ISO 27001 Statement of Applicability Template
Written By Micah
The Statement of Applicability (SoA) is an integral part of your ISMS documentation. The SoA is used to indicate to your assessor or certification body which ISO annex requirements are in scope and out of scope for your organization's assessment.
The SoA in its most basic form is a list of all the ISO annex requirements that need to be met in order to be certified. It is highly likely that for most companies at least one of the annex requirements will not be applicable, and therefore will be out of scope. For example, annex 7.8 states that "Equipment should be sited securely and protected." If your organization is fully remote, and does not have an office where equipment is stored, it would be appropriate to mark this annex as out of scope with the justification being that the company is fully remote.
Annexes should only be marked out of scope if you feel confident that you can make the case to your assessor that they are legitimately requirements that are not applicable to your business. If you don't currently have controls or processes to meet an annex requirement, but it is reasonably applicable to your business, that means we have a gap and controls will need to be implemented.
Strike Graph has several templates available, if your organization is pursuing ISO 27001:2022, use the template below.
If your organization has previously been certified on the ISO 27001:2013 standard, and is moving to the 2022 standard, use this template as it includes the 2013 annex references as well as the 2022 references.
If your organization is also pursuing ISO 27701 in addition to ISO 27001, use the template below to add the additional annexes to your ISO 27001 SoA.
A video demonstration of how to utilize the Statement of Applicability template can be found here.
Who needs a policy like this?
Organizations that are implementing ISO 27001 and ISO 27701
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
If you need help using the template, please let us know.
β