2.4 Statement of Applicability (SoA) & Control Selection (Clause 6.1.3)
Key Takeaways
- The Statement of Applicability (SoA) is a mandatory document required by Clause 6.1.3 d that details which ISO/IEC 27001 Annex A controls are included or excluded, along with detailed justifications.
- SoA serves as the central bridge between risk treatment outcomes, legal/regulatory compliance obligations, contractual duties, and Annex A controls.
- ISO/IEC 27001:2022 structures Annex A into 93 controls organized across 4 themes: Organizational (37), People (8), Physical (14), and Technological (34).
- Every Annex A control must be documented in the SoA with its implementation status (Implemented, In Progress, Planned), justification for inclusion/exclusion, and responsible control owner.
- Certification auditors review the SoA as the primary audit scope baseline; excluding an applicable Annex A control without valid justification results in a major non-conformity.
2.4 Statement of Applicability (SoA) & Control Selection (Clause 6.1.3)
The Statement of Applicability (SoA) is arguably the single most important document within an Information Security Management System (ISMS). Mandated by ISO/IEC 27001:2022 Clause 6.1.3 d), the SoA links the organization's risk assessment and risk treatment decisions to the reference security controls listed in Annex A of the standard.
1. Purpose & Significance of the SoA
The SoA summarizes the organization's security posture, control choices, and regulatory commitments in a single authoritative document. It serves three vital functions:
- Primary Audit Scope Boundary: Certification Body auditors use the SoA as the definitive baseline against which Stage 1 and Stage 2 audits are conducted. If a control is listed as applicable, auditors will audit its implementation and operational effectiveness.
- Traceability Bridge: It explicitly links selected Annex A controls to risk assessment findings, statutory/legal requirements, customer contracts, and core business goals.
- Transparency & Third-Party Assurance: Clients, regulators, and insurers inspect the SoA to verify which security controls are maintained within the ISMS boundary.
2. Mandatory Data Fields under Clause 6.1.3 d)
ISO/IEC 27001:2022 Clause 6.1.3 d) specifies that the Statement of Applicability must contain the following mandatory information for all 93 controls listed in Annex A:
- Control Identifier & Title: Exact reference (e.g., A.5.15 Access Control, A.8.25 Secure Coding).
- Inclusion / Exclusion Decision: Clear statement indicating whether the control is selected (Applicable) or excluded (Not Applicable).
- Justification for Inclusion: Specific reasons why the control was selected (e.g., mitigates High risk R-104, satisfies GDPR Article 32, required by customer Master Services Agreement).
- Justification for Exclusion: Detailed factual justification explaining why an excluded control is not applicable (e.g., organization operates 100% serverless infrastructure without physical data centers).
- Implementation Status: Operational state of the control (e.g., Fully Implemented, In Progress, Planned).
Sample Statement of Applicability (SoA) Table Excerpt
| Control ID | Control Name | Theme | Applicable? | Justification for Inclusion / Exclusion | Implementation Status |
|---|---|---|---|---|---|
| A.5.15 | Access Control | Organizational | Yes | Mitigates unauthorized access risk R-012; complies with Clause 6.1.3. | Fully Implemented |
| A.7.4 | Physical Security Monitoring | Physical | Yes | Protects corporate headquarters; mitigates physical intrusion risk R-045. | Fully Implemented |
| A.7.11 | Physical Supporting Utilities | Physical | No | Excluded: Organization operates 100% in cloud (AWS); owns no utility infrastructure. | Not Applicable |
| A.8.25 | Secure Coding | Technological | Yes | Mitigates software vulnerability risk R-089; mandated by client contract. | In Progress (Q3 Target) |
3. Control Selection & ISO 27001:2022 Annex A Architecture
ISO/IEC 27001:2022 restructured Annex A from 114 controls across 14 domains (the 2013 edition) into 93 controls consolidated across 4 practical themes:
+-----------------------------------------------------------------------------+
| ISO/IEC 27001:2022 ANNEX A STRUCTURE |
+-----------------------------------------------------------------------------+
| [5. Organizational] | [6. People] | [7. Physical] | [8. Technological]|
| (37 Controls) | (8 Controls) | (14 Controls) | (34 Controls) |
+-----------------------------------------------------------------------------+
The 4 Control Themes
- Organizational Controls (Clause 5 / 37 Controls): Policy governance, asset management, access control rules, supplier relationships, incident management, threat intelligence, and business continuity.
- People Controls (Clause 6 / 8 Controls): Screening, employment agreements, security awareness training, disciplinary processes, remote working, and non-disclosure agreements.
- Physical Controls (Clause 7 / 14 Controls): Physical security perimeters, entry controls, equipment protection, clear desk policies, cabling security, and asset disposal.
- Technological Controls (Clause 8 / 34 Controls): Authentication, network security, data masking, secure coding, vulnerability management, backup, log monitoring, and cryptography.
Control Attributes (ISO 27002:2022)
ISO 27002:2022 introduced 5 attribute categorization types to help organizations filter and sort controls:
- Control Type: Preventive, Detective, Corrective.
- Information Security Properties: Confidentiality, Integrity, Availability.
- Cybersecurity Concepts: Identify, Protect, Detect, Respond, Recover (NIST CSF alignment).
- Operational Capabilities: Governance, Asset Management, Information Protection, Application Security, etc.
- Security Domains: Governance & Ecosystem, Protection, Defense, Resilience.
4. Rules for Valid Inclusions & Exclusions
Certification auditors heavily scrutinize Annex A exclusions. Lead Implementers must adhere to strict justification rules:
+-----------------------------------------------------------------------------+
| VALID VS. INVALID EXCLUSION RULES |
+-----------------------------------------------------------------------------+
| VALID EXCLUSIONS: |
| - Absence of underlying physical infrastructure (e.g., 100% cloud SaaS) |
| - Absence of software development activities (e.g., zero custom code) |
| |
| INVALID EXCLUSIONS: |
| - Control is 'too expensive' or 'too difficult to implement' |
| - Control addresses an identified unacceptable risk, but budget is lacking |
| - Excluding controls mandated by applicable statutory or legal laws |
+-----------------------------------------------------------------------------+
Common Pitfalls in SoA Formulation
- Blank Justifications: Leaving justification fields empty or writing generic phrases like 'Not needed.'
- Excluding Legal Mandates: Excluding data privacy or encryption controls when operating under GDPR or HIPAA laws.
- Disconnect from Risk Assessment: Selecting controls in the SoA that were never identified during the risk treatment process, or omitting controls that were selected in the Risk Treatment Plan.
5. PECB Exam Tips & Critical Scenarios
- Mandatory Fields: On the exam, remember that Clause 6.1.3 d) requires determination of inclusion/exclusion, justifications for both, and implementation status for all 93 controls.
- Justifying Exclusions: If a cloud-native organization excludes A.7.11 (Physical Supporting Utilities), the justification must cite the factual absence of physical data center ownership and reliance on accredited third-party cloud attestations.
- 2022 Theme Structure: Remember the 4 themes (Organizational, People, Physical, Technological) totaling 93 controls.
Which set of items represents the mandatory information required for every Annex A control listed in the Statement of Applicability (SoA) under Clause 6.1.3 d)?
An organization operates as a cloud-native SaaS provider. All IT infrastructure is hosted entirely within AWS serverless environments, and the company maintains no physical server rooms or hardware data center infrastructure. How should control A.7.11 (Physical Supporting Utilities) be documented in the SoA?
How is Annex A structured in the ISO/IEC 27001:2022 standard revision?