Select applicable Annex A controls + build the SoA
Scenario
Based on your Day 7 risk assessment, you must now produce the ISO 27001:2022 Statement of Applicability (SoA). The SoA is the SINGLE document the certifier reads first — it lists all 93 Annex A controls, whether each is Applied (Yes/No), and WHY.
Your role
You are the ISMS Manager producing the SoA.
Your task
Produce a SoA table for these 12 illustrative Annex A controls: - A.5.1 Policies for information security - A.5.15 Access control - A.5.17 Authentication information - A.5.23 Information security for use of cloud services - A.5.34 Privacy and protection of PII - A.6.3 Information security awareness, education and training - A.7.10 Storage media - A.8.9 Configuration management - A.8.16 Monitoring activities - A.8.23 Web filtering - A.8.25 Secure development life cycle - A.8.32 Change management For EACH: Applied (Y/N), Justification (why or why not), Implementation status (Not started / In progress / Implemented / Optimised), Evidence reference (which document/system).
Deliverable format: Markdown table, 12 rows, 5 columns
Toolkit
- ISO 27001:2022 SoA is mandatory (Clause 6.1.3.d)
- Justification for 'No' is HARDER than for 'Yes' — must reference risk assessment
- Every control marked 'Yes' MUST have an evidence pointer, even if it's a work-in-progress reference
- Common trap: marking A.7.10 (storage media) as N/A when USB use is not actually prohibited
Success criteria (what the AI grades against)
- All 12 rows filled
- Applied=No has explicit justification (not 'not needed')
- Web filtering (A.8.23) probably Applied for an NBFC (secure browsing)
- Storage media (A.7.10) should be Applied — Board data on laptops
- Cloud services (A.5.23) is Applied since they use AWS
- Evidence pointers reference REAL artifact names not 'TBD'
Log in to submit your deliverable for AI review.
Log in / Register