annex A controls must appear; every "No" needs a defensible justification. Keep evidence links fresh or it decays.

Xem trước

Statement of Applicability (SoA)

The signature ISO/IEC 27001 document – mandatory cl.6.1.3 d. Lists ALL Annex A controls (93 in the 2022 revision) with: included/excluded, justification, implementation status. Auditors will walk this table row by row.

FieldValue
Document IDDOC-ISMS-011
StandardISO/IEC 27001:2022
VersionN.N
Approved byTop management

Control groups (Annex A:2022 structure)

  • A.5 Organizational controls (37)
  • A.6 People controls (8)
  • A.7 Physical controls (14)
  • A.8 Technological controls (34)

Applicability matrix

ControlTitleApplicable?JustificationImplementationEvidence / doc ref
A.5.1Policies for information securityYesCore ISMS requirementImplementedDOC-ISMS-001
A.5.2Information security rolesYesRACI definedImplementedDOC-ISMS-001 §3.2
A.5.3Segregation of dutiesYesCritical ops splitPartialreview NN
A.5.7Threat intelligenceYesNeeded for risk IDImplementedfeed + triage
A.5.9Inventory of assetsYesrequiredImplementedDOC-ISMS-012
A.5.10Acceptable useYesrequiredImplementedPOL-AUP-001
A.5.26Incident responseYesrequiredImplementedDOC-ISMS-020
A.5.31Legal requirementsYesrequiredImplementedDOC-ISMS-014
A.5.34Privacy & PIIYesGDPR scopeImplementedDPIA process
A.6.3Awareness & trainingYesstaff handling dataImplementedtraining records
A.7.4Physical monitoringPartiallyoffice onlyImplementedbadge logs
A.8.1Endpoint protectionYeslaptops in scopeImplementedMDM policy
A.8.9Configuration mgmtYessystems hardeningPartialbaseline doc
A.8.15LoggingYesincident forensicsImplementedSIEM
A.8.16Monitoring activitiesYesdetectionImplementedalerts
A.8.24CryptographyYesdata at rest/transitImplementedenc policy
...(repeat for all 93 controls)

Justification of exclusions

ControlWhy excluded
A.N.NReason – must be defensible to auditor

Approval & linkage

  • Justification references risk treatment plan (DOC-ISMS-013)
  • Approved by management – date + signature
  • Reviewed at least annually and after incidents

Template liên quan