Glossary

Statement of Applicability

The Statement of Applicability is ISO 27001’s central document: a complete inventory of Annex A controls annotated with whether each applies to your ISMS, why, and how it’s implemented. Certification auditors read it first because it reveals whether your risk assessment actually drove your control decisions — or whether the controls were adopted wholesale and the justifications written backward.

What auditors probe

Exclusions get the scrutiny. Every excluded control needs a defensible rationale tied to your scope and risk assessment; “not relevant” without reasoning is a Stage 1 finding waiting to happen. The strongest SoAs read as decisions with evidence — each inclusion traceable to a risk, each exclusion to a documented boundary.

Related Terms

Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.

vCISO — A vCISO provides fractional executive security leadership — strategy, risk decisions, and buyer-facing credibility — without a full-time CISO salary.