Statement of Applicability Template
Produces a complete, defensible SoA with justification wording that withstands auditor challenge on both inclusion and exclusion.
Available soon
- Format
- Excel
- Size
- 97 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- SoA Approval
- Statement of Applicability
- Worked Example
- Wording Guide
- Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Start from your risk assessment and risk treatment plan (clauses 6.1.2 and 6.1.3) and your ISMS scope (clause 4.3, IS-02). The SoA records the result of risk treatment; it does not replace it. Controls must be chosen from the risk assessment, not from the Annex A list; the Statement of Applicability must justify every inclusion and exclusion. (IS-03) |
| 2 | On the Statement of Applicability sheet, all 93 controls are listed in Annex A order. Keep every row: a control missing from the SoA is a finding. For each control choose Applicable? Yes or No. The Annex A Control Implementation Library explains each control and, for those that depend on scope, the question that decides. |
| 3 | For each control that applies: choose the main reason (Risk treatment, Legal or regulatory, Contractual, Business requirement) and, if there is a second, Also required by. Where risk treatment is a reason, list the risk IDs from your risk register. Write one sentence of justification: what the control protects against, or which law or contract requires it. |
| 4 | Then record the implementation status (Implemented, Partly, Planned, Not implemented), who delivers it (Us, Supplier, Us and a supplier), how it is implemented — name the policy, procedure or system — the owner, and an evidence reference for anything implemented. A control carried out by a supplier is applicable and "Delivered by: Supplier"; it is not an exclusion. |
| 5 | For each control that does not apply: choose the exclusion reason type (Activity not carried out within the scope; Risk assessment found no risk the control would treat; Outside the ISMS scope) and write a justification of at least 12 words that follows from your risk assessment and scope, and says what would make you revisit it. "N/A", "not applicable" or "not relevant" on their own are flagged: they will not withstand an auditor's challenge. The Wording Guide sheet shows weak and defensible wording side by side. |
| 6 | Clear every Check that does not say OK. Each row shows only its first unresolved item; clear it and the next, if any, appears. |
| 7 | Complete the SoA Approval sheet: the version, the risk assessment, treatment plan and scope it rests on, and approval by e.g. Executive Committee. The SoA is controlled documented information (clause 7.5.3, IS-04): keep superseded versions, and do not change a decision without re-approval. |
| 8 | From the start of Phase 4 update the status columns at least monthly (IS-10), and review every decision when the risk assessment, the scope or the organisation changes, and at least every 12 months. The certification body asks for the SoA at Stage 1 and samples its controls at Stage 2; see the Stage 1 and Stage 2 Audit Preparation Guide. |
| 9 | Delete the Worked Example sheet and the EXAMPLE column on the SoA Approval sheet before the SoA is approved. Do not type over the white calculated column. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
EXAMPLE: a software services company with 240 staff in two offices, an NIS2 important entity, preparing for its first certification (Stage 2 on 2027-03-01). Its scope: the design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. Statuses are as at 2026-09-30 (EXAMPLE date; in your SoA, use the date of your update).
In the EXAMPLE, references such as ISP-001 are documents in the example organisation's policy register (the Security Policy Management pack). A reference such as (PT-12) is its document on that policy topic, not in the register extract. Risk IDs R-01 to R-12 are its risk register (see the Definitions sheet); your risk method and register may come from the Information Security Risk Management pack.
In the EXAMPLE, 92 controls apply and 1 is excluded (A.8.30 Outsourced development: no development is contracted out). Physical controls in the cloud provider's data centres are applicable and delivered by the supplier, not excluded. An SoA with many exclusions is usually a sign that controls were dropped for convenience.
Tailoring — small organisation: most controls still apply; keep the justification to one sentence and implement proportionately. Exclude only where the activity genuinely does not happen in scope.
Tailoring — regulated entity: ISO/IEC 27001:2022 is the requirement for certification. Where a law such as NIS2 or DORA requires a control, choose Legal or regulatory as a reason; do not exclude a control the law requires. Certification is evidence for a regulator, not compliance with the law.
Tailoring — IT run by a service provider: record each control the provider runs as Delivered by: Supplier or Us and a supplier, with the contract or the provider's certificate as how it is implemented. Check that the provider's certificate covers the service you buy.
SoA Approval
Statement of Applicability — version and approval
The SoA is controlled documented information (clause 7.5.3). Record what it rests on and who approved it. Delete the EXAMPLE column before approval.
| Item | Your SoA | EXAMPLE | Guidance |
|---|---|---|---|
| SoA version | [[1.0]] | ISMS-03, version 1.1 — statuses updated; decisions unchanged since 1.0 | Increase the minor version for a status update, the major version when a decision changes. |
| Status | [[Draft / Approved / Superseded]] | Approved | Only an approved SoA is presented to the certification body. |
| ISMS scope it covers (document and version) | [[e.g. ISMS Scope Statement v1.0]] | ISMS-01 ISMS Scope Statement, approved 2026-05-11: the design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on | The SoA covers the whole scope and nothing outside it (IS-02). |
| Risk assessment it is based on (version, date) | [[e.g. Risk assessment v1.0, YYYY-MM-DD]] | ISMS-07 Information Security Risk Register, approved 2026-07-20, assessed with ISMS-02 Risk Management Methodology | Every Risk ID in the SoA comes from this assessment. A new assessment means reviewing the SoA. |
| Risk treatment plan (version, date) | [[e.g. Risk treatment plan v1.0, YYYY-MM-DD]] | ISMS-04 Risk Treatment Plan, approved 2026-08-24 with the risk owners' acceptance of residual risk | Risk owners approve the plan and accept the residual risk (clause 6.1.3). |
| Implementation status as at | [[YYYY-MM-DD]] | 2026-09-30 | The date the status columns were last updated. EXAMPLE date: replace it with the date of your update. |
| Prepared by (name, role) | [[Name, ISMS manager]] | Head of Information Security (the ISMS manager) | |
| Decisions approved by (name, role) | [[e.g. Executive Committee]] | Executive Committee | Top management approves the decisions, not only the ISMS manager (IS-01). |
| Date decisions were approved | [[YYYY-MM-DD]] | 2026-08-24 (version 1.0) | A change to any Applicable? decision needs a new approval. |
| Next review | [[YYYY-MM-DD — at least every 12 months, and after a change to the risk assessment or scope]] | Before the Stage 1 audit on 2027-01-18, then every 12 months | |
| Where it is kept and who may see it | [[e.g. ISMS document library; shared with the certification body, and with customers under a confidentiality agreement]] | ISMS document library; shared with the certification body, and with customers under a confidentiality agreement | The SoA describes your defences: classify and share it accordingly. |
EXAMPLE references and dates are the example organisation's ISMS documents (ISMS-01, ISMS-02, ISMS-07, ISMS-04, ISMS-03), as the Mandatory ISMS Documentation Checklist lists them.
Statement of Applicability
All 93 Annex A controls. Yellow columns are yours; Check calculates. Keep every row: decide each one Yes or No, with the reason.
| Control | Control title (ISO/IEC 27001:2022) | Theme | Applicable? | Main reason for inclusion | Also required by | Risk IDs treated | Justification for inclusion | Implementation status | Delivered by | How it is implemented (policy, procedure or system) | Owner | Evidence reference | Exclusion reason type | Justification for exclusion | Notes | Check (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| A.5.1 | Policies for information security | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.2 | Information security roles and responsibilities | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.3 | Segregation of duties | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.4 | Management responsibilities | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.5 | Contact with authorities | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.6 | Contact with special interest groups | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.7 | Threat intelligence | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.8 | Information security in project management | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.9 | Inventory of information and other associated assets | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.10 | Acceptable use of information and other associated assets | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.11 | Return of assets | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.12 | Classification of information | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.13 | Labelling of information | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.14 | Information transfer | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.15 | Access control | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.16 | Identity management | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.17 | Authentication information | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.18 | Access rights | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.19 | Information security in supplier relationships | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.20 | Addressing information security within supplier agreements | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.21 | Managing information security in the ICT supply chain | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.22 | Monitoring, review and change management of supplier services | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.23 | Information security for use of cloud services | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.24 | Information security incident management planning and preparation | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.25 | Assessment and decision on information security events | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.26 | Response to information security incidents | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.27 | Learning from information security incidents | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.28 | Collection of evidence | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.29 | Information security during disruption | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.30 | ICT readiness for business continuity | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.31 | Legal, statutory, regulatory and contractual requirements | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.32 | Intellectual property rights | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.33 | Protection of records | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.34 | Privacy and protection of PII | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.35 | Independent review of information security | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.36 | Compliance with policies, rules and standards for information security | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.5.37 | Documented operating procedures | A.5 Organizational controls | Decide: applicable Yes or No | |||||||||||||
| A.6.1 | Screening | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.2 | Terms and conditions of employment | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.3 | Information security awareness, education and training | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.4 | Disciplinary process | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.5 | Responsibilities after termination or change of employment | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.6 | Confidentiality or non-disclosure agreements | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.7 | Remote working | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.6.8 | Information security event reporting | A.6 People controls | Decide: applicable Yes or No | |||||||||||||
| A.7.1 | Physical security perimeters | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.2 | Physical entry | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.3 | Securing offices, rooms and facilities | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.4 | Physical security monitoring | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.5 | Protecting against physical and environmental threats | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.6 | Working in secure areas | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.7 | Clear desk and clear screen | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.8 | Equipment siting and protection | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.9 | Security of assets off-premises | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.10 | Storage media | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.11 | Supporting utilities | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.12 | Cabling security | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.13 | Equipment maintenance | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.7.14 | Secure disposal or re-use of equipment | A.7 Physical controls | Decide: applicable Yes or No | |||||||||||||
| A.8.1 | User endpoint devices | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.2 | Privileged access rights | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.3 | Information access restriction | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.4 | Access to source code | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.5 | Secure authentication | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.6 | Capacity management | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.7 | Protection against malware | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.8 | Management of technical vulnerabilities | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.9 | Configuration management | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.10 | Information deletion | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.11 | Data masking | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.12 | Data leakage prevention | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.13 | Information backup | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.14 | Redundancy of information processing facilities | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.15 | Logging | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.16 | Monitoring activities | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.17 | Clock synchronization | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.18 | Use of privileged utility programs | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.19 | Installation of software on operational systems | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.20 | Networks security | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.21 | Security of network services | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.22 | Segregation of networks | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.23 | Web filtering | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.24 | Use of cryptography | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.25 | Secure development life cycle | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.26 | Application security requirements | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.27 | Secure system architecture and engineering principles | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.28 | Secure coding | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.29 | Security testing in development and acceptance | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.30 | Outsourced development | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.31 | Separation of development, test and production environments | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.32 | Change management | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.33 | Test information | A.8 Technological controls | Decide: applicable Yes or No | |||||||||||||
| A.8.34 | Protection of information systems during audit testing | A.8 Technological controls | Decide: applicable Yes or No |
Worked Example
EXAMPLE: the example organisation's completed SoA, statuses as at 2026-09-30. Same columns as the Statement of Applicability sheet. Delete this sheet before approval.
| Example | Control | Control title (ISO/IEC 27001:2022) | Theme | Applicable? | Main reason for inclusion | Also required by | Risk IDs treated | Justification for inclusion | Implementation status | Delivered by | How it is implemented (policy, procedure or system) | Owner | Evidence reference | Exclusion reason type | Justification for exclusion | Notes | Check (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | A.5.1 | Policies for information security | A.5 Organizational controls | Yes | Business requirement | Legal or regulatory | The ISMS needs an approved top policy; customers and the NIS2 duties of an important entity expect one. | Implemented | Us | ISP-001 Information Security Policy; topic policies in the policy register | Head of Information Security | Evidence library, folder A.5.1 | OK | ||||
| EXAMPLE | A.5.2 | Information security roles and responsibilities | A.5 Organizational controls | Yes | Business requirement | Legal or regulatory | Every control needs an accountable owner; NIS2 expects management accountability. | Implemented | Us | ISMS-06 ISMS Manual (processes, roles and responsibilities) | Head of Information Security | Evidence library, folder A.5.2 | OK | ||||
| EXAMPLE | A.5.3 | Segregation of duties | A.5 Organizational controls | Yes | Risk treatment | R-07 | Separates requesting from approving access and developing from deploying code. | Implemented | Us | ACP-001 Access Control Policy; code review enforced before merge | Head of IT | Evidence library, folder A.5.3 | OK | ||||
| EXAMPLE | A.5.4 | Management responsibilities | A.5 Organizational controls | Yes | Business requirement | Managers must require their teams to follow the policies for any control to work. | Implemented | Us | ISP-001 Information Security Policy; managers' objectives include training and access review completion | Chief Operating Officer | Evidence library, folder A.5.4 | OK | |||||
| EXAMPLE | A.5.5 | Contact with authorities | A.5 Organizational controls | Yes | Legal or regulatory | R-11 | As an NIS2 important entity the company must be able to notify the national authority on time. | Planned | Us | Head of Information Security | Gap in the ISMS Gap & Remediation Tracker: No list of which authorities to contact, when, and who may do it. | OK | |||||
| EXAMPLE | A.5.6 | Contact with special interest groups | A.5 Organizational controls | Yes | Risk treatment | R-03 | Early warning of vulnerabilities in the platform's technology stack. | Implemented | Us | Membership of a national software-sector information-sharing group; vendor security forums | Head of Information Security | Evidence library, folder A.5.6 | OK | ||||
| EXAMPLE | A.5.7 | Threat intelligence | A.5 Organizational controls | Yes | Risk treatment | R-02, R-03 | Threat information tunes detection and patch priorities for the attacks the platform faces. | Planned | Us and a supplier | Head of Information Security | Gap in the ISMS Gap & Remediation Tracker: Threat information is read informally; nothing is recorded or acted on. | OK | |||||
| EXAMPLE | A.5.8 | Information security in project management | A.5 Organizational controls | Yes | Risk treatment | R-04 | New product features and internal projects change data and systems; security is set at initiation. | Planned | Us | Head of Engineering | Gap in the ISMS Gap & Remediation Tracker: Security is not a step in the project method. | OK | |||||
| EXAMPLE | A.5.9 | Inventory of information and other associated assets | A.5 Organizational controls | Yes | Risk treatment | R-01, R-03 | Scanning, access and backup all depend on knowing what assets exist. | Implemented | Us | Asset management and information classification policy (PT-04); inventory built from device management and cloud accounts | Head of IT | Evidence library, folder A.5.9 | OK | ||||
| EXAMPLE | A.5.10 | Acceptable use of information and other associated assets | A.5 Organizational controls | Yes | Risk treatment | R-08, R-10 | Sets the rules staff follow with company data and devices. | Implemented | Us | AUP-001 Acceptable Use Policy (review overdue; being updated) | Head of IT | Evidence library, folder A.5.10 | OK | ||||
| EXAMPLE | A.5.11 | Return of assets | A.5 Organizational controls | Yes | Risk treatment | R-08 | Devices and access must come back at every exit. | Implemented | Us | JML-PRC Joiner, Mover, Leaver Procedure (leaver checklist) | HR Director | Evidence library, folder A.5.11 | OK | ||||
| EXAMPLE | A.5.12 | Classification of information | A.5 Organizational controls | Yes | Contractual | Risk treatment | R-01 | Customer contracts require customer data to be identified and handled as confidential. | Implemented | Us | Asset management and information classification policy (PT-04) (classification scheme) | Head of Information Security | Evidence library, folder A.5.12 | OK | |||
| EXAMPLE | A.5.13 | Labelling of information | A.5 Organizational controls | Yes | Contractual | R-01 | Labels make customer data recognisable wherever it is handled. | Not implemented | Us | Head of IT | Gap in the ISMS Gap & Remediation Tracker: No labelling of classified information. | OK | |||||
| EXAMPLE | A.5.14 | Information transfer | A.5 Organizational controls | Yes | Risk treatment | Contractual | R-01 | Customer data is exchanged by file transfer and email; transfers must be protected. | Implemented | Us | AUP-001 Acceptable Use Policy; external sharing restricted in the collaboration suite | Head of Information Security | Evidence library, folder A.5.14 | OK | |||
| EXAMPLE | A.5.15 | Access control | A.5 Organizational controls | Yes | Risk treatment | R-01, R-07 | Access to the platform and customer data must follow need-to-know. | Implemented | Us | ACP-001 Access Control Policy | Head of IT | Evidence library, folder A.5.15 | OK | ||||
| EXAMPLE | A.5.16 | Identity management | A.5 Organizational controls | Yes | Risk treatment | R-01 | One identity per person, created only from an HR trigger. | Implemented | Us | ACP-001 Access Control Policy; JML-PRC Joiner, Mover, Leaver Procedure | Head of IT | Evidence library, folder A.5.16 | OK | ||||
| EXAMPLE | A.5.17 | Authentication information | A.5 Organizational controls | Yes | Risk treatment | R-01, R-10 | Stolen credentials are the main route to customer data. | Implemented | Us | ACP-001 Access Control Policy; company password manager | Head of IT | Evidence library, folder A.5.17 | OK | ||||
| EXAMPLE | A.5.18 | Access rights | A.5 Organizational controls | Yes | Risk treatment | Legal or regulatory | R-01, R-07 | Access must be granted on approval, changed on moves and reviewed. | Implemented | Us | ACP-001 Access Control Policy; JML-PRC Joiner, Mover, Leaver Procedure; quarterly access reviews (User Access Review pack) | Head of IT | Evidence library, folder A.5.18 | OK | |||
| EXAMPLE | A.5.19 | Information security in supplier relationships | A.5 Organizational controls | Yes | Risk treatment | Legal or regulatory | R-05, R-06 | The platform depends on a cloud provider and several software-as-a-service suppliers. | Partly | Us | SUP-001 Supplier Security Policy drafted and with its approver; supplier register kept by Procurement | Head of Procurement | Evidence library, folder A.5.19 | Gap in the ISMS Gap & Remediation Tracker: The Supplier Security Policy (P04 register SUP-001) is awaiting approval; supplier tiers not yet applied. | OK | ||
| EXAMPLE | A.5.20 | Addressing information security within supplier agreements | A.5 Organizational controls | Yes | Risk treatment | Contractual | R-06 | Supplier security duties must be in the contracts to be enforceable. | Partly | Us | Security clauses in the newest supplier contracts; the rest at renewal | Head of Procurement | Evidence library, folder A.5.20 | Gap in the ISMS Gap & Remediation Tracker: Security clauses are missing from most key supplier contracts. | OK | ||
| EXAMPLE | A.5.21 | Managing information security in the ICT supply chain | A.5 Organizational controls | Yes | Risk treatment | R-03, R-06 | Open-source components and the cloud provider's own suppliers are part of the product's supply chain. | Planned | Us | Head of Procurement | Gap in the ISMS Gap & Remediation Tracker: No check of the security of the software and cloud supply chain. | OK | |||||
| EXAMPLE | A.5.22 | Monitoring, review and change management of supplier services | A.5 Organizational controls | Yes | Risk treatment | R-05, R-06 | Supplier assurance must be kept current. | Planned | Us | Head of Procurement | Gap in the ISMS Gap & Remediation Tracker: Supplier performance and changes are not reviewed for security. | OK | |||||
| EXAMPLE | A.5.23 | Information security for use of cloud services | A.5 Organizational controls | Yes | Risk treatment | Contractual | R-05, R-06 | The whole service runs on one cloud provider under shared responsibility. | Implemented | Us and a supplier | Cloud responsibility matrix; configuration baseline for the provider's services; provider's certificate and assurance report reviewed | Head of IT | Evidence library, folder A.5.23 | OK | |||
| EXAMPLE | A.5.24 | Information security incident management planning and preparation | A.5 Organizational controls | Yes | Risk treatment | Legal or regulatory | R-02, R-11 | Incident readiness is needed for the platform and for NIS2 reporting deadlines. | Implemented | Us | INC-001 Incident Management Policy | Head of Information Security | Evidence library, folder A.5.24 | OK | |||
| EXAMPLE | A.5.25 | Assessment and decision on information security events | A.5 Organizational controls | Yes | Risk treatment | R-02, R-11 | Events must be classified quickly to meet reporting deadlines. | Implemented | Us | INC-001 Incident Management Policy (severity criteria) | Head of Information Security | Evidence library, folder A.5.25 | OK | ||||
| EXAMPLE | A.5.26 | Response to information security incidents | A.5 Organizational controls | Yes | Risk treatment | Legal or regulatory | R-02, R-11 | Incidents on the platform must be contained and notified on time. | Implemented | Us and a supplier | INC-001 Incident Management Policy; managed security provider retained for response | Head of Information Security | Evidence library, folder A.5.26 | OK | |||
| EXAMPLE | A.5.27 | Learning from information security incidents | A.5 Organizational controls | Yes | Risk treatment | R-02 | Lessons from incidents feed the risk assessment. | Implemented | Us | INC-001 Incident Management Policy (post-incident review) | Head of Information Security | Evidence library, folder A.5.27 | OK | ||||
| EXAMPLE | A.5.28 | Collection of evidence | A.5 Organizational controls | Yes | Legal or regulatory | R-11 | Evidence may be needed for regulators, customers or legal action. | Planned | Us and a supplier | Legal Counsel | Gap in the ISMS Gap & Remediation Tracker: No agreed way to collect and preserve evidence from an incident. | OK | |||||
| EXAMPLE | A.5.29 | Information security during disruption | A.5 Organizational controls | Yes | Risk treatment | R-05 | Security must hold during a platform or office disruption. | Implemented | Us | Business continuity and ICT resilience policy (PT-16) (security during disruption, emergency access) | IT Operations Manager | Evidence library, folder A.5.29 | OK | ||||
| EXAMPLE | A.5.30 | ICT readiness for business continuity | A.5 Organizational controls | Yes | Risk treatment | Contractual | R-05, R-09 | Customer contracts set availability and recovery commitments. | Partly | Us and a supplier | Business continuity and ICT resilience policy (PT-16); recovery objectives set for the platform | IT Operations Manager | Evidence library, folder A.5.30 | Gap in the ISMS Gap & Remediation Tracker: Recovery objectives are set but the platform's recovery has not been tested. | OK | ||
| EXAMPLE | A.5.31 | Legal, statutory, regulatory and contractual requirements | A.5 Organizational controls | Yes | Legal or regulatory | Contractual | R-11 | NIS2, data protection law and customer security schedules apply to the service. | Planned | Us | Legal Counsel | Gap in the ISMS Gap & Remediation Tracker: No register of legal, regulatory and contractual security requirements. | OK | ||||
| EXAMPLE | A.5.32 | Intellectual property rights | A.5 Organizational controls | Yes | Legal or regulatory | R-11 | The product includes third-party and open-source code under licence. | Implemented | Us | Licence register; open-source licence checks in the build pipeline | Legal Counsel | Evidence library, folder A.5.32 | OK | ||||
| EXAMPLE | A.5.33 | Protection of records | A.5 Organizational controls | Yes | Legal or regulatory | R-11 | Financial, contractual, personnel and security records must be kept for set periods. | Planned | Us | Legal Counsel | Gap in the ISMS Gap & Remediation Tracker: Retention periods are not set for security records. | OK | |||||
| EXAMPLE | A.5.34 | Privacy and protection of PII | A.5 Organizational controls | Yes | Legal or regulatory | Contractual | R-01, R-11 | The company processes customers' personal data as a processor and staff data as a controller. | Implemented | Us | Records of processing; privacy impact assessments; breach procedure linked to INC-001 | Legal Counsel | Evidence library, folder A.5.34 | OK | |||
| EXAMPLE | A.5.35 | Independent review of information security | A.5 Organizational controls | Yes | Business requirement | Top management wants an independent view of the ISMS, beyond the certification audit. | Planned | Us | Chief Operating Officer | Gap in the ISMS Gap & Remediation Tracker: No plan for independent review of the ISMS beyond the certification audit. | OK | ||||||
| EXAMPLE | A.5.36 | Compliance with policies, rules and standards for information security | A.5 Organizational controls | Yes | Business requirement | Policies must be shown to be followed, and deviations approved. | Implemented | Us | ISP-001 Information Security Policy; EXC-STD Security Exception & Waiver Standard | Head of Information Security | Evidence library, folder A.5.36 | OK | |||||
| EXAMPLE | A.5.37 | Documented operating procedures | A.5 Organizational controls | Yes | Risk treatment | R-05, R-09 | Deployments, backups and user administration must be done the same way by whoever is on call. | Implemented | Us | Runbooks in the engineering wiki, reviewed at each platform change | IT Operations Manager | Evidence library, folder A.5.37 | OK | ||||
| EXAMPLE | A.6.1 | Screening | A.6 People controls | Yes | Risk treatment | R-07 | Staff get access to customer data. | Implemented | Us | People security policy (PT-14); checks by role before start | HR Director | Evidence library, folder A.6.1 | OK | ||||
| EXAMPLE | A.6.2 | Terms and conditions of employment | A.6 People controls | Yes | Risk treatment | R-07 | Security duties must be part of every contract of employment. | Implemented | Us | People security policy (PT-14); contract templates with confidentiality and security terms | HR Director | Evidence library, folder A.6.2 | OK | ||||
| EXAMPLE | A.6.3 | Information security awareness, education and training | A.6 People controls | Yes | Risk treatment | Legal or regulatory | R-10 | Phishing is a leading risk; NIS2 expects cyber-security training. | Implemented | Us | People security policy (PT-14); awareness campaign with completion tracked | Head of Information Security | Evidence library, folder A.6.3 | OK | |||
| EXAMPLE | A.6.4 | Disciplinary process | A.6 People controls | Yes | Business requirement | Policy breaches must have a fair, known consequence. | Planned | Us | HR Director | Gap in the ISMS Gap & Remediation Tracker: The disciplinary procedure does not mention information security breaches. | OK | ||||||
| EXAMPLE | A.6.5 | Responsibilities after termination or change of employment | A.6 People controls | Yes | Risk treatment | R-07 | Confidentiality continues after exit and access must end with the role. | Implemented | Us | JML-PRC Joiner, Mover, Leaver Procedure | HR Director | Evidence library, folder A.6.5 | OK | ||||
| EXAMPLE | A.6.6 | Confidentiality or non-disclosure agreements | A.6 People controls | Yes | Contractual | R-01 | Customer contracts require confidentiality from everyone with access to their data. | Implemented | Us | Standard confidentiality agreements for staff and third parties | HR Director | Evidence library, folder A.6.6 | OK | ||||
| EXAMPLE | A.6.7 | Remote working | A.6 People controls | Yes | Risk treatment | R-08 | Most staff work remotely part of the week. | Implemented | Us | AUP-001 Acceptable Use Policy; RMT-GDL Remote Working Guideline; device compliance required for access | Head of IT | Evidence library, folder A.6.7 | OK | ||||
| EXAMPLE | A.6.8 | Information security event reporting | A.6 People controls | Yes | Risk treatment | Legal or regulatory | R-02, R-11 | Fast reporting is needed to meet incident reporting deadlines. | Implemented | Us | INC-001 Incident Management Policy (report button and mailbox) | Head of Information Security | Evidence library, folder A.6.8 | OK | |||
| EXAMPLE | A.7.1 | Physical security perimeters | A.7 Physical controls | Yes | Risk treatment | R-12 | Two offices hold staff devices; the platform sits in the provider's data centres. | Implemented | Us and a supplier | Physical and environmental security standard (PT-13); building perimeter run by the landlords | Office Manager | Evidence library, folder A.7.1 | OK | ||||
| EXAMPLE | A.7.2 | Physical entry | A.7 Physical controls | Yes | Risk treatment | R-12 | Only staff and escorted visitors may enter the offices. | Implemented | Us and a supplier | Physical and environmental security standard (PT-13); badge access and visitor log | Office Manager | Evidence library, folder A.7.2 | OK | ||||
| EXAMPLE | A.7.3 | Securing offices, rooms and facilities | A.7 Physical controls | Yes | Risk treatment | R-12 | The equipment room and HR room must be locked. | Implemented | Us | Physical and environmental security standard (PT-13); locked equipment room and HR room | Office Manager | Evidence library, folder A.7.3 | OK | ||||
| EXAMPLE | A.7.4 | Physical security monitoring | A.7 Physical controls | Yes | Risk treatment | R-12 | An intrusion to the offices out of hours must be noticed. | Partly | Us and a supplier | Landlord camera and alarm cover the first office; the second is being confirmed | Office Manager | Evidence library, folder A.7.4 | Gap in the ISMS Gap & Remediation Tracker: Camera coverage and alarm monitoring of the second office are not confirmed. | OK | |||
| EXAMPLE | A.7.5 | Protecting against physical and environmental threats | A.7 Physical controls | Yes | Risk treatment | R-05, R-12 | Fire or flood could damage office equipment; the provider protects the data centres. | Implemented | Us and a supplier | Physical and environmental security standard (PT-13); landlord fire systems; provider's assurance report for the data centres | Office Manager | Evidence library, folder A.7.5 | OK | ||||
| EXAMPLE | A.7.6 | Working in secure areas | A.7 Physical controls | Yes | Risk treatment | R-05, R-12 | The office equipment room is a secure area; the cloud provider's data centres hold the platform. | Implemented | Us and a supplier | Physical and environmental security standard (PT-13) (equipment room rules); provider's certificate and assurance report, reviewed under A.5.22 | Office Manager | Evidence library, folder A.7.6 | OK | ||||
| EXAMPLE | A.7.7 | Clear desk and clear screen | A.7 Physical controls | Yes | Risk treatment | R-01 | Customer data is on screens in open-plan offices. | Planned | Us | Office Manager | Gap in the ISMS Gap & Remediation Tracker: No clear desk and clear screen rule. | OK | |||||
| EXAMPLE | A.7.8 | Equipment siting and protection | A.7 Physical controls | Yes | Risk treatment | R-12 | Office network equipment must be protected; platform equipment is the provider's. | Implemented | Us and a supplier | Network equipment in the locked equipment room; provider's assurance report | Office Manager | Evidence library, folder A.7.8 | OK | ||||
| EXAMPLE | A.7.9 | Security of assets off-premises | A.7 Physical controls | Yes | Risk treatment | R-08 | Laptops and phones travel with staff. | Implemented | Us | AUP-001 Acceptable Use Policy; RMT-GDL Remote Working Guideline; full-disk encryption and remote wipe | Head of IT | Evidence library, folder A.7.9 | OK | ||||
| EXAMPLE | A.7.10 | Storage media | A.7 Physical controls | Yes | Risk treatment | R-01, R-08 | Removable media could carry customer data out. | Implemented | Us | USB storage blocked by device management except approved encrypted drives | Head of IT | Evidence library, folder A.7.10 | OK | ||||
| EXAMPLE | A.7.11 | Supporting utilities | A.7 Physical controls | Yes | Risk treatment | R-05 | The platform depends on the data centres' power and cooling. | Implemented | Supplier | Provider's assurance report; the offices hold no equipment that must run through an outage | IT Operations Manager | Evidence library, folder A.7.11 | OK | ||||
| EXAMPLE | A.7.12 | Cabling security | A.7 Physical controls | Yes | Risk treatment | R-05 | Cabling that carries customer data is in the provider's data centres and the landlords' risers. | Implemented | Supplier | Provider's assurance report; landlord building management | IT Operations Manager | Evidence library, folder A.7.12 | OK | ||||
| EXAMPLE | A.7.13 | Equipment maintenance | A.7 Physical controls | Yes | Risk treatment | R-08 | Laptops go for repair; the provider maintains platform hardware. | Implemented | Us and a supplier | Physical and environmental security standard (PT-13); repairs only through the approved vendor with the drive encrypted | IT Operations Manager | Evidence library, folder A.7.13 | OK | ||||
| EXAMPLE | A.7.14 | Secure disposal or re-use of equipment | A.7 Physical controls | Yes | Risk treatment | R-01 | Old laptops and drives may still hold customer data. | Planned | Us and a supplier | IT Operations Manager | Gap in the ISMS Gap & Remediation Tracker: Disposal of laptops and drives is done by a supplier without certificates. | OK | |||||
| EXAMPLE | A.8.1 | User endpoint devices | A.8 Technological controls | Yes | Risk treatment | R-02, R-08 | Staff devices reach customer data and the platform. | Implemented | Us | AUP-001 Acceptable Use Policy; device management with compliance-based access | Head of IT | Evidence library, folder A.8.1 | OK | ||||
| EXAMPLE | A.8.2 | Privileged access rights | A.8 Technological controls | Yes | Risk treatment | R-01, R-07 | Platform administrators can reach all customer data. | Implemented | Us | ACP-001 Access Control Policy; time-limited admin roles; reviews every 3 months | Head of IT | Evidence library, folder A.8.2 | OK | ||||
| EXAMPLE | A.8.3 | Information access restriction | A.8 Technological controls | Yes | Risk treatment | Contractual | R-01 | Customers' data must be separated from each other and from staff without a need. | Implemented | Us | ACP-001 Access Control Policy; tenant isolation in the platform | Head of IT | Evidence library, folder A.8.3 | OK | |||
| EXAMPLE | A.8.4 | Access to source code | A.8 Technological controls | Yes | Risk treatment | R-04, R-07 | The source code is the product. | Implemented | Us | Secure development and change management standard (PT-12); repository access by team, branch protection | Head of Engineering | Evidence library, folder A.8.4 | OK | ||||
| EXAMPLE | A.8.5 | Secure authentication | A.8 Technological controls | Yes | Risk treatment | R-01, R-10 | Multi-factor authentication stops most account takeovers. | Implemented | Us | ACP-001 Access Control Policy; single sign-on with multi-factor authentication for all systems | Head of IT | Evidence library, folder A.8.5 | OK | ||||
| EXAMPLE | A.8.6 | Capacity management | A.8 Technological controls | Yes | Risk treatment | Contractual | R-05 | Customer contracts set service levels the platform must meet. | Partly | Us and a supplier | Platform capacity dashboards watched by operations | IT Operations Manager | Evidence library, folder A.8.6 | Gap in the ISMS Gap & Remediation Tracker: Capacity is watched but no thresholds or forecast exist. | OK | ||
| EXAMPLE | A.8.7 | Protection against malware | A.8 Technological controls | Yes | Risk treatment | R-02 | Malware is the usual start of ransomware. | Implemented | Us | Endpoint protection on all devices and servers | Head of IT | Evidence library, folder A.8.7 | OK | ||||
| EXAMPLE | A.8.8 | Management of technical vulnerabilities | A.8 Technological controls | Yes | Risk treatment | R-03 | Unpatched vulnerabilities are a leading cause of breaches. | Implemented | Us | VMS-001 Vulnerability & Exposure Management Standard | Head of IT | Evidence library, folder A.8.8 | OK | ||||
| EXAMPLE | A.8.9 | Configuration management | A.8 Technological controls | Yes | Risk treatment | R-04 | Misconfiguration of cloud services exposes customer data. | Planned | Us | Head of IT | Gap in the ISMS Gap & Remediation Tracker: No approved baseline configurations for servers, laptops or cloud services. | OK | |||||
| EXAMPLE | A.8.10 | Information deletion | A.8 Technological controls | Yes | Legal or regulatory | Contractual | R-11 | Customer data must be deleted at contract end and personal data when no longer needed. | Planned | Us | IT Operations Manager | Gap in the ISMS Gap & Remediation Tracker: Customer data is not deleted on a set schedule after contracts end. | OK | ||||
| EXAMPLE | A.8.11 | Data masking | A.8 Technological controls | Yes | Legal or regulatory | R-01, R-11 | Personal data copied for testing and support must not be exposed. | Not implemented | Us | Head of Engineering | Gap in the ISMS Gap & Remediation Tracker: Production data is copied to test without masking. | OK | |||||
| EXAMPLE | A.8.12 | Data leakage prevention | A.8 Technological controls | Yes | Risk treatment | R-01 | Customer data could be shared out by mistake or deliberately. | Not implemented | Us | Head of IT | Gap in the ISMS Gap & Remediation Tracker: No controls to detect data leaving through email, storage or endpoints. | OK | |||||
| EXAMPLE | A.8.13 | Information backup | A.8 Technological controls | Yes | Risk treatment | Contractual | R-02, R-09 | Recovery from ransomware or corruption depends on backups. | Implemented | Us and a supplier | BKP-001 Backup Standard (review overdue); immutable copies in a second region | IT Operations Manager | Evidence library, folder A.8.13 | OK | |||
| EXAMPLE | A.8.14 | Redundancy of information processing facilities | A.8 Technological controls | Yes | Risk treatment | Contractual | R-05 | Customer contracts promise high availability. | Implemented | Us and a supplier | Platform runs across three availability zones with tested failover | IT Operations Manager | Evidence library, folder A.8.14 | OK | |||
| EXAMPLE | A.8.15 | Logging | A.8 Technological controls | Yes | Risk treatment | Legal or regulatory | R-02, R-07 | Logs are needed to detect and investigate incidents and report them. | Implemented | Us | Central log store administrators cannot alter; 12-month retention | Head of IT | Evidence library, folder A.8.15 | OK | |||
| EXAMPLE | A.8.16 | Monitoring activities | A.8 Technological controls | Yes | Risk treatment | R-02, R-07 | Attacks must be spotted while they can still be stopped. | Partly | Us | Logs collected centrally from the platform and devices | Head of IT | Evidence library, folder A.8.16 | Gap in the ISMS Gap & Remediation Tracker: Logs are collected but not monitored for anomalies. | OK | |||
| EXAMPLE | A.8.17 | Clock synchronization | A.8 Technological controls | Yes | Risk treatment | R-02 | Investigations need consistent timestamps. | Implemented | Us | All systems use the cloud provider's time service | IT Operations Manager | Evidence library, folder A.8.17 | OK | ||||
| EXAMPLE | A.8.18 | Use of privileged utility programs | A.8 Technological controls | Yes | Risk treatment | R-07 | Admin tools could bypass controls. | Planned | Us | Head of IT | Gap in the ISMS Gap & Remediation Tracker: Use of privileged utility programs is not restricted. | OK | |||||
| EXAMPLE | A.8.19 | Installation of software on operational systems | A.8 Technological controls | Yes | Risk treatment | R-02, R-04 | Unapproved software on servers or devices brings malware and change risk. | Implemented | Us | Software installed only from the managed catalogue; platform changes only through the pipeline | Head of IT | Evidence library, folder A.8.19 | OK | ||||
| EXAMPLE | A.8.20 | Networks security | A.8 Technological controls | Yes | Risk treatment | R-01, R-02 | The platform network and office networks must be protected. | Implemented | Us and a supplier | Cloud network security groups as code; office firewall managed by IT | Head of IT | Evidence library, folder A.8.20 | OK | ||||
| EXAMPLE | A.8.21 | Security of network services | A.8 Technological controls | Yes | Risk treatment | R-05 | The service depends on the provider's network and on DNS. | Implemented | Us and a supplier | Service agreements with the cloud and connectivity providers; DNS in the company's own account | Head of IT | Evidence library, folder A.8.21 | OK | ||||
| EXAMPLE | A.8.22 | Segregation of networks | A.8 Technological controls | Yes | Risk treatment | R-01, R-02 | Separation limits how far an attack can spread. | Implemented | Us | Separate production, staging and corporate networks; guest wireless isolated | Head of IT | Evidence library, folder A.8.22 | OK | ||||
| EXAMPLE | A.8.23 | Web filtering | A.8 Technological controls | Yes | Risk treatment | R-02, R-10 | Malicious sites are a common route for malware and phishing. | Partly | Us | Web filtering on the office networks | Head of IT | Evidence library, folder A.8.23 | Gap in the ISMS Gap & Remediation Tracker: Web filtering is on in the offices only, not on remote devices. | OK | |||
| EXAMPLE | A.8.24 | Use of cryptography | A.8 Technological controls | Yes | Risk treatment | Contractual | R-01 | Customer contracts require encryption in transit and at rest. | Implemented | Us and a supplier | Cryptography and key management standard (PT-10); provider key management service | Head of IT | Evidence library, folder A.8.24 | OK | |||
| EXAMPLE | A.8.25 | Secure development life cycle | A.8 Technological controls | Yes | Risk treatment | R-04 | The company develops the software it sells. | Implemented | Us | Secure development and change management standard (PT-12) | Head of Engineering | Evidence library, folder A.8.25 | OK | ||||
| EXAMPLE | A.8.26 | Application security requirements | A.8 Technological controls | Yes | Risk treatment | Contractual | R-04 | Customer security requirements must be designed into features. | Planned | Us | Head of Engineering | Gap in the ISMS Gap & Remediation Tracker: Security requirements are not written into feature specifications. | OK | ||||
| EXAMPLE | A.8.27 | Secure system architecture and engineering principles | A.8 Technological controls | Yes | Risk treatment | R-04 | Secure design principles must guide the platform architecture. | Planned | Us | Head of Engineering | Gap in the ISMS Gap & Remediation Tracker: Architecture principles for security are not written down. | OK | |||||
| EXAMPLE | A.8.28 | Secure coding | A.8 Technological controls | Yes | Risk treatment | R-03, R-04 | Coding flaws become customer-facing vulnerabilities. | Implemented | Us | Secure development and change management standard (PT-12); code and dependency scanning; peer review | Head of Engineering | Evidence library, folder A.8.28 | OK | ||||
| EXAMPLE | A.8.29 | Security testing in development and acceptance | A.8 Technological controls | Yes | Risk treatment | Contractual | R-04 | Customers ask for annual independent penetration testing. | Implemented | Us and a supplier | Security tests in the pipeline; annual external penetration test | Head of Engineering | Evidence library, folder A.8.29 | OK | |||
| EXAMPLE | A.8.30 | Outsourced development | A.8 Technological controls | No | Activity not carried out within the scope | All software is developed by the company's own staff; no development is outsourced. Revisit if a contractor or agency writes code. The risk assessment (ISMS-07) found no risk this control would treat. | OK | ||||||||||
| EXAMPLE | A.8.31 | Separation of development, test and production environments | A.8 Technological controls | Yes | Risk treatment | R-04 | Development must not touch production or its data. | Implemented | Us | Secure development and change management standard (PT-12); separate cloud accounts per environment | Head of Engineering | Evidence library, folder A.8.31 | OK | ||||
| EXAMPLE | A.8.32 | Change management | A.8 Technological controls | Yes | Risk treatment | R-04, R-05 | Unmanaged changes cause outages and security gaps. | Implemented | Us | Secure development and change management standard (PT-12); every change through the pipeline with approval | Head of Engineering | Evidence library, folder A.8.32 | OK | ||||
| EXAMPLE | A.8.33 | Test information | A.8 Technological controls | Yes | Legal or regulatory | R-01, R-11 | Test environments must not hold unprotected personal data. | Planned | Us | Head of Engineering | Gap in the ISMS Gap & Remediation Tracker: No rules for selecting and protecting test data. | OK | |||||
| EXAMPLE | A.8.34 | Protection of information systems during audit testing | A.8 Technological controls | Yes | Risk treatment | R-05 | Penetration tests and audits must not disrupt the live service. | Implemented | Us | Test scope and timing agreed in writing; tester accounts removed at the end | Head of IT | Evidence library, folder A.8.34 | OK |
Wording Guide
Weak justifications and wording that withstands challenge, side by side. The defensible wording is EXAMPLE wording from the worked example; [[double brackets]] mark what you fill in where it has no such case.
| Decision | Weak — will be challenged | Withstands challenge | Why it works |
|---|---|---|---|
| Exclusion | N/A | A.8.30, Activity not carried out within the scope: "All software is developed by the company's own staff; no development is outsourced. Revisit if a contractor or agency writes code. The risk assessment (ISMS-07) found no risk this control would treat." | It names the fact about the scope, links it to the risk assessment, and says what would change the decision. |
| Exclusion | Not applicable — we are in the cloud | Do not exclude. A.7.11 is applicable, delivered by: Supplier. Justification: "The platform depends on the data centres' power and cooling." How: "Provider's assurance report; the offices hold no equipment that must run through an outage." | Physical controls at a provider are still needed; the provider carries them out. Excluding them tells the auditor you have not thought about where your data is. |
| Exclusion | Not relevant to our business | Outside the ISMS scope: "[[The activity or site]] is outside the ISMS scope ([[scope statement, version and section]]); [[how the interface to it is controlled, for example by supplier controls]]." | An exclusion by scope points to the scope statement, which itself justifies the boundary (IS-02). |
| Inclusion | Required by ISO | A.8.2, Risk treatment, R-01, R-07: "Platform administrators can reach all customer data." | Annex A requires nothing by itself: controls are chosen to treat risks (IS-03). Name the risks, the law or the contract. |
| Inclusion | Best practice | A.8.24, Contractual: "Customer contracts require encryption in transit and at rest." | Say whose requirement it is and where it is written. |
| Inclusion | Implemented | A.8.5, status Implemented. How: "ACP-001 Access Control Policy; single sign-on with multi-factor authentication for all systems." Evidence: "Evidence library, folder A.8.5." | Status alone is not evidence: name the document or system that implements it and where an auditor can see it working. |
Summary
SoA summary
Calculated from the Statement of Applicability sheet (Your SoA) and the Worked Example sheet (EXAMPLE). Take the counts to management review with the approved SoA.
Decisions and implementation status
| Measure | Your SoA | EXAMPLE | What it means | |||
|---|---|---|---|---|---|---|
| Controls listed | 93 | 93 | All 93 must be listed. | |||
| Applicable | 0 | 92 | Controls included, each with a reason. | |||
| Excluded | 0 | 1 | Controls excluded, each justified from the risk assessment and scope. | |||
| No decision yet | 93 | 0 | Must be zero before approval. | |||
| Applicable — implemented | 0 | 64 | Implemented and producing evidence. | |||
| Applicable — partly | 0 | 7 | ||||
| Applicable — planned | 0 | 18 | ||||
| Applicable — not implemented | 0 | 3 | Applicable but not started: each needs a gap with an owner and a date (IS-08). | |||
| Applicable — no status yet | 0 | 0 | ||||
| Share of applicable controls implemented | 70% | The Certification Readiness Self-Assessment measures readiness in more depth. | ||||
| Applicable — delivered wholly or partly by a supplier | 0 | 22 | Check each is covered by a contract and supplier monitoring (A.5.19 to A.5.22). | |||
| Exclusions flagged as weak or too short | 0 | 0 | Rewrite before approval (IS-03). | |||
| Rows with a check to resolve | 93 | 0 | Must be zero before approval. | |||
By theme
| Theme | Controls | Your SoA: applicable | Your SoA: excluded | Your SoA: implemented | EXAMPLE: applicable | EXAMPLE: excluded | EXAMPLE: implemented |
|---|---|---|---|---|---|---|---|
| A.5 Organizational controls | 37 | 0 | 0 | 0 | 37 | 0 | 24 |
| A.6 People controls | 8 | 0 | 0 | 0 | 8 | 0 | 7 |
| A.7 Physical controls | 14 | 0 | 0 | 0 | 14 | 0 | 11 |
| A.8 Technological controls | 34 | 0 | 0 | 0 | 33 | 1 | 22 |
| All themes | 93 | 0 | 0 | 0 | 92 | 1 | 64 |
The EXAMPLE figures are the worked example as at 2026-09-30. Delete the Worked Example sheet before approval, then delete the EXAMPLE columns here.
Lists
| Applicable | InclusionReason | ImplementationStatus | DeliveredBy | ExclusionReason | WeakPhrase | MinExclusionWords |
|---|---|---|---|---|---|---|
| Yes | Risk treatment | Implemented | Us | Activity not carried out within the scope | n/a | 12 |
| No | Legal or regulatory | Partly | Supplier | Risk assessment found no risk the control would treat | na | |
| Contractual | Planned | Us and a supplier | Outside the ISMS scope | not applicable | ||
| Business requirement | Not implemented | not relevant |
does not apply
not needed
not required
none
no
-
—
tbc
tbd
see scope
WeakPhrase: an exclusion justification made only of one of these is flagged. MinExclusionWords: fewer words than this is flagged as too short. Change either here.
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Statement of Applicability (SoA) | The record of which Annex A controls the organisation needs, why each is included, whether it is implemented, and why any is excluded (clause 6.1.3). An auditor reads it first and tests it throughout. |
| Applicable | The control is needed: it treats a risk from the risk assessment, or a law, contract or business need requires it. A control a supplier carries out for you is applicable. |
| Excluded | The control is not needed, because the activity it addresses does not happen within scope or the risk assessment found no risk it would treat. The justification must say which, and why. |
| Reason — Risk treatment | The control treats one or more risks in the risk register; name them in Risk IDs treated. |
| Reason — Legal or regulatory | A law or regulation requires it, such as data protection or cyber-security law that applies to you. |
| Reason — Contractual | A customer or partner contract requires it. |
| Reason — Business requirement | Top management or the business requires it for a reason not captured above, such as a customer expectation or group policy. |
| Exclusion — Activity not carried out within the scope | The control addresses an activity the organisation does not carry out within the scope, such as outsourced development when none is outsourced. |
| Exclusion — Risk assessment found no risk the control would treat | The risk assessment was done and no risk needs this control. Point to the assessment. |
| Exclusion — Outside the ISMS scope | The activity or asset is outside the scope set by the scope statement, which justifies the boundary (IS-02). |
| Implemented | In place and operating, with records an auditor could sample. |
| Partly | Some of the control is in place; the rest is on the gap tracker with an owner and a date. |
| Planned | Not yet in place; the work has an owner and a date. |
| Not implemented | Applicable, but no work has started. Raise a gap in the ISMS Gap & Remediation Tracker (IS-08). |
| Delivered by | Us, Supplier, Us and a supplier. Who carries out the control day to day. Accountability stays with you whichever you choose. |
| Risk IDs | The references of the risks, in your risk register, that the control treats. |
| R-01 (EXAMPLE) | Customer data exposed through a compromised staff or administrator account. A risk in the example organisation's register. |
| R-02 (EXAMPLE) | Ransomware or a destructive attack on the cloud platform or staff devices. A risk in the example organisation's register. |
| R-03 (EXAMPLE) | An exploitable vulnerability in the platform or its software dependencies. A risk in the example organisation's register. |
| R-04 (EXAMPLE) | Insecure code or configuration released to customers. A risk in the example organisation's register. |
| R-05 (EXAMPLE) | Prolonged outage of the cloud platform or another critical supplier. A risk in the example organisation's register. |
| R-06 (EXAMPLE) | A security failure at a supplier with access to customer data. A risk in the example organisation's register. |
| R-07 (EXAMPLE) | Misuse of privileged access by an insider. A risk in the example organisation's register. |
| R-08 (EXAMPLE) | A laptop or phone with company data lost or stolen. A risk in the example organisation's register. |
| R-09 (EXAMPLE) | Customer or company data lost, corrupted or unrecoverable. A risk in the example organisation's register. |
| R-10 (EXAMPLE) | Phishing or social engineering leading to fraud or account takeover. A risk in the example organisation's register. |
| R-11 (EXAMPLE) | Failure to meet legal, regulatory or contractual security obligations, including incident reporting. A risk in the example organisation's register. |
| R-12 (EXAMPLE) | Unauthorised physical access to the offices or the equipment in them. A risk in the example organisation's register. |
| Evidence reference | Where an auditor can see the control working: a folder, a system report or a record ID. |
| Controlled documented information | A document kept under control: identified, reviewed, approved, versioned, distributed to those who need it, and kept when superseded (clause 7.5.3). |
| Check (calc) | The first missing or inconsistent item on the row. OK means the row is complete. |
| EXAMPLE | A worked example: a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30. Delete before approval. |
| IS-nn | Rule numbers in the ISO 27001 Implementation Methodology & Project Plan. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 6.1.3 — Information security risk treatment | The Statement of Applicability as a whole: the necessary controls, the justification for each inclusion and exclusion, and whether each is implemented |
| ISO/IEC 27001:2022 | Clause 6.1.2 — Information security risk assessment | Risk IDs treated and the SoA Approval basis: every inclusion or risk-based exclusion traced to the risk assessment |
| ISO/IEC 27001:2022 | Clause 7.5.3 — Control of documented information | SoA Approval: version, approval, distribution and retention of superseded versions |
| NIST CSF 2.0 | GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed” | Legal or regulatory and Contractual reasons for inclusion: requirements understood and traced to controls |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0