A Statement of Applicability (SoA) is a critical document that an organisation must produce for an ISO 27001 ISMS (Information security management system).
The SoA is a crucial, mandatory report for achieving ISO 27001 certification and an essential report for managing and controlling an ISMS.
ISO/IEC 27001:2022 states that, as part of the risk assessment process, organisations must produce an SoA that includes the following:
- The necessary controls
- Necessary Justifications for their inclusion
- Whether the necessary controls have been implemented or not
- Justifications for excluding any of the Annex A controls.
ISO 27001:2022 requires an ISMS to consider and document an organisation’s legal, statutory, regulatory, and contractual requirements for information security and its approach to meeting them. The SoA will record the list of controls selected to meet these requirements and whether they were implemented for reasons other than the risk assessment.
Steps to develop a Statement of Applicability:
The detailed process steps for developing an SoA is described below:
Step 1 – Identification and analysis of the risks
An organisation needs to identify all events that might compromise an asset's confidentiality, integrity, and availability (CIA) within the scope of the ISMS. It is also required to analyse how the risk might occur by identifying the vulnerability in an asset and a threat that might exploit that vulnerability.
Step 2 – Selection of controls to treat the identified risks
As part of the risk assessment, mitigating the risks to reduce them to an agreed, acceptable level is required.
The following are recommended ways by ISO 27001 to treat the risks:
- Retain (or Tolerate)
- Avoid (Terminate)
- Share (or Transfer)
- Modify (or Treat).
Modifying the risk involves applying the necessary security controls to reduce the impact and likelihood of the risk occurring. These controls can be referenced from ISO 27002 (or Annex A of ISO 27001) and those contained in other frameworks, such as the Payment Card Industry Data Security Standard (PCI DSS) or NIST SP 800-53.
Step 3 - Planning the risk treatment
The risk treatment plan (RTP) must be produced as part of a certified ISO 27001 ISMS. This summarises each identified risk, the responses determined for each risk, the risk owners, and the target date when the risk treatment will be applied.
Step 4 – Implement controls
An SoA should set out a list of all controls recommended by Annex A, together with a statement of whether the control has been applied and a justification for its inclusion or exclusion. Implementing the selected controls can be a time-consuming task, depending on the gap between the organisation’s actual security level and your risk appetite.
Maintaining the SoA
ISO 27001 requires the organisation to continually review, update, and improve the ISMS to ensure its effectiveness and adaptability to the constantly changing threat environment.
Clause 8.2 in ISO 27001 states that risk assessments should be performed at planned intervals or when significant changes occur.
An organisation may reduce its risk appetite and plan to reduce the impact and likelihood of identified risks by identifying new controls. A new SoA must be produced each time the organisation conducts a risk assessment. However, the SoA should be maintained between risk assessments so that an accurate record of the controls selected is readily available and to verify whether or not they have been implemented.

