Statement of Applicability (SoA): Background, Benefits, Controls

Organizations should always place the highest priority on security, especially in today's AI era. A Statement of Applicability (SoA) is one of the most important documents required for ISO/IEC 27001 certification, which in turn is a key prerequisite for an Information Security Management System (ISMS). This article explains exactly what a Statement of Applicability is, the benefits it offers, and the best practices organizations should follow.

Statement of Applicability (SoA): Background, Benefits, Controls

What Is an SoA?

The Statement of Applicability (SoA) is a core document within an ISO/IEC 27001-compliant ISMS. It documents which security controls have been selected, their implementation status, and why specific controls have been included or excluded.

This enables organizations to demonstrate that they comply with the requirements of ISO/IEC 27001. It therefore plays a critical role for audits and certifications, while also providing transparency for auditors, customers, and business partners.

What a SoA Contains

A Statement of Applicability typically includes:

  • Relevant controls from Annex A of ISO/IEC 27001
  • The justification for including or excluding individual controls
  • The implementation status of each control

Important: Not every control listed in Annex A must be implemented. What matters is that there is a well-documented and justifiable rationale for selecting or excluding each individual control.

The Benefits at a Glance

A Statement of Applicability provides the following benefits in particular:

  • Evidence of compliance for auditors and customers
  • Transparency regarding applicable and excluded controls
  • Clear traceability between risks and security controls
  • Improving efficiency of audits and ISMS maintenance
  • A foundation for the continuous improvement of information security

Relationship to ISO/IEC 27001 Certification

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It defines how organizations identify, assess, and treat information security risks. Certification strengthens the trust of customers and partners, improves risk management, and has become mandatory—or at least business-critical—for critical infrastructure operators and many industries.

Achieving certification requires a documented and operational ISMS with clearly defined responsibilities, risk management processes, security policies, regular audits, and the continuous improvement of security controls.

Accordingly, a Statement of Applicability lays the foundation for implementing security controls in a structured manner. It creates the prerequisites for obtaining ISO/IEC 27001 certification and establishing a highly organized and effective approach to information security management.

Benefits of an SoA

Creating a Statement of Applicability serves several clear purposes and provides an important foundation for cybersecurity. An Information Security Management System is built directly upon it.

The following are the key benefits that an SoA provides—regardless of whether an organization is pursuing ISO/IEC 27001 certification.

1. Overview

An SoA provides a clear overview of security controls. It helps organizations identify, organize, and document them in a structured manner.

2. Audit Relevance

For auditors, an SoA is often the starting point of an audit. It provides insight into whether the documented controls have been implemented correctly, forming the basis for a successful audit. Since the rationale for included and excluded controls is already documented, the number of follow-up questions is significantly reduced.

3. Regulatory Evidence

In the event of a data breach, an SoA can demonstrate that the implemented safeguards are based on an ISO/IEC 27001-compliant risk assessment and therefore meet applicable regulatory requirements.

4. Transparency and Traceability

An SoA documents for every control whether it is applicable, why it has been selected or excluded, and how it is to be implemented, if necessary. This makes decisions transparent and traceable at any time.

5. Connection to Risk Assessment

An SoA bridges the gap between risk assessment and implemented security controls. It shows how identified risks are addressed and why the selected controls are appropriate.

6. ISMS Management

This document serves as an important reference for operating, maintaining, and continuously improving an ISMS. It simplifies the planning and monitoring of appropriate security controls.

7. Communication Within the Organization

Departments such as management, IT, and finance benefit from a shared overview of the applicable security controls. This makes it easier to coordinate responsibilities, implementation efforts, and status reporting.

8. Support for Change

An SoA provides a structured way to document changes to the organization’s security strategy. As a result, updates resulting from new risks, technologies, or regulatory requirements can be incorporated in a transparent manner.

Practical Controls for Organizations

A Statement of Applicability should not be viewed solely as a document required for ISO/IEC 27001 Certification. Instead, it should be understood as an effective tool for continuously improving information security. It delivers the greatest value when it is closely integrated with risk management and the organization’s day-to-day security practices.

Organizations should therefore avoid simply working through a checklist. Instead, they should integrate the SoA into their security processes in a meaningful way to establish a highly effective information security management approach.

The following best practices have proven particularly valuable:

#1 Conduct a Thorough Risk Assessment

The first step is to identify the relevant risks affecting information, systems, and business processes. The selected controls should be based on these actual risks rather than being implemented simply because they are listed in the standard.

#2 Evaluate Every Control Transparently

For every control, organizations should clearly document whether it is applicable, why it is or is not applicable, its implementation status, and who is responsible for it. Any excluded controls should likewise be supported by a well-documented rationale.

#3 Don’t Just “Check Off” Annex A

Organizations should carefully assess whether additional technical or organizational controls are required. From an operational perspective, it is equally important that the SoA accurately reflects the organization’s actual security strategy.

#4 Update the SoA Regularly

Once created, a Statement of Applicability is by no means valid indefinitely. It requires regular updates following changes to the IT landscape, security incidents, or new legal and regulatory requirements. At the latest, it should be reviewed and updated as part of the organization’s annual ISMS review.

#5 Link the SoA with Other ISMS Documents

To maintain a consistent ISMS rather than a collection of isolated documents, organizations should link the SoA with other security-related documentation. This includes, for example, risk treatment documentation, Asset Management records, Business Continuity Management documentation, and Incident Management processes.

#6 Monitor the Implementation Status

The purpose of a Statement of Applicability is not merely to document which controls apply. Those responsible should also verify that these controls are being implemented effectively. Internal audits and appropriate performance metrics provide the foundation for doing so.

#7 Involve Business Departments

If an SoA is created from a single perspective or within organizational silos, its scope and quality will inevitably be limited. Stakeholders from areas such as IT, information security, and compliance should therefore collaborate to define the most appropriate controls. This leads to more realistic risk assessments and greater organizational acceptance.

#8 Use the SoA as an Improvement Roadmap

A Statement of Applicability can also serve as a roadmap for further developing the ISMS. For example, controls that have not yet been implemented can be prioritized and assigned clear responsibilities and implementation timelines.

FAQ

Below are some frequently asked questions about the Statement of Applicability (SoA):

What Is the Purpose of a Statement of Applicability in ISO/IEC 27001?

Within the framework of ISO/IEC 27001, a Statement of Applicability (SoA) documents which security controls apply to an organization, which controls have been excluded, and the reasons for these decisions. It demonstrates that the selection of controls is based on a formal risk assessment and supports both the implementation of the ISMS and internal as well as external audits.

Is an SoA Mandatory?

Yes. A Statement of Applicability (SoA) is a mandatory component of an Information Security Management System (ISMS) in accordance with ISO/IEC 27001. Organizations are required to prepare it in order to document their selection of security controls.

What Are the Four Types of Risk Assessment?

A common classification distinguishes between the following four types of risk assessment:

  1. Qualitative: Assessment based on categories such as “low,” “medium,” or “high”
  2. Quantitative: Assessment based on numerical values, such as potential financial losses
  3. Semi-quantitative: A combination of qualitative categories and scoring systems
  4. Scenario-based: Analysis of specific threat scenarios and their potential impact

The most appropriate method depends on the specific requirements of the organization, as well as the complexity and availability of its risk data.

Stay up-to-date with OTRS newsletter

Choose the Solution That Fits Your Service Use Cases