Developing the Statement of Applicability
๐ 1. Prerequisites & Context
- Required Tools/Skills: ๐ #risk-assessment, ๐ #annex-a-controls
- Core Concept: A central document that lists every security control from the standard and marks it as applicable or not.
๐ง 2. The Big Idea: Why This Matters
Think of the SoA as a customized menu. You don't order every single dish at a restaurant; you only pick what you actually need to eat.
In security, you don't need every single control. If you have no physical office, you don't need a rule about locking front doors.
Quality beats quantity here. If you blindly check "Yes" to every control, you create a massive workload of rules you can't actually manage. Targeted security that solves real risks is far more effective than a long list of useless checkboxes.
- Annex A: The master list of security options provided by ISO.
- Justification: The logical reason why a control is included or left out.
- Exclusion: The act of intentionally skipping a control because it doesn't apply.
๐ง 3. Step-by-Step: How It Works
The SoA turns your risk assessment into a concrete plan. It bridges the gap between finding a problem and fixing it.
[Control ID] + [Applicable: Yes/No] + [Justification] + [Implementation Status] = SoA Entry
Phase 1: Go through the Annex A list one by one. Ask yourself if the control helps stop a risk you identified earlier.
Phase 2: Decide if the control is applicable. If it is, mark it "Yes"; if it's irrelevant to your business, mark it "No".
Phase 3: Write a clear justification. Explain why it's needed to stop a risk, or why it's useless for your specific setup.
๐ก 4. A Practical Example in Action
Imagine a remote-first software company. They look at the control for "Physical Entry Controls" (locking doors). Since they have no office, they mark this as Not Applicable. Their justification is: "Company is 100% remote with no physical premises."
Next, they look at "Access Control" (passwords). This is Applicable because they use cloud tools. Their justification is: "Needed to protect customer data in the cloud."
โ ๏ธ 5. Common Mistakes to Watch Out For
โ The Mistake: Marking everything as "Applicable" to make the company look more secure.
โ How to Fix It: Be honest and lean. Only include controls that actually manage a risk you have.
โก 6. Your Action Checklist
Full Module Access Available
This section is complete and ready for review. Explore the comprehensive lesson examples, structured guides, and implementation checklists.
