Cybersecurity & resilience
Statement of Applicability (SoA)
Published Reviewed
The Statement of Applicability is the ISO/IEC 27001 document that lists every control in Annex A, states whether each is applicable to the organisation, and justifies every inclusion and exclusion. It is the bridge between the risk assessment and the implemented controls, and one of the first documents a certification auditor asks for — an unjustified exclusion is a classic nonconformity.
Läs definitionen på svenska: Uttalande om tillämplighet (SoA)
Where this term does its work
Related terms
This definition is general information, not legal advice. Always verify the current official source.