Master New Skills with 5-Minute Bite-Sized Learning Modules

Start your journey for free.

Developing the Statement of Applicability

Module 2 of 21

Developing the Statement of Applicability

4 min You will be able to create a basic Statement of Applicability document.

๐Ÿ”‘ 1. Prerequisites & Context

  • Required Tools/Skills: ๐Ÿ”— #risk-assessment, ๐Ÿ”— #annex-a-controls
  • Core Concept: A central document that lists every security control from the standard and marks it as applicable or not.

๐Ÿง  2. The Big Idea: Why This Matters

Think of the SoA as a customized menu. You don't order every single dish at a restaurant; you only pick what you actually need to eat.

In security, you don't need every single control. If you have no physical office, you don't need a rule about locking front doors.

Quality beats quantity here. If you blindly check "Yes" to every control, you create a massive workload of rules you can't actually manage. Targeted security that solves real risks is far more effective than a long list of useless checkboxes.

  • Annex A: The master list of security options provided by ISO.
  • Justification: The logical reason why a control is included or left out.
  • Exclusion: The act of intentionally skipping a control because it doesn't apply.

๐Ÿ”ง 3. Step-by-Step: How It Works

The SoA turns your risk assessment into a concrete plan. It bridges the gap between finding a problem and fixing it.

[Control ID] + [Applicable: Yes/No] + [Justification] + [Implementation Status] = SoA Entry

Phase 1: Go through the Annex A list one by one. Ask yourself if the control helps stop a risk you identified earlier.

Phase 2: Decide if the control is applicable. If it is, mark it "Yes"; if it's irrelevant to your business, mark it "No".

Phase 3: Write a clear justification. Explain why it's needed to stop a risk, or why it's useless for your specific setup.


๐Ÿ’ก 4. A Practical Example in Action

Imagine a remote-first software company. They look at the control for "Physical Entry Controls" (locking doors). Since they have no office, they mark this as Not Applicable. Their justification is: "Company is 100% remote with no physical premises."

Next, they look at "Access Control" (passwords). This is Applicable because they use cloud tools. Their justification is: "Needed to protect customer data in the cloud."


โš ๏ธ 5. Common Mistakes to Watch Out For

โŒ The Mistake: Marking everything as "Applicable" to make the company look more secure.

โœ… How to Fix It: Be honest and lean. Only include controls that actually manage a risk you have.


โšก 6. Your Action Checklist

Full Module Access Available

This section is complete and ready for review. Explore the comprehensive lesson examples, structured guides, and implementation checklists.

Open Full Lesson

Created by Reork

Our courses are dynamically generated using advanced AI models and structured around our proven 21-step micro-learning framework to help you master skills faster in just 5 minutes a day.