ISO/IEC 27001

Connect risk treatment, Annex A control selection, ownership, implementation, and evidence in one working record.

Start with scope and risk treatment

Define the services, entities, assets, locations, and interfaces in the information security management system. Then assess information security risks and choose treatment options. The Statement of Applicability, or SoA, records the control decisions arising from that work and checks the selected controls against ISO/IEC 27001 Annex A.

An auditor should be able to trace an important risk through its treatment decision to a control owner and evidence. A generic SoA assembled before the risk assessment obscures that chain.

Explain inclusion and exclusion

For each Annex A control, document whether it is applicable, why, and whether it is implemented. The reason should refer to the scoped operation, risks, legal and contractual needs, or selected treatment. An exclusion deserves an explanation; “not relevant” without context gives a reviewer little basis to understand the decision.

ISO committee auditing guidance notes that interested-party requirements should flow through risk assessment and treatment into the SoA. Keep that relationship visible when customer requirements change.

Connect status to operating evidence

A control marked implemented should have an owner, process, and evidence source. For access management, for example, a policy may say who approves access, while sample tickets and reviews show that the process ran. If a selected control is still being built, mark it honestly and put it in the treatment plan with a date and accountable owner.

Where SOC 2 or another framework also uses the control, map the shared operating record. Preserve each framework’s different scope and assessment question.

Keep the SoA current

Revisit applicability when the ISMS boundary, suppliers, technology, laws, products, or threat picture changes. Review the SoA after significant risk assessment changes and management decisions. Version the record so an independent assessor can see which decisions applied at the time of assessment.

Certification is decided by an independent certification body. A well-maintained SoA helps the organization explain and operate its own risk treatment regardless of the assessment outcome.

Put it into practice

  • Complete scope and risk treatment before finalizing the SoA.
  • Give a specific rationale for every included and excluded Annex A control.
  • Tie implemented status to an owner and operating evidence.
  • Review the record after material changes and risk decisions.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources