Free resource
A Statement of Applicability is the document ISO 27001 requires you to maintain listing every Annex A control, whether it applies to you, and why. This builder gives you all 93 controls from the 2022 revision, somewhere to record the decision and the justification for each, and a CSV you can hand to an auditor.
It runs entirely in your browser. Nothing you type is sent anywhere, and your draft is saved locally so you can close the tab and come back to it.
Clause
6.1.3 d)
Controls
93
Themes
Four
Revision
ISO/IEC 27001:2022
What ISO 27001 asks the document to contain
The justifications have to be yours. An auditor is reading them to understand your reasoning about your scope, and generic wording is the fastest way to earn follow-up questions.
ISO/IEC 27001:2022 Annex A · 93 controls
Organisation and ISMS scope: ________________________________________
Progress
0 of 93 controls decided
A.5.1
Policies for information security
Not decided
A.5.2
Information security roles and responsibilities
Not decided
A.5.3
Segregation of duties
Not decided
A.5.4
Management responsibilities
Not decided
A.5.5
Contact with authorities
Not decided
A.5.6
Contact with special interest groups
Not decided
A.5.7
Threat intelligence
Not decided
A.5.8
Information security in project management
Not decided
A.5.9
Inventory of information and other associated assets
Not decided
A.5.10
Acceptable use of information and other associated assets
Not decided
A.5.11
Return of assets
Not decided
A.5.12
Classification of information
Not decided
A.5.13
Labelling of information
Not decided
A.5.14
Information transfer
Not decided
A.5.15
Access control
Not decided
A.5.16
Identity management
Not decided
A.5.17
Authentication information
Not decided
A.5.18
Access rights
Not decided
A.5.19
Information security in supplier relationships
Not decided
A.5.20
Addressing information security within supplier agreements
Not decided
A.5.21
Managing information security in the ICT supply chain
Not decided
A.5.22
Monitoring, review and change management of supplier services
Not decided
A.5.23
Information security for use of cloud services
Not decided
A.5.24
Information security incident management planning and preparation
Not decided
A.5.25
Assessment and decision on information security events
Not decided
A.5.26
Response to information security incidents
Not decided
A.5.27
Learning from information security incidents
Not decided
A.5.28
Collection of evidence
Not decided
A.5.29
Information security during disruption
Not decided
A.5.30
ICT readiness for business continuity
Not decided
A.5.31
Legal, statutory, regulatory and contractual requirements
Not decided
A.5.32
Intellectual property rights
Not decided
A.5.33
Protection of records
Not decided
A.5.34
Privacy and protection of PII
Not decided
A.5.35
Independent review of information security
Not decided
A.5.36
Compliance with policies, rules and standards for information security
Not decided
A.5.37
Documented operating procedures
Not decided
A.6.1
Screening
Not decided
A.6.2
Terms and conditions of employment
Not decided
A.6.3
Information security awareness, education and training
Not decided
A.6.4
Disciplinary process
Not decided
A.6.5
Responsibilities after termination or change of employment
Not decided
A.6.6
Confidentiality or non-disclosure agreements
Not decided
A.6.7
Remote working
Not decided
A.6.8
Information security event reporting
Not decided
A.7.1
Physical security perimeters
Not decided
A.7.2
Physical entry
Not decided
A.7.3
Securing offices, rooms and facilities
Not decided
A.7.4
Physical security monitoring
Not decided
A.7.5
Protecting against physical and environmental threats
Not decided
A.7.6
Working in secure areas
Not decided
A.7.7
Clear desk and clear screen
Not decided
A.7.8
Equipment siting and protection
Not decided
A.7.9
Security of assets off-premises
Not decided
A.7.10
Storage media
Not decided
A.7.11
Supporting utilities
Not decided
A.7.12
Cabling security
Not decided
A.7.13
Equipment maintenance
Not decided
A.7.14
Secure disposal or re-use of equipment
Not decided
A.8.1
User end point devices
Not decided
A.8.2
Privileged access rights
Not decided
A.8.3
Information access restriction
Not decided
A.8.4
Access to source code
Not decided
A.8.5
Secure authentication
Not decided
A.8.6
Capacity management
Not decided
A.8.7
Protection against malware
Not decided
A.8.8
Management of technical vulnerabilities
Not decided
A.8.9
Configuration management
Not decided
A.8.10
Information deletion
Not decided
A.8.11
Data masking
Not decided
A.8.12
Data leakage prevention
Not decided
A.8.13
Information backup
Not decided
A.8.14
Redundancy of information processing facilities
Not decided
A.8.15
Logging
Not decided
A.8.16
Monitoring activities
Not decided
A.8.17
Clock synchronization
Not decided
A.8.18
Use of privileged utility programs
Not decided
A.8.19
Installation of software on operational systems
Not decided
A.8.20
Networks security
Not decided
A.8.21
Security of network services
Not decided
A.8.22
Segregation of networks
Not decided
A.8.23
Web filtering
Not decided
A.8.24
Use of cryptography
Not decided
A.8.25
Secure development life cycle
Not decided
A.8.26
Application security requirements
Not decided
A.8.27
Secure system architecture and engineering principles
Not decided
A.8.28
Secure coding
Not decided
A.8.29
Security testing in development and acceptance
Not decided
A.8.30
Outsourced development
Not decided
A.8.31
Separation of development, test and production environments
Not decided
A.8.32
Change management
Not decided
A.8.33
Test information
Not decided
A.8.34
Protection of information systems during audit testing
Not decided
Control titles are the Annex A titles from ISO/IEC 27001:2022. The standard's own text is not reproduced here; if you need the normative wording, buy the standard from ISO.
Being clear
Filling this in does not make anyone ISO 27001 certified. Certification comes from an accredited body auditing a working ISMS, and the SoA is one of the documents they will ask to see. It is a genuinely important one: it is where an auditor learns how you reasoned about scope.
The other thing worth saying plainly is that an SoA goes stale. The moment a system changes, a control gets implemented, or scope moves, the document drifts from reality, and the version in the audit folder stops matching the thing being audited. A spreadsheet cannot tell you when that has happened.
Where Alvor comes in
Alvor keeps the record an SoA is produced from, rather than the document itself: control applicability and implementation status maintained per control, evidence with freshness states, and named sign-offs. The Statement of Applicability is then generated from that record, on screen and as CSV, so it reflects the current state rather than the day someone last opened the spreadsheet.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.