PHASE 01
Set scope and risk context
Describe the organization, systems, data, locations, suppliers, and exclusions. Use your risk assessment to drive applicability.
- Define an owner for the SoA.
- Record the assessment date and review trigger.
Create a lightweight Statement of Applicability that records relevant controls, decisions, owners, evidence, and review dates.
A lightweight SoA is a decision register. It explains which controls apply, why they matter, how they operate, and where the evidence lives.
PHASE 01
Describe the organization, systems, data, locations, suppliers, and exclusions. Use your risk assessment to drive applicability.
PHASE 02
For each relevant control, state applicable or not applicable, the rationale, implementation status, owner, and evidence location.
PHASE 03
Review the SoA when scope, suppliers, incidents, architecture, or risk decisions change.
Yes, but document a risk-based rationale. Excluding a control without explanation weakens the SoA.