Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Statement of Applicability Template

Produces a complete, defensible SoA with justification wording that withstands auditor challenge on both inclusion and exclusion.

Available soon

Format
Excel
Size
97 KB
Length
12 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • SoA Approval
  • Statement of Applicability
  • Worked Example
  • Wording Guide
  • Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Start from your risk assessment and risk treatment plan (clauses 6.1.2 and 6.1.3) and your ISMS scope (clause 4.3, IS-02). The SoA records the result of risk treatment; it does not replace it. Controls must be chosen from the risk assessment, not from the Annex A list; the Statement of Applicability must justify every inclusion and exclusion. (IS-03)
2On the Statement of Applicability sheet, all 93 controls are listed in Annex A order. Keep every row: a control missing from the SoA is a finding. For each control choose Applicable? Yes or No. The Annex A Control Implementation Library explains each control and, for those that depend on scope, the question that decides.
3For each control that applies: choose the main reason (Risk treatment, Legal or regulatory, Contractual, Business requirement) and, if there is a second, Also required by. Where risk treatment is a reason, list the risk IDs from your risk register. Write one sentence of justification: what the control protects against, or which law or contract requires it.
4Then record the implementation status (Implemented, Partly, Planned, Not implemented), who delivers it (Us, Supplier, Us and a supplier), how it is implemented — name the policy, procedure or system — the owner, and an evidence reference for anything implemented. A control carried out by a supplier is applicable and "Delivered by: Supplier"; it is not an exclusion.
5For each control that does not apply: choose the exclusion reason type (Activity not carried out within the scope; Risk assessment found no risk the control would treat; Outside the ISMS scope) and write a justification of at least 12 words that follows from your risk assessment and scope, and says what would make you revisit it. "N/A", "not applicable" or "not relevant" on their own are flagged: they will not withstand an auditor's challenge. The Wording Guide sheet shows weak and defensible wording side by side.
6Clear every Check that does not say OK. Each row shows only its first unresolved item; clear it and the next, if any, appears.
7Complete the SoA Approval sheet: the version, the risk assessment, treatment plan and scope it rests on, and approval by e.g. Executive Committee. The SoA is controlled documented information (clause 7.5.3, IS-04): keep superseded versions, and do not change a decision without re-approval.
8From the start of Phase 4 update the status columns at least monthly (IS-10), and review every decision when the risk assessment, the scope or the organisation changes, and at least every 12 months. The certification body asks for the SoA at Stage 1 and samples its controls at Stage 2; see the Stage 1 and Stage 2 Audit Preparation Guide.
9Delete the Worked Example sheet and the EXAMPLE column on the SoA Approval sheet before the SoA is approved. Do not type over the white calculated column.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

EXAMPLE: a software services company with 240 staff in two offices, an NIS2 important entity, preparing for its first certification (Stage 2 on 2027-03-01). Its scope: the design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. Statuses are as at 2026-09-30 (EXAMPLE date; in your SoA, use the date of your update).

In the EXAMPLE, references such as ISP-001 are documents in the example organisation's policy register (the Security Policy Management pack). A reference such as (PT-12) is its document on that policy topic, not in the register extract. Risk IDs R-01 to R-12 are its risk register (see the Definitions sheet); your risk method and register may come from the Information Security Risk Management pack.

In the EXAMPLE, 92 controls apply and 1 is excluded (A.8.30 Outsourced development: no development is contracted out). Physical controls in the cloud provider's data centres are applicable and delivered by the supplier, not excluded. An SoA with many exclusions is usually a sign that controls were dropped for convenience.

Tailoring — small organisation: most controls still apply; keep the justification to one sentence and implement proportionately. Exclude only where the activity genuinely does not happen in scope.

Tailoring — regulated entity: ISO/IEC 27001:2022 is the requirement for certification. Where a law such as NIS2 or DORA requires a control, choose Legal or regulatory as a reason; do not exclude a control the law requires. Certification is evidence for a regulator, not compliance with the law.

Tailoring — IT run by a service provider: record each control the provider runs as Delivered by: Supplier or Us and a supplier, with the contract or the provider's certificate as how it is implemented. Check that the provider's certificate covers the service you buy.

SoA Approval

Statement of Applicability — version and approval

The SoA is controlled documented information (clause 7.5.3). Record what it rests on and who approved it. Delete the EXAMPLE column before approval.

ItemYour SoAEXAMPLEGuidance
SoA version[[1.0]]ISMS-03, version 1.1 — statuses updated; decisions unchanged since 1.0Increase the minor version for a status update, the major version when a decision changes.
Status[[Draft / Approved / Superseded]]ApprovedOnly an approved SoA is presented to the certification body.
ISMS scope it covers (document and version)[[e.g. ISMS Scope Statement v1.0]]ISMS-01 ISMS Scope Statement, approved 2026-05-11: the design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run onThe SoA covers the whole scope and nothing outside it (IS-02).
Risk assessment it is based on (version, date)[[e.g. Risk assessment v1.0, YYYY-MM-DD]]ISMS-07 Information Security Risk Register, approved 2026-07-20, assessed with ISMS-02 Risk Management MethodologyEvery Risk ID in the SoA comes from this assessment. A new assessment means reviewing the SoA.
Risk treatment plan (version, date)[[e.g. Risk treatment plan v1.0, YYYY-MM-DD]]ISMS-04 Risk Treatment Plan, approved 2026-08-24 with the risk owners' acceptance of residual riskRisk owners approve the plan and accept the residual risk (clause 6.1.3).
Implementation status as at[[YYYY-MM-DD]]2026-09-30The date the status columns were last updated. EXAMPLE date: replace it with the date of your update.
Prepared by (name, role)[[Name, ISMS manager]]Head of Information Security (the ISMS manager)
Decisions approved by (name, role)[[e.g. Executive Committee]]Executive CommitteeTop management approves the decisions, not only the ISMS manager (IS-01).
Date decisions were approved[[YYYY-MM-DD]]2026-08-24 (version 1.0)A change to any Applicable? decision needs a new approval.
Next review[[YYYY-MM-DD — at least every 12 months, and after a change to the risk assessment or scope]]Before the Stage 1 audit on 2027-01-18, then every 12 months
Where it is kept and who may see it[[e.g. ISMS document library; shared with the certification body, and with customers under a confidentiality agreement]]ISMS document library; shared with the certification body, and with customers under a confidentiality agreementThe SoA describes your defences: classify and share it accordingly.

EXAMPLE references and dates are the example organisation's ISMS documents (ISMS-01, ISMS-02, ISMS-07, ISMS-04, ISMS-03), as the Mandatory ISMS Documentation Checklist lists them.

Statement of Applicability

All 93 Annex A controls. Yellow columns are yours; Check calculates. Keep every row: decide each one Yes or No, with the reason.

ControlControl title (ISO/IEC 27001:2022)ThemeApplicable?Main reason for inclusionAlso required byRisk IDs treatedJustification for inclusionImplementation statusDelivered byHow it is implemented (policy, procedure or system)OwnerEvidence referenceExclusion reason typeJustification for exclusionNotesCheck (calc)
A.5.1Policies for information securityA.5 Organizational controlsDecide: applicable Yes or No
A.5.2Information security roles and responsibilitiesA.5 Organizational controlsDecide: applicable Yes or No
A.5.3Segregation of dutiesA.5 Organizational controlsDecide: applicable Yes or No
A.5.4Management responsibilitiesA.5 Organizational controlsDecide: applicable Yes or No
A.5.5Contact with authoritiesA.5 Organizational controlsDecide: applicable Yes or No
A.5.6Contact with special interest groupsA.5 Organizational controlsDecide: applicable Yes or No
A.5.7Threat intelligenceA.5 Organizational controlsDecide: applicable Yes or No
A.5.8Information security in project managementA.5 Organizational controlsDecide: applicable Yes or No
A.5.9Inventory of information and other associated assetsA.5 Organizational controlsDecide: applicable Yes or No
A.5.10Acceptable use of information and other associated assetsA.5 Organizational controlsDecide: applicable Yes or No
A.5.11Return of assetsA.5 Organizational controlsDecide: applicable Yes or No
A.5.12Classification of informationA.5 Organizational controlsDecide: applicable Yes or No
A.5.13Labelling of informationA.5 Organizational controlsDecide: applicable Yes or No
A.5.14Information transferA.5 Organizational controlsDecide: applicable Yes or No
A.5.15Access controlA.5 Organizational controlsDecide: applicable Yes or No
A.5.16Identity managementA.5 Organizational controlsDecide: applicable Yes or No
A.5.17Authentication informationA.5 Organizational controlsDecide: applicable Yes or No
A.5.18Access rightsA.5 Organizational controlsDecide: applicable Yes or No
A.5.19Information security in supplier relationshipsA.5 Organizational controlsDecide: applicable Yes or No
A.5.20Addressing information security within supplier agreementsA.5 Organizational controlsDecide: applicable Yes or No
A.5.21Managing information security in the ICT supply chainA.5 Organizational controlsDecide: applicable Yes or No
A.5.22Monitoring, review and change management of supplier servicesA.5 Organizational controlsDecide: applicable Yes or No
A.5.23Information security for use of cloud servicesA.5 Organizational controlsDecide: applicable Yes or No
A.5.24Information security incident management planning and preparationA.5 Organizational controlsDecide: applicable Yes or No
A.5.25Assessment and decision on information security eventsA.5 Organizational controlsDecide: applicable Yes or No
A.5.26Response to information security incidentsA.5 Organizational controlsDecide: applicable Yes or No
A.5.27Learning from information security incidentsA.5 Organizational controlsDecide: applicable Yes or No
A.5.28Collection of evidenceA.5 Organizational controlsDecide: applicable Yes or No
A.5.29Information security during disruptionA.5 Organizational controlsDecide: applicable Yes or No
A.5.30ICT readiness for business continuityA.5 Organizational controlsDecide: applicable Yes or No
A.5.31Legal, statutory, regulatory and contractual requirementsA.5 Organizational controlsDecide: applicable Yes or No
A.5.32Intellectual property rightsA.5 Organizational controlsDecide: applicable Yes or No
A.5.33Protection of recordsA.5 Organizational controlsDecide: applicable Yes or No
A.5.34Privacy and protection of PIIA.5 Organizational controlsDecide: applicable Yes or No
A.5.35Independent review of information securityA.5 Organizational controlsDecide: applicable Yes or No
A.5.36Compliance with policies, rules and standards for information securityA.5 Organizational controlsDecide: applicable Yes or No
A.5.37Documented operating proceduresA.5 Organizational controlsDecide: applicable Yes or No
A.6.1ScreeningA.6 People controlsDecide: applicable Yes or No
A.6.2Terms and conditions of employmentA.6 People controlsDecide: applicable Yes or No
A.6.3Information security awareness, education and trainingA.6 People controlsDecide: applicable Yes or No
A.6.4Disciplinary processA.6 People controlsDecide: applicable Yes or No
A.6.5Responsibilities after termination or change of employmentA.6 People controlsDecide: applicable Yes or No
A.6.6Confidentiality or non-disclosure agreementsA.6 People controlsDecide: applicable Yes or No
A.6.7Remote workingA.6 People controlsDecide: applicable Yes or No
A.6.8Information security event reportingA.6 People controlsDecide: applicable Yes or No
A.7.1Physical security perimetersA.7 Physical controlsDecide: applicable Yes or No
A.7.2Physical entryA.7 Physical controlsDecide: applicable Yes or No
A.7.3Securing offices, rooms and facilitiesA.7 Physical controlsDecide: applicable Yes or No
A.7.4Physical security monitoringA.7 Physical controlsDecide: applicable Yes or No
A.7.5Protecting against physical and environmental threatsA.7 Physical controlsDecide: applicable Yes or No
A.7.6Working in secure areasA.7 Physical controlsDecide: applicable Yes or No
A.7.7Clear desk and clear screenA.7 Physical controlsDecide: applicable Yes or No
A.7.8Equipment siting and protectionA.7 Physical controlsDecide: applicable Yes or No
A.7.9Security of assets off-premisesA.7 Physical controlsDecide: applicable Yes or No
A.7.10Storage mediaA.7 Physical controlsDecide: applicable Yes or No
A.7.11Supporting utilitiesA.7 Physical controlsDecide: applicable Yes or No
A.7.12Cabling securityA.7 Physical controlsDecide: applicable Yes or No
A.7.13Equipment maintenanceA.7 Physical controlsDecide: applicable Yes or No
A.7.14Secure disposal or re-use of equipmentA.7 Physical controlsDecide: applicable Yes or No
A.8.1User endpoint devicesA.8 Technological controlsDecide: applicable Yes or No
A.8.2Privileged access rightsA.8 Technological controlsDecide: applicable Yes or No
A.8.3Information access restrictionA.8 Technological controlsDecide: applicable Yes or No
A.8.4Access to source codeA.8 Technological controlsDecide: applicable Yes or No
A.8.5Secure authenticationA.8 Technological controlsDecide: applicable Yes or No
A.8.6Capacity managementA.8 Technological controlsDecide: applicable Yes or No
A.8.7Protection against malwareA.8 Technological controlsDecide: applicable Yes or No
A.8.8Management of technical vulnerabilitiesA.8 Technological controlsDecide: applicable Yes or No
A.8.9Configuration managementA.8 Technological controlsDecide: applicable Yes or No
A.8.10Information deletionA.8 Technological controlsDecide: applicable Yes or No
A.8.11Data maskingA.8 Technological controlsDecide: applicable Yes or No
A.8.12Data leakage preventionA.8 Technological controlsDecide: applicable Yes or No
A.8.13Information backupA.8 Technological controlsDecide: applicable Yes or No
A.8.14Redundancy of information processing facilitiesA.8 Technological controlsDecide: applicable Yes or No
A.8.15LoggingA.8 Technological controlsDecide: applicable Yes or No
A.8.16Monitoring activitiesA.8 Technological controlsDecide: applicable Yes or No
A.8.17Clock synchronizationA.8 Technological controlsDecide: applicable Yes or No
A.8.18Use of privileged utility programsA.8 Technological controlsDecide: applicable Yes or No
A.8.19Installation of software on operational systemsA.8 Technological controlsDecide: applicable Yes or No
A.8.20Networks securityA.8 Technological controlsDecide: applicable Yes or No
A.8.21Security of network servicesA.8 Technological controlsDecide: applicable Yes or No
A.8.22Segregation of networksA.8 Technological controlsDecide: applicable Yes or No
A.8.23Web filteringA.8 Technological controlsDecide: applicable Yes or No
A.8.24Use of cryptographyA.8 Technological controlsDecide: applicable Yes or No
A.8.25Secure development life cycleA.8 Technological controlsDecide: applicable Yes or No
A.8.26Application security requirementsA.8 Technological controlsDecide: applicable Yes or No
A.8.27Secure system architecture and engineering principlesA.8 Technological controlsDecide: applicable Yes or No
A.8.28Secure codingA.8 Technological controlsDecide: applicable Yes or No
A.8.29Security testing in development and acceptanceA.8 Technological controlsDecide: applicable Yes or No
A.8.30Outsourced developmentA.8 Technological controlsDecide: applicable Yes or No
A.8.31Separation of development, test and production environmentsA.8 Technological controlsDecide: applicable Yes or No
A.8.32Change managementA.8 Technological controlsDecide: applicable Yes or No
A.8.33Test informationA.8 Technological controlsDecide: applicable Yes or No
A.8.34Protection of information systems during audit testingA.8 Technological controlsDecide: applicable Yes or No

Worked Example

EXAMPLE: the example organisation's completed SoA, statuses as at 2026-09-30. Same columns as the Statement of Applicability sheet. Delete this sheet before approval.

ExampleControlControl title (ISO/IEC 27001:2022)ThemeApplicable?Main reason for inclusionAlso required byRisk IDs treatedJustification for inclusionImplementation statusDelivered byHow it is implemented (policy, procedure or system)OwnerEvidence referenceExclusion reason typeJustification for exclusionNotesCheck (calc)
EXAMPLEA.5.1Policies for information securityA.5 Organizational controlsYesBusiness requirementLegal or regulatoryThe ISMS needs an approved top policy; customers and the NIS2 duties of an important entity expect one.ImplementedUsISP-001 Information Security Policy; topic policies in the policy registerHead of Information SecurityEvidence library, folder A.5.1OK
EXAMPLEA.5.2Information security roles and responsibilitiesA.5 Organizational controlsYesBusiness requirementLegal or regulatoryEvery control needs an accountable owner; NIS2 expects management accountability.ImplementedUsISMS-06 ISMS Manual (processes, roles and responsibilities)Head of Information SecurityEvidence library, folder A.5.2OK
EXAMPLEA.5.3Segregation of dutiesA.5 Organizational controlsYesRisk treatmentR-07Separates requesting from approving access and developing from deploying code.ImplementedUsACP-001 Access Control Policy; code review enforced before mergeHead of ITEvidence library, folder A.5.3OK
EXAMPLEA.5.4Management responsibilitiesA.5 Organizational controlsYesBusiness requirementManagers must require their teams to follow the policies for any control to work.ImplementedUsISP-001 Information Security Policy; managers' objectives include training and access review completionChief Operating OfficerEvidence library, folder A.5.4OK
EXAMPLEA.5.5Contact with authoritiesA.5 Organizational controlsYesLegal or regulatoryR-11As an NIS2 important entity the company must be able to notify the national authority on time.PlannedUsHead of Information SecurityGap in the ISMS Gap & Remediation Tracker: No list of which authorities to contact, when, and who may do it.OK
EXAMPLEA.5.6Contact with special interest groupsA.5 Organizational controlsYesRisk treatmentR-03Early warning of vulnerabilities in the platform's technology stack.ImplementedUsMembership of a national software-sector information-sharing group; vendor security forumsHead of Information SecurityEvidence library, folder A.5.6OK
EXAMPLEA.5.7Threat intelligenceA.5 Organizational controlsYesRisk treatmentR-02, R-03Threat information tunes detection and patch priorities for the attacks the platform faces.PlannedUs and a supplierHead of Information SecurityGap in the ISMS Gap & Remediation Tracker: Threat information is read informally; nothing is recorded or acted on.OK
EXAMPLEA.5.8Information security in project managementA.5 Organizational controlsYesRisk treatmentR-04New product features and internal projects change data and systems; security is set at initiation.PlannedUsHead of EngineeringGap in the ISMS Gap & Remediation Tracker: Security is not a step in the project method.OK
EXAMPLEA.5.9Inventory of information and other associated assetsA.5 Organizational controlsYesRisk treatmentR-01, R-03Scanning, access and backup all depend on knowing what assets exist.ImplementedUsAsset management and information classification policy (PT-04); inventory built from device management and cloud accountsHead of ITEvidence library, folder A.5.9OK
EXAMPLEA.5.10Acceptable use of information and other associated assetsA.5 Organizational controlsYesRisk treatmentR-08, R-10Sets the rules staff follow with company data and devices.ImplementedUsAUP-001 Acceptable Use Policy (review overdue; being updated)Head of ITEvidence library, folder A.5.10OK
EXAMPLEA.5.11Return of assetsA.5 Organizational controlsYesRisk treatmentR-08Devices and access must come back at every exit.ImplementedUsJML-PRC Joiner, Mover, Leaver Procedure (leaver checklist)HR DirectorEvidence library, folder A.5.11OK
EXAMPLEA.5.12Classification of informationA.5 Organizational controlsYesContractualRisk treatmentR-01Customer contracts require customer data to be identified and handled as confidential.ImplementedUsAsset management and information classification policy (PT-04) (classification scheme)Head of Information SecurityEvidence library, folder A.5.12OK
EXAMPLEA.5.13Labelling of informationA.5 Organizational controlsYesContractualR-01Labels make customer data recognisable wherever it is handled.Not implementedUsHead of ITGap in the ISMS Gap & Remediation Tracker: No labelling of classified information.OK
EXAMPLEA.5.14Information transferA.5 Organizational controlsYesRisk treatmentContractualR-01Customer data is exchanged by file transfer and email; transfers must be protected.ImplementedUsAUP-001 Acceptable Use Policy; external sharing restricted in the collaboration suiteHead of Information SecurityEvidence library, folder A.5.14OK
EXAMPLEA.5.15Access controlA.5 Organizational controlsYesRisk treatmentR-01, R-07Access to the platform and customer data must follow need-to-know.ImplementedUsACP-001 Access Control PolicyHead of ITEvidence library, folder A.5.15OK
EXAMPLEA.5.16Identity managementA.5 Organizational controlsYesRisk treatmentR-01One identity per person, created only from an HR trigger.ImplementedUsACP-001 Access Control Policy; JML-PRC Joiner, Mover, Leaver ProcedureHead of ITEvidence library, folder A.5.16OK
EXAMPLEA.5.17Authentication informationA.5 Organizational controlsYesRisk treatmentR-01, R-10Stolen credentials are the main route to customer data.ImplementedUsACP-001 Access Control Policy; company password managerHead of ITEvidence library, folder A.5.17OK
EXAMPLEA.5.18Access rightsA.5 Organizational controlsYesRisk treatmentLegal or regulatoryR-01, R-07Access must be granted on approval, changed on moves and reviewed.ImplementedUsACP-001 Access Control Policy; JML-PRC Joiner, Mover, Leaver Procedure; quarterly access reviews (User Access Review pack)Head of ITEvidence library, folder A.5.18OK
EXAMPLEA.5.19Information security in supplier relationshipsA.5 Organizational controlsYesRisk treatmentLegal or regulatoryR-05, R-06The platform depends on a cloud provider and several software-as-a-service suppliers.PartlyUsSUP-001 Supplier Security Policy drafted and with its approver; supplier register kept by ProcurementHead of ProcurementEvidence library, folder A.5.19Gap in the ISMS Gap & Remediation Tracker: The Supplier Security Policy (P04 register SUP-001) is awaiting approval; supplier tiers not yet applied.OK
EXAMPLEA.5.20Addressing information security within supplier agreementsA.5 Organizational controlsYesRisk treatmentContractualR-06Supplier security duties must be in the contracts to be enforceable.PartlyUsSecurity clauses in the newest supplier contracts; the rest at renewalHead of ProcurementEvidence library, folder A.5.20Gap in the ISMS Gap & Remediation Tracker: Security clauses are missing from most key supplier contracts.OK
EXAMPLEA.5.21Managing information security in the ICT supply chainA.5 Organizational controlsYesRisk treatmentR-03, R-06Open-source components and the cloud provider's own suppliers are part of the product's supply chain.PlannedUsHead of ProcurementGap in the ISMS Gap & Remediation Tracker: No check of the security of the software and cloud supply chain.OK
EXAMPLEA.5.22Monitoring, review and change management of supplier servicesA.5 Organizational controlsYesRisk treatmentR-05, R-06Supplier assurance must be kept current.PlannedUsHead of ProcurementGap in the ISMS Gap & Remediation Tracker: Supplier performance and changes are not reviewed for security.OK
EXAMPLEA.5.23Information security for use of cloud servicesA.5 Organizational controlsYesRisk treatmentContractualR-05, R-06The whole service runs on one cloud provider under shared responsibility.ImplementedUs and a supplierCloud responsibility matrix; configuration baseline for the provider's services; provider's certificate and assurance report reviewedHead of ITEvidence library, folder A.5.23OK
EXAMPLEA.5.24Information security incident management planning and preparationA.5 Organizational controlsYesRisk treatmentLegal or regulatoryR-02, R-11Incident readiness is needed for the platform and for NIS2 reporting deadlines.ImplementedUsINC-001 Incident Management PolicyHead of Information SecurityEvidence library, folder A.5.24OK
EXAMPLEA.5.25Assessment and decision on information security eventsA.5 Organizational controlsYesRisk treatmentR-02, R-11Events must be classified quickly to meet reporting deadlines.ImplementedUsINC-001 Incident Management Policy (severity criteria)Head of Information SecurityEvidence library, folder A.5.25OK
EXAMPLEA.5.26Response to information security incidentsA.5 Organizational controlsYesRisk treatmentLegal or regulatoryR-02, R-11Incidents on the platform must be contained and notified on time.ImplementedUs and a supplierINC-001 Incident Management Policy; managed security provider retained for responseHead of Information SecurityEvidence library, folder A.5.26OK
EXAMPLEA.5.27Learning from information security incidentsA.5 Organizational controlsYesRisk treatmentR-02Lessons from incidents feed the risk assessment.ImplementedUsINC-001 Incident Management Policy (post-incident review)Head of Information SecurityEvidence library, folder A.5.27OK
EXAMPLEA.5.28Collection of evidenceA.5 Organizational controlsYesLegal or regulatoryR-11Evidence may be needed for regulators, customers or legal action.PlannedUs and a supplierLegal CounselGap in the ISMS Gap & Remediation Tracker: No agreed way to collect and preserve evidence from an incident.OK
EXAMPLEA.5.29Information security during disruptionA.5 Organizational controlsYesRisk treatmentR-05Security must hold during a platform or office disruption.ImplementedUsBusiness continuity and ICT resilience policy (PT-16) (security during disruption, emergency access)IT Operations ManagerEvidence library, folder A.5.29OK
EXAMPLEA.5.30ICT readiness for business continuityA.5 Organizational controlsYesRisk treatmentContractualR-05, R-09Customer contracts set availability and recovery commitments.PartlyUs and a supplierBusiness continuity and ICT resilience policy (PT-16); recovery objectives set for the platformIT Operations ManagerEvidence library, folder A.5.30Gap in the ISMS Gap & Remediation Tracker: Recovery objectives are set but the platform's recovery has not been tested.OK
EXAMPLEA.5.31Legal, statutory, regulatory and contractual requirementsA.5 Organizational controlsYesLegal or regulatoryContractualR-11NIS2, data protection law and customer security schedules apply to the service.PlannedUsLegal CounselGap in the ISMS Gap & Remediation Tracker: No register of legal, regulatory and contractual security requirements.OK
EXAMPLEA.5.32Intellectual property rightsA.5 Organizational controlsYesLegal or regulatoryR-11The product includes third-party and open-source code under licence.ImplementedUsLicence register; open-source licence checks in the build pipelineLegal CounselEvidence library, folder A.5.32OK
EXAMPLEA.5.33Protection of recordsA.5 Organizational controlsYesLegal or regulatoryR-11Financial, contractual, personnel and security records must be kept for set periods.PlannedUsLegal CounselGap in the ISMS Gap & Remediation Tracker: Retention periods are not set for security records.OK
EXAMPLEA.5.34Privacy and protection of PIIA.5 Organizational controlsYesLegal or regulatoryContractualR-01, R-11The company processes customers' personal data as a processor and staff data as a controller.ImplementedUsRecords of processing; privacy impact assessments; breach procedure linked to INC-001Legal CounselEvidence library, folder A.5.34OK
EXAMPLEA.5.35Independent review of information securityA.5 Organizational controlsYesBusiness requirementTop management wants an independent view of the ISMS, beyond the certification audit.PlannedUsChief Operating OfficerGap in the ISMS Gap & Remediation Tracker: No plan for independent review of the ISMS beyond the certification audit.OK
EXAMPLEA.5.36Compliance with policies, rules and standards for information securityA.5 Organizational controlsYesBusiness requirementPolicies must be shown to be followed, and deviations approved.ImplementedUsISP-001 Information Security Policy; EXC-STD Security Exception & Waiver StandardHead of Information SecurityEvidence library, folder A.5.36OK
EXAMPLEA.5.37Documented operating proceduresA.5 Organizational controlsYesRisk treatmentR-05, R-09Deployments, backups and user administration must be done the same way by whoever is on call.ImplementedUsRunbooks in the engineering wiki, reviewed at each platform changeIT Operations ManagerEvidence library, folder A.5.37OK
EXAMPLEA.6.1ScreeningA.6 People controlsYesRisk treatmentR-07Staff get access to customer data.ImplementedUsPeople security policy (PT-14); checks by role before startHR DirectorEvidence library, folder A.6.1OK
EXAMPLEA.6.2Terms and conditions of employmentA.6 People controlsYesRisk treatmentR-07Security duties must be part of every contract of employment.ImplementedUsPeople security policy (PT-14); contract templates with confidentiality and security termsHR DirectorEvidence library, folder A.6.2OK
EXAMPLEA.6.3Information security awareness, education and trainingA.6 People controlsYesRisk treatmentLegal or regulatoryR-10Phishing is a leading risk; NIS2 expects cyber-security training.ImplementedUsPeople security policy (PT-14); awareness campaign with completion trackedHead of Information SecurityEvidence library, folder A.6.3OK
EXAMPLEA.6.4Disciplinary processA.6 People controlsYesBusiness requirementPolicy breaches must have a fair, known consequence.PlannedUsHR DirectorGap in the ISMS Gap & Remediation Tracker: The disciplinary procedure does not mention information security breaches.OK
EXAMPLEA.6.5Responsibilities after termination or change of employmentA.6 People controlsYesRisk treatmentR-07Confidentiality continues after exit and access must end with the role.ImplementedUsJML-PRC Joiner, Mover, Leaver ProcedureHR DirectorEvidence library, folder A.6.5OK
EXAMPLEA.6.6Confidentiality or non-disclosure agreementsA.6 People controlsYesContractualR-01Customer contracts require confidentiality from everyone with access to their data.ImplementedUsStandard confidentiality agreements for staff and third partiesHR DirectorEvidence library, folder A.6.6OK
EXAMPLEA.6.7Remote workingA.6 People controlsYesRisk treatmentR-08Most staff work remotely part of the week.ImplementedUsAUP-001 Acceptable Use Policy; RMT-GDL Remote Working Guideline; device compliance required for accessHead of ITEvidence library, folder A.6.7OK
EXAMPLEA.6.8Information security event reportingA.6 People controlsYesRisk treatmentLegal or regulatoryR-02, R-11Fast reporting is needed to meet incident reporting deadlines.ImplementedUsINC-001 Incident Management Policy (report button and mailbox)Head of Information SecurityEvidence library, folder A.6.8OK
EXAMPLEA.7.1Physical security perimetersA.7 Physical controlsYesRisk treatmentR-12Two offices hold staff devices; the platform sits in the provider's data centres.ImplementedUs and a supplierPhysical and environmental security standard (PT-13); building perimeter run by the landlordsOffice ManagerEvidence library, folder A.7.1OK
EXAMPLEA.7.2Physical entryA.7 Physical controlsYesRisk treatmentR-12Only staff and escorted visitors may enter the offices.ImplementedUs and a supplierPhysical and environmental security standard (PT-13); badge access and visitor logOffice ManagerEvidence library, folder A.7.2OK
EXAMPLEA.7.3Securing offices, rooms and facilitiesA.7 Physical controlsYesRisk treatmentR-12The equipment room and HR room must be locked.ImplementedUsPhysical and environmental security standard (PT-13); locked equipment room and HR roomOffice ManagerEvidence library, folder A.7.3OK
EXAMPLEA.7.4Physical security monitoringA.7 Physical controlsYesRisk treatmentR-12An intrusion to the offices out of hours must be noticed.PartlyUs and a supplierLandlord camera and alarm cover the first office; the second is being confirmedOffice ManagerEvidence library, folder A.7.4Gap in the ISMS Gap & Remediation Tracker: Camera coverage and alarm monitoring of the second office are not confirmed.OK
EXAMPLEA.7.5Protecting against physical and environmental threatsA.7 Physical controlsYesRisk treatmentR-05, R-12Fire or flood could damage office equipment; the provider protects the data centres.ImplementedUs and a supplierPhysical and environmental security standard (PT-13); landlord fire systems; provider's assurance report for the data centresOffice ManagerEvidence library, folder A.7.5OK
EXAMPLEA.7.6Working in secure areasA.7 Physical controlsYesRisk treatmentR-05, R-12The office equipment room is a secure area; the cloud provider's data centres hold the platform.ImplementedUs and a supplierPhysical and environmental security standard (PT-13) (equipment room rules); provider's certificate and assurance report, reviewed under A.5.22Office ManagerEvidence library, folder A.7.6OK
EXAMPLEA.7.7Clear desk and clear screenA.7 Physical controlsYesRisk treatmentR-01Customer data is on screens in open-plan offices.PlannedUsOffice ManagerGap in the ISMS Gap & Remediation Tracker: No clear desk and clear screen rule.OK
EXAMPLEA.7.8Equipment siting and protectionA.7 Physical controlsYesRisk treatmentR-12Office network equipment must be protected; platform equipment is the provider's.ImplementedUs and a supplierNetwork equipment in the locked equipment room; provider's assurance reportOffice ManagerEvidence library, folder A.7.8OK
EXAMPLEA.7.9Security of assets off-premisesA.7 Physical controlsYesRisk treatmentR-08Laptops and phones travel with staff.ImplementedUsAUP-001 Acceptable Use Policy; RMT-GDL Remote Working Guideline; full-disk encryption and remote wipeHead of ITEvidence library, folder A.7.9OK
EXAMPLEA.7.10Storage mediaA.7 Physical controlsYesRisk treatmentR-01, R-08Removable media could carry customer data out.ImplementedUsUSB storage blocked by device management except approved encrypted drivesHead of ITEvidence library, folder A.7.10OK
EXAMPLEA.7.11Supporting utilitiesA.7 Physical controlsYesRisk treatmentR-05The platform depends on the data centres' power and cooling.ImplementedSupplierProvider's assurance report; the offices hold no equipment that must run through an outageIT Operations ManagerEvidence library, folder A.7.11OK
EXAMPLEA.7.12Cabling securityA.7 Physical controlsYesRisk treatmentR-05Cabling that carries customer data is in the provider's data centres and the landlords' risers.ImplementedSupplierProvider's assurance report; landlord building managementIT Operations ManagerEvidence library, folder A.7.12OK
EXAMPLEA.7.13Equipment maintenanceA.7 Physical controlsYesRisk treatmentR-08Laptops go for repair; the provider maintains platform hardware.ImplementedUs and a supplierPhysical and environmental security standard (PT-13); repairs only through the approved vendor with the drive encryptedIT Operations ManagerEvidence library, folder A.7.13OK
EXAMPLEA.7.14Secure disposal or re-use of equipmentA.7 Physical controlsYesRisk treatmentR-01Old laptops and drives may still hold customer data.PlannedUs and a supplierIT Operations ManagerGap in the ISMS Gap & Remediation Tracker: Disposal of laptops and drives is done by a supplier without certificates.OK
EXAMPLEA.8.1User endpoint devicesA.8 Technological controlsYesRisk treatmentR-02, R-08Staff devices reach customer data and the platform.ImplementedUsAUP-001 Acceptable Use Policy; device management with compliance-based accessHead of ITEvidence library, folder A.8.1OK
EXAMPLEA.8.2Privileged access rightsA.8 Technological controlsYesRisk treatmentR-01, R-07Platform administrators can reach all customer data.ImplementedUsACP-001 Access Control Policy; time-limited admin roles; reviews every 3 monthsHead of ITEvidence library, folder A.8.2OK
EXAMPLEA.8.3Information access restrictionA.8 Technological controlsYesRisk treatmentContractualR-01Customers' data must be separated from each other and from staff without a need.ImplementedUsACP-001 Access Control Policy; tenant isolation in the platformHead of ITEvidence library, folder A.8.3OK
EXAMPLEA.8.4Access to source codeA.8 Technological controlsYesRisk treatmentR-04, R-07The source code is the product.ImplementedUsSecure development and change management standard (PT-12); repository access by team, branch protectionHead of EngineeringEvidence library, folder A.8.4OK
EXAMPLEA.8.5Secure authenticationA.8 Technological controlsYesRisk treatmentR-01, R-10Multi-factor authentication stops most account takeovers.ImplementedUsACP-001 Access Control Policy; single sign-on with multi-factor authentication for all systemsHead of ITEvidence library, folder A.8.5OK
EXAMPLEA.8.6Capacity managementA.8 Technological controlsYesRisk treatmentContractualR-05Customer contracts set service levels the platform must meet.PartlyUs and a supplierPlatform capacity dashboards watched by operationsIT Operations ManagerEvidence library, folder A.8.6Gap in the ISMS Gap & Remediation Tracker: Capacity is watched but no thresholds or forecast exist.OK
EXAMPLEA.8.7Protection against malwareA.8 Technological controlsYesRisk treatmentR-02Malware is the usual start of ransomware.ImplementedUsEndpoint protection on all devices and serversHead of ITEvidence library, folder A.8.7OK
EXAMPLEA.8.8Management of technical vulnerabilitiesA.8 Technological controlsYesRisk treatmentR-03Unpatched vulnerabilities are a leading cause of breaches.ImplementedUsVMS-001 Vulnerability & Exposure Management StandardHead of ITEvidence library, folder A.8.8OK
EXAMPLEA.8.9Configuration managementA.8 Technological controlsYesRisk treatmentR-04Misconfiguration of cloud services exposes customer data.PlannedUsHead of ITGap in the ISMS Gap & Remediation Tracker: No approved baseline configurations for servers, laptops or cloud services.OK
EXAMPLEA.8.10Information deletionA.8 Technological controlsYesLegal or regulatoryContractualR-11Customer data must be deleted at contract end and personal data when no longer needed.PlannedUsIT Operations ManagerGap in the ISMS Gap & Remediation Tracker: Customer data is not deleted on a set schedule after contracts end.OK
EXAMPLEA.8.11Data maskingA.8 Technological controlsYesLegal or regulatoryR-01, R-11Personal data copied for testing and support must not be exposed.Not implementedUsHead of EngineeringGap in the ISMS Gap & Remediation Tracker: Production data is copied to test without masking.OK
EXAMPLEA.8.12Data leakage preventionA.8 Technological controlsYesRisk treatmentR-01Customer data could be shared out by mistake or deliberately.Not implementedUsHead of ITGap in the ISMS Gap & Remediation Tracker: No controls to detect data leaving through email, storage or endpoints.OK
EXAMPLEA.8.13Information backupA.8 Technological controlsYesRisk treatmentContractualR-02, R-09Recovery from ransomware or corruption depends on backups.ImplementedUs and a supplierBKP-001 Backup Standard (review overdue); immutable copies in a second regionIT Operations ManagerEvidence library, folder A.8.13OK
EXAMPLEA.8.14Redundancy of information processing facilitiesA.8 Technological controlsYesRisk treatmentContractualR-05Customer contracts promise high availability.ImplementedUs and a supplierPlatform runs across three availability zones with tested failoverIT Operations ManagerEvidence library, folder A.8.14OK
EXAMPLEA.8.15LoggingA.8 Technological controlsYesRisk treatmentLegal or regulatoryR-02, R-07Logs are needed to detect and investigate incidents and report them.ImplementedUsCentral log store administrators cannot alter; 12-month retentionHead of ITEvidence library, folder A.8.15OK
EXAMPLEA.8.16Monitoring activitiesA.8 Technological controlsYesRisk treatmentR-02, R-07Attacks must be spotted while they can still be stopped.PartlyUsLogs collected centrally from the platform and devicesHead of ITEvidence library, folder A.8.16Gap in the ISMS Gap & Remediation Tracker: Logs are collected but not monitored for anomalies.OK
EXAMPLEA.8.17Clock synchronizationA.8 Technological controlsYesRisk treatmentR-02Investigations need consistent timestamps.ImplementedUsAll systems use the cloud provider's time serviceIT Operations ManagerEvidence library, folder A.8.17OK
EXAMPLEA.8.18Use of privileged utility programsA.8 Technological controlsYesRisk treatmentR-07Admin tools could bypass controls.PlannedUsHead of ITGap in the ISMS Gap & Remediation Tracker: Use of privileged utility programs is not restricted.OK
EXAMPLEA.8.19Installation of software on operational systemsA.8 Technological controlsYesRisk treatmentR-02, R-04Unapproved software on servers or devices brings malware and change risk.ImplementedUsSoftware installed only from the managed catalogue; platform changes only through the pipelineHead of ITEvidence library, folder A.8.19OK
EXAMPLEA.8.20Networks securityA.8 Technological controlsYesRisk treatmentR-01, R-02The platform network and office networks must be protected.ImplementedUs and a supplierCloud network security groups as code; office firewall managed by ITHead of ITEvidence library, folder A.8.20OK
EXAMPLEA.8.21Security of network servicesA.8 Technological controlsYesRisk treatmentR-05The service depends on the provider's network and on DNS.ImplementedUs and a supplierService agreements with the cloud and connectivity providers; DNS in the company's own accountHead of ITEvidence library, folder A.8.21OK
EXAMPLEA.8.22Segregation of networksA.8 Technological controlsYesRisk treatmentR-01, R-02Separation limits how far an attack can spread.ImplementedUsSeparate production, staging and corporate networks; guest wireless isolatedHead of ITEvidence library, folder A.8.22OK
EXAMPLEA.8.23Web filteringA.8 Technological controlsYesRisk treatmentR-02, R-10Malicious sites are a common route for malware and phishing.PartlyUsWeb filtering on the office networksHead of ITEvidence library, folder A.8.23Gap in the ISMS Gap & Remediation Tracker: Web filtering is on in the offices only, not on remote devices.OK
EXAMPLEA.8.24Use of cryptographyA.8 Technological controlsYesRisk treatmentContractualR-01Customer contracts require encryption in transit and at rest.ImplementedUs and a supplierCryptography and key management standard (PT-10); provider key management serviceHead of ITEvidence library, folder A.8.24OK
EXAMPLEA.8.25Secure development life cycleA.8 Technological controlsYesRisk treatmentR-04The company develops the software it sells.ImplementedUsSecure development and change management standard (PT-12)Head of EngineeringEvidence library, folder A.8.25OK
EXAMPLEA.8.26Application security requirementsA.8 Technological controlsYesRisk treatmentContractualR-04Customer security requirements must be designed into features.PlannedUsHead of EngineeringGap in the ISMS Gap & Remediation Tracker: Security requirements are not written into feature specifications.OK
EXAMPLEA.8.27Secure system architecture and engineering principlesA.8 Technological controlsYesRisk treatmentR-04Secure design principles must guide the platform architecture.PlannedUsHead of EngineeringGap in the ISMS Gap & Remediation Tracker: Architecture principles for security are not written down.OK
EXAMPLEA.8.28Secure codingA.8 Technological controlsYesRisk treatmentR-03, R-04Coding flaws become customer-facing vulnerabilities.ImplementedUsSecure development and change management standard (PT-12); code and dependency scanning; peer reviewHead of EngineeringEvidence library, folder A.8.28OK
EXAMPLEA.8.29Security testing in development and acceptanceA.8 Technological controlsYesRisk treatmentContractualR-04Customers ask for annual independent penetration testing.ImplementedUs and a supplierSecurity tests in the pipeline; annual external penetration testHead of EngineeringEvidence library, folder A.8.29OK
EXAMPLEA.8.30Outsourced developmentA.8 Technological controlsNoActivity not carried out within the scopeAll software is developed by the company's own staff; no development is outsourced. Revisit if a contractor or agency writes code. The risk assessment (ISMS-07) found no risk this control would treat.OK
EXAMPLEA.8.31Separation of development, test and production environmentsA.8 Technological controlsYesRisk treatmentR-04Development must not touch production or its data.ImplementedUsSecure development and change management standard (PT-12); separate cloud accounts per environmentHead of EngineeringEvidence library, folder A.8.31OK
EXAMPLEA.8.32Change managementA.8 Technological controlsYesRisk treatmentR-04, R-05Unmanaged changes cause outages and security gaps.ImplementedUsSecure development and change management standard (PT-12); every change through the pipeline with approvalHead of EngineeringEvidence library, folder A.8.32OK
EXAMPLEA.8.33Test informationA.8 Technological controlsYesLegal or regulatoryR-01, R-11Test environments must not hold unprotected personal data.PlannedUsHead of EngineeringGap in the ISMS Gap & Remediation Tracker: No rules for selecting and protecting test data.OK
EXAMPLEA.8.34Protection of information systems during audit testingA.8 Technological controlsYesRisk treatmentR-05Penetration tests and audits must not disrupt the live service.ImplementedUsTest scope and timing agreed in writing; tester accounts removed at the endHead of ITEvidence library, folder A.8.34OK

Wording Guide

Weak justifications and wording that withstands challenge, side by side. The defensible wording is EXAMPLE wording from the worked example; [[double brackets]] mark what you fill in where it has no such case.

DecisionWeak — will be challengedWithstands challengeWhy it works
ExclusionN/AA.8.30, Activity not carried out within the scope: "All software is developed by the company's own staff; no development is outsourced. Revisit if a contractor or agency writes code. The risk assessment (ISMS-07) found no risk this control would treat."It names the fact about the scope, links it to the risk assessment, and says what would change the decision.
ExclusionNot applicable — we are in the cloudDo not exclude. A.7.11 is applicable, delivered by: Supplier. Justification: "The platform depends on the data centres' power and cooling." How: "Provider's assurance report; the offices hold no equipment that must run through an outage."Physical controls at a provider are still needed; the provider carries them out. Excluding them tells the auditor you have not thought about where your data is.
ExclusionNot relevant to our businessOutside the ISMS scope: "[[The activity or site]] is outside the ISMS scope ([[scope statement, version and section]]); [[how the interface to it is controlled, for example by supplier controls]]."An exclusion by scope points to the scope statement, which itself justifies the boundary (IS-02).
InclusionRequired by ISOA.8.2, Risk treatment, R-01, R-07: "Platform administrators can reach all customer data."Annex A requires nothing by itself: controls are chosen to treat risks (IS-03). Name the risks, the law or the contract.
InclusionBest practiceA.8.24, Contractual: "Customer contracts require encryption in transit and at rest."Say whose requirement it is and where it is written.
InclusionImplementedA.8.5, status Implemented. How: "ACP-001 Access Control Policy; single sign-on with multi-factor authentication for all systems." Evidence: "Evidence library, folder A.8.5."Status alone is not evidence: name the document or system that implements it and where an auditor can see it working.

Summary

SoA summary

Calculated from the Statement of Applicability sheet (Your SoA) and the Worked Example sheet (EXAMPLE). Take the counts to management review with the approved SoA.

Decisions and implementation status

MeasureYour SoAEXAMPLEWhat it means
Controls listed9393All 93 must be listed.
Applicable092Controls included, each with a reason.
Excluded01Controls excluded, each justified from the risk assessment and scope.
No decision yet930Must be zero before approval.
Applicable — implemented064Implemented and producing evidence.
Applicable — partly07
Applicable — planned018
Applicable — not implemented03Applicable but not started: each needs a gap with an owner and a date (IS-08).
Applicable — no status yet00
Share of applicable controls implemented70%The Certification Readiness Self-Assessment measures readiness in more depth.
Applicable — delivered wholly or partly by a supplier022Check each is covered by a contract and supplier monitoring (A.5.19 to A.5.22).
Exclusions flagged as weak or too short00Rewrite before approval (IS-03).
Rows with a check to resolve930Must be zero before approval.

By theme

ThemeControlsYour SoA: applicableYour SoA: excludedYour SoA: implementedEXAMPLE: applicableEXAMPLE: excludedEXAMPLE: implemented
A.5 Organizational controls3700037024
A.6 People controls8000807
A.7 Physical controls1400014011
A.8 Technological controls3400033122
All themes9300092164

The EXAMPLE figures are the worked example as at 2026-09-30. Delete the Worked Example sheet before approval, then delete the EXAMPLE columns here.

Lists

ApplicableInclusionReasonImplementationStatusDeliveredByExclusionReasonWeakPhraseMinExclusionWords
YesRisk treatmentImplementedUsActivity not carried out within the scopen/a12
NoLegal or regulatoryPartlySupplierRisk assessment found no risk the control would treatna
ContractualPlannedUs and a supplierOutside the ISMS scopenot applicable
Business requirementNot implementednot relevant

does not apply

not needed

not required

none

no

-

—

tbc

tbd

see scope

WeakPhrase: an exclusion justification made only of one of these is flagged. MinExclusionWords: fewer words than this is flagged as too short. Change either here.

Definitions

Definitions

TermMeaning in this workbook
Statement of Applicability (SoA)The record of which Annex A controls the organisation needs, why each is included, whether it is implemented, and why any is excluded (clause 6.1.3). An auditor reads it first and tests it throughout.
ApplicableThe control is needed: it treats a risk from the risk assessment, or a law, contract or business need requires it. A control a supplier carries out for you is applicable.
ExcludedThe control is not needed, because the activity it addresses does not happen within scope or the risk assessment found no risk it would treat. The justification must say which, and why.
Reason — Risk treatmentThe control treats one or more risks in the risk register; name them in Risk IDs treated.
Reason — Legal or regulatoryA law or regulation requires it, such as data protection or cyber-security law that applies to you.
Reason — ContractualA customer or partner contract requires it.
Reason — Business requirementTop management or the business requires it for a reason not captured above, such as a customer expectation or group policy.
Exclusion — Activity not carried out within the scopeThe control addresses an activity the organisation does not carry out within the scope, such as outsourced development when none is outsourced.
Exclusion — Risk assessment found no risk the control would treatThe risk assessment was done and no risk needs this control. Point to the assessment.
Exclusion — Outside the ISMS scopeThe activity or asset is outside the scope set by the scope statement, which justifies the boundary (IS-02).
ImplementedIn place and operating, with records an auditor could sample.
PartlySome of the control is in place; the rest is on the gap tracker with an owner and a date.
PlannedNot yet in place; the work has an owner and a date.
Not implementedApplicable, but no work has started. Raise a gap in the ISMS Gap & Remediation Tracker (IS-08).
Delivered byUs, Supplier, Us and a supplier. Who carries out the control day to day. Accountability stays with you whichever you choose.
Risk IDsThe references of the risks, in your risk register, that the control treats.
R-01 (EXAMPLE)Customer data exposed through a compromised staff or administrator account. A risk in the example organisation's register.
R-02 (EXAMPLE)Ransomware or a destructive attack on the cloud platform or staff devices. A risk in the example organisation's register.
R-03 (EXAMPLE)An exploitable vulnerability in the platform or its software dependencies. A risk in the example organisation's register.
R-04 (EXAMPLE)Insecure code or configuration released to customers. A risk in the example organisation's register.
R-05 (EXAMPLE)Prolonged outage of the cloud platform or another critical supplier. A risk in the example organisation's register.
R-06 (EXAMPLE)A security failure at a supplier with access to customer data. A risk in the example organisation's register.
R-07 (EXAMPLE)Misuse of privileged access by an insider. A risk in the example organisation's register.
R-08 (EXAMPLE)A laptop or phone with company data lost or stolen. A risk in the example organisation's register.
R-09 (EXAMPLE)Customer or company data lost, corrupted or unrecoverable. A risk in the example organisation's register.
R-10 (EXAMPLE)Phishing or social engineering leading to fraud or account takeover. A risk in the example organisation's register.
R-11 (EXAMPLE)Failure to meet legal, regulatory or contractual security obligations, including incident reporting. A risk in the example organisation's register.
R-12 (EXAMPLE)Unauthorised physical access to the offices or the equipment in them. A risk in the example organisation's register.
Evidence referenceWhere an auditor can see the control working: a folder, a system report or a record ID.
Controlled documented informationA document kept under control: identified, reviewed, approved, versioned, distributed to those who need it, and kept when superseded (clause 7.5.3).
Check (calc)The first missing or inconsistent item on the row. OK means the row is complete.
EXAMPLEA worked example: a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30. Delete before approval.
IS-nnRule numbers in the ISO 27001 Implementation Methodology & Project Plan.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 6.1.3 — Information security risk treatmentThe Statement of Applicability as a whole: the necessary controls, the justification for each inclusion and exclusion, and whether each is implemented
ISO/IEC 27001:2022Clause 6.1.2 — Information security risk assessmentRisk IDs treated and the SoA Approval basis: every inclusion or risk-based exclusion traced to the risk assessment
ISO/IEC 27001:2022Clause 7.5.3 — Control of documented informationSoA Approval: version, approval, distribution and retention of superseded versions
NIST CSF 2.0GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed”Legal or regulatory and Contractual reasons for inclusion: requirements understood and traced to controls

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0