The Statement of Applicability (SoA) serves as the primary reference document for auditors during the certification audit. It lists all Annex A controls, justifies inclusions and exclusions, and documents implementation status for each control.
“The SoA shall include justification for inclusions and exclusions of controls and state their implementation status. The SoA provides auditors with the definitive list of controls relevant to the ISMS.”
— ISO/IEC 27001:2022, Clause 6.1.3 d
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit