SCOPE Β· RISK Β· APPLICABILITY

ISO 27001 SoA Lite

Create a lightweight Statement of Applicability that records relevant controls, decisions, owners, evidence, and review dates.

A lightweight SoA is a decision register. It explains which controls apply, why they matter, how they operate, and where the evidence lives.

PHASE 01

Set scope and risk context

Describe the organization, systems, data, locations, suppliers, and exclusions. Use your risk assessment to drive applicability.

  • Define an owner for the SoA.
  • Record the assessment date and review trigger.

PHASE 02

Record each control decision

For each relevant control, state applicable or not applicable, the rationale, implementation status, owner, and evidence location.

  • Avoid vague reasons such as not needed.
  • Link exceptions to risk acceptance and expiry.

PHASE 03

Keep it operational

Review the SoA when scope, suppliers, incidents, architecture, or risk decisions change.

  • Sample evidence that controls actually operate.
  • Track gaps in the same register used for remediation.

Frequently asked questions

Can a control be not applicable?

Yes, but document a risk-based rationale. Excluding a control without explanation weakens the SoA.