---
title: Nothing is More Critical Than an ISO 27001 Statement of Applicability
description: When it comes to all the different documents and implementations required for ISO 27001, none are more important than your statement of applicability.
image: https://blog.intertecintl.com/hubfs/Risk%20Assessment.%20Business%20Concept%20on%20Blurred%20Background.%20Office%20Folder%20with%20Inscription%20Risk%20Assessment%20on%20Working%20Desktop.%20Risk%20Assessment%20-%20Concept.%203D..jpeg
---

[![Logo_web](https://blog.intertecintl.com/hs-fs/hubfs/Logo_web.png?width=1920&height=1080&name=Logo_web.png "Logo_web")](http://Intertec%20International)

- [Why Nearshore?](https://www.intertecintl.com/why-nearshore)
- [About Intertec](https://www.intertecintl.com/about)
- [Blog](https://blog.intertecintl.com)
- [Employment Verification](https://info.intertecintl.com/request-employee-information-from-human-resources)

[![Contact Us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/7230565/ee4af9bf-0c3c-411c-a65a-bf21cf958902.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/7230565/ee4af9bf-0c3c-411c-a65a-bf21cf958902)

[![Intertec International](https://blog.intertecintl.com/hs-fs/hubfs/Logo_web.png?width=1920&height=1080&name=Logo_web.png "Intertec International")](http://Intertec%20International)

- [Why Nearshore?](https://www.intertecintl.com/why-nearshore)
- [About Intertec](https://www.intertecintl.com/about)
- [Blog](https://blog.intertecintl.com)
- [Employment Verification](https://info.intertecintl.com/request-employee-information-from-human-resources)

[![Schedule A Meeting](https://no-cache.hubspot.com/cta/default/7230565/bb88404d-87cd-4a9d-9ec6-63d42304ee0b.png)](https://cta-redirect.hubspot.com/cta/redirect/7230565/bb88404d-87cd-4a9d-9ec6-63d42304ee0b)

# INTERTEC BLOG

## **Our Latest Content is on the FPT Blog**

Feel free to browse our existing content below, however, if you're looking for the latest articles, we now post them to [FPT Software's blog page](https://blog.fpt-software.com/). 

## [Nothing is More Critical Than an ISO 27001 Statement of Applicability](https://blog.intertecintl.com/nothing-is-more-important-to-your-iso-27001-than-your-statement-of-applicability)

 April 1, 2021 / by [Frederid Palacios](https://blog.intertecintl.com/author/frederid-palacios)

- [Tweet](https://twitter.com/share)

When it comes to all the different documents, [scopes](https://blog.intertecintl.com/defining-the-scope-of-your-isms-for-iso-27001), procedures, and implementations that are required for your ISO 27001 certification, none are more important than your statement of applicability. In fact, most companies downplay the importance of the statement, much to their detriment, thinking that it’s a duplication of their efforts in previous steps and documents, but this is not so. It’s far more than that. Technically, to be fair, all of the steps in the audit and certification process are equally important, but this step of defining the applicability of your choice in security controls is the connective process between planning and implementation. 

![Risk Assessment. Business Concept on Blurred Background. Office Folder with Inscription Risk Assessment on Working Desktop. Risk Assessment - Concept. 3D.](https://blog.intertecintl.com/hs-fs/hubfs/Risk%20Assessment.%20Business%20Concept%20on%20Blurred%20Background.%20Office%20Folder%20with%20Inscription%20Risk%20Assessment%20on%20Working%20Desktop.%20Risk%20Assessment%20-%20Concept.%203D..jpeg?width=1000&name=Risk%20Assessment.%20Business%20Concept%20on%20Blurred%20Background.%20Office%20Folder%20with%20Inscription%20Risk%20Assessment%20on%20Working%20Desktop.%20Risk%20Assessment%20-%20Concept.%203D..jpeg)

Your Statement of Applicability (SoA, for short) is the critical document that defines how you will implement a large portion of your information security plan. As the main link between the [risk assessment methodology & treatment](https://blog.intertecintl.com/developing-a-risk-assessment-methodology-for-your-iso-certification) plan that you’ve already defined and the actual implementation of your information security, your SoA defines which controls from the [ISO Annex A](https://advisera.com/27001academy/what-is-iso-27001/) suits your ISMS.

 

## How Does Your Statement of Applicability Fit in?

As a refresher, the purpose of going through[the key steps](https://blog.intertecintl.com/planning-for-your-iso-27001-certification-is-just-basic-project-management) of getting your ISO 27001 certification is to ensure that you’re protecting 3 key touch points about the information in your possession. They are:

- Ensuring the **Confidentiality** of information so that only authorized persons can have access rights to the data.
- Ensuring the **Integrity** of the information so that only authorized persons can change any data.
- Ensuring the **Availability** of information so that it remains accessible to the authorized persons whenever they need it. 

By the time you’ve [defined the scope](https://blog.intertecintl.com/defining-the-scope-of-your-isms-for-iso-27001) of your ISO project, [established an ISMS](https://blog.intertecintl.com/benefits-of-an-iso-compliant-isms) policy, a [security policy](https://blog.intertecintl.com/writing-a-security-policy-for-your-iso-certification), and sorted out your [risk assessments](https://blog.intertecintl.com/developing-a-risk-assessment-methodology-for-your-iso-certification) and risk treatments, you’re technically ready to clearly outline your plan by:

- Listing and defining all the controls from Annex A that are applicable.
- Outlining the reasons why you’ve chosen these specific controls.
- Defining the objectives to be achieved with the controls.
- Giving a description of how these controls are to be implemented in your organisation.

If you’ve been keeping up with the previous blogs we’ve shared regarding your ISO 27001 certification, then none of this should be new information.

But something that hasn’t been explored in previous blogs is that while the controls listed in Annex A seem to be fairly comprehensive, they’re not exhaustive by any means. Hence, you may need to consider other sources for controls as well. Which is where breaking down the importance of this statement comes into play.

 

## Why You Need Your SoA

Given that you’ve already developed your mandatory Risk Assessment Report, which outlines which controls you’ll be utilizing moving forward to mitigate said risks, why is this document even necessary? It’s necessary, because being ISO certified is more than just about being protected from and prepared for risk. Your ISO certification should be a holistic plan for not only protection, but for compliance and governance, accounting for every facet of your organization’s ISMS, from endpoint to endpoint. There are also several other [key reasons](https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/) why you need your SoA: 

- **On one hand**, your risk treatment aims to outline the controls that are necessary to decrease any risks you’ve identified. The SoA also identities the controls that are required for other reasons - such as legal reasons, contractual requirements, other processes, etc…
- **Secondly**, the SoA justifies the inclusion and exclusion of your chosen controls from Annex A, and the inclusion of controls from other sources as you see fit. The linear relationship between your list controls and the reasons for choosing them, makes this statement a practical checklist for operational use.
- **Thirdly**, your Risk Assessment Report could be a hefty document, filled with a few thousand or so risks that your organization has identified, if not more. This makes the document less than ideal for everyday operational use. The SoA, on the other hand, is meant to be short. It has a row for each of the 114 controls from Annex A, as well as a row for any other external inclusions. This makes it more manageable to present to management and update it regularly.
- **Finally**, and most importantly, the SoA must document whether each applicable control has been implemented or not. A good practice would be to describe how each applicable control has been implemented. This could be via a reference to a specific document that outlines the policy, procedure, or working instruction, or by shortly describing the procedure in use, or outline which equipment is used. Auditors will be looking for this.

When it comes time for your certification audit, the auditor will take your SoA and walk around the company to ensure that you’ve implemented the controls the way that was described in your SoA. This is their key guiding document during their on-site audit.

An additional key consideration is that if you develop the time to generate a thorough Statement, it could decrease the number of other documents. For example, if you want to document a certain control, but the description of the procedure for that control is relatively short, it can live in your SoA, rather than in a separate document. 

[![Cyber Security as a Competitive Advantage](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/7230565/3dbc25c1-2506-4ef1-89e7-b28f06cd6591.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/7230565/3dbc25c1-2506-4ef1-89e7-b28f06cd6591)

## How This Helps Your ISO Certification Audit

Consider this document an exercise in putting together an action plan that has real world connections. It’s one thing to generate volumes of documents on what the potential risks and dangers are, and how your organization can mitigate those risks and protect the sensitive data. But that’s just an exercise in hypotheticals. It needs real-world practically. Your SoA takes those esoteric ideas and puts them into tangible actions, procedures, and accountabilities. 

Hence, when putting this together, you’ll find that you’ll spend more time on implementing your ISMS according to ISO 27001 and writing this document, than you’ll anticipate. Once you’re going down the list of applicable controls, you need to actually think about how you will put it into practice. For example:

- Will you need new equipment?
- Change long-standing procedures and protocols?
- Re-evaluate your remote working policy?
- Will you need to hire more trained staff, or reduce your workforce?
- Will you have to crack down on who has god-mode privileges in your IT department?

These are important and potentially expensive decisions that must be made. This is why it takes a long time to reach a definitive decision. The good element is that your SoA forces you and your organization to do this job in a systematic way, thus ensuring that all the conditions and controls are addressed, and nothing is missed.

Therefore, this isn’t one of those documents you need to generate just to make the auditor happy, and mark it off on your [ISO 27001 checklist](https://blog.intertecintl.com/planning-for-your-iso-27001-certification-is-just-basic-project-management). This is a practical exercise that has real world implications. By defining what you want to do with your organization’s information security, and how you’ll do it, you’ll walk away with the perfect overview of your information security procedures - a detailed document that lists what controls you’re adhering to, a justification for your choice of controls, and a description of how it’s being done. 

By answering the basic questions of what, why, and how, you’re boosting your organization's information security capacity, and overcoming the largest hurdle in your ISO 27110 audit.

[![contact us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/7230565/99945ac5-0911-40bf-95ca-d96080542cf0.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/7230565/99945ac5-0911-40bf-95ca-d96080542cf0)

  

 Tags: [Cyber Security](https://blog.intertecintl.com/topic/cyber-security)

![Frederid Palacios](https://blog.intertecintl.com/hubfs/Images/fred_headshot.jpeg)

#### Written by [Frederid Palacios](https://blog.intertecintl.com/author/frederid-palacios)

Fred Palacios is a seasoned software architect with more than 20 years of experience participating in the entire software development cycle across a host of different industries--from automotive and services to petroleum, financial, and supply chain. In that time, his experience working closely with high-level stakeholders has provided him with a strategic vision for developing the right solutions to flexibly meet critical business needs. As CTO of Intertec, he's continuing to focus on the creation of business-critical applications for large enterprise projects, particularly those that handle high concurrency and large datasets. He is passionate about using technology as a tool to solve real-world problems and also mentoring technical teams to achieve their maximum potential and deliver quality software.

## Leave A Comment

### Subscribe to Email Updates

- [Recent](https://blog.intertecintl.com/nothing-is-more-important-to-your-iso-27001-than-your-statement-of-applicability#tab-1)
- [Popular](https://blog.intertecintl.com/nothing-is-more-important-to-your-iso-27001-than-your-statement-of-applicability#tab-2)
- [Categories](https://blog.intertecintl.com/nothing-is-more-important-to-your-iso-27001-than-your-statement-of-applicability#tab-3)

### Lists by Topic

- [Cyber Security (56)](https://blog.intertecintl.com/tag/cyber-security)
- [Technical Support Services (50)](https://blog.intertecintl.com/tag/technical-support-services)
- [Cloud Migration (45)](https://blog.intertecintl.com/tag/cloud-migration)
- [Project Management (31)](https://blog.intertecintl.com/tag/project-management)
- [Software Development (26)](https://blog.intertecintl.com/tag/software-development)
- [Infrastructure (16)](https://blog.intertecintl.com/tag/infrastructure)
- [Remote Work (15)](https://blog.intertecintl.com/tag/remote-work)
- [Recruitment (11)](https://blog.intertecintl.com/tag/recruitment)
- [Near-Shoring (9)](https://blog.intertecintl.com/tag/near-shoring)
- [Quality Assurance (9)](https://blog.intertecintl.com/tag/quality-assurance)
- [Agile (8)](https://blog.intertecintl.com/tag/agile)
- [MDM (8)](https://blog.intertecintl.com/tag/mdm)
- [DevOps (7)](https://blog.intertecintl.com/tag/devops)
- [GRC (7)](https://blog.intertecintl.com/tag/grc)
- [Governance, Risk, and Compliance (7)](https://blog.intertecintl.com/tag/governance-risk-and-compliance)
- [DaaS (6)](https://blog.intertecintl.com/tag/daas)
- [Product Development (6)](https://blog.intertecintl.com/tag/product-development)
- [Test Engineering (5)](https://blog.intertecintl.com/tag/test-engineering)
- [KPIs (3)](https://blog.intertecintl.com/tag/kpis)
- [SAP Hybris (3)](https://blog.intertecintl.com/tag/sap-hybris)
- [Cloud Security (2)](https://blog.intertecintl.com/tag/cloud-security)
- [20th Anniversary (1)](https://blog.intertecintl.com/tag/20th-anniversary)
- [E-commerce (1)](https://blog.intertecintl.com/tag/e-commerce)

see all

### Posts by Topic

- [Cyber Security (56)](https://blog.intertecintl.com/tag/cyber-security)
- [Technical Support Services (50)](https://blog.intertecintl.com/tag/technical-support-services)
- [Cloud Migration (45)](https://blog.intertecintl.com/tag/cloud-migration)
- [Project Management (31)](https://blog.intertecintl.com/tag/project-management)
- [Software Development (26)](https://blog.intertecintl.com/tag/software-development)
- [Infrastructure (16)](https://blog.intertecintl.com/tag/infrastructure)
- [Remote Work (15)](https://blog.intertecintl.com/tag/remote-work)
- [Recruitment (11)](https://blog.intertecintl.com/tag/recruitment)
- [Near-Shoring (9)](https://blog.intertecintl.com/tag/near-shoring)
- [Quality Assurance (9)](https://blog.intertecintl.com/tag/quality-assurance)
- [Agile (8)](https://blog.intertecintl.com/tag/agile)
- [MDM (8)](https://blog.intertecintl.com/tag/mdm)
- [DevOps (7)](https://blog.intertecintl.com/tag/devops)
- [GRC (7)](https://blog.intertecintl.com/tag/grc)
- [Governance, Risk, and Compliance (7)](https://blog.intertecintl.com/tag/governance-risk-and-compliance)
- [DaaS (6)](https://blog.intertecintl.com/tag/daas)
- [Product Development (6)](https://blog.intertecintl.com/tag/product-development)
- [Test Engineering (5)](https://blog.intertecintl.com/tag/test-engineering)
- [KPIs (3)](https://blog.intertecintl.com/tag/kpis)
- [SAP Hybris (3)](https://blog.intertecintl.com/tag/sap-hybris)
- [Cloud Security (2)](https://blog.intertecintl.com/tag/cloud-security)
- [20th Anniversary (1)](https://blog.intertecintl.com/tag/20th-anniversary)
- [E-commerce (1)](https://blog.intertecintl.com/tag/e-commerce)

See all

### Recent Posts

---

### Find What You're Looking For

### Filter by Topic

- [Cyber Security (56)](https://blog.intertecintl.com/tag/cyber-security)
- [Technical Support Services (50)](https://blog.intertecintl.com/tag/technical-support-services)
- [Cloud Migration (45)](https://blog.intertecintl.com/tag/cloud-migration)
- [Project Management (31)](https://blog.intertecintl.com/tag/project-management)
- [Software Development (26)](https://blog.intertecintl.com/tag/software-development)
- [Infrastructure (16)](https://blog.intertecintl.com/tag/infrastructure)
- [Remote Work (15)](https://blog.intertecintl.com/tag/remote-work)
- [Recruitment (11)](https://blog.intertecintl.com/tag/recruitment)
- [Near-Shoring (9)](https://blog.intertecintl.com/tag/near-shoring)
- [Quality Assurance (9)](https://blog.intertecintl.com/tag/quality-assurance)
- [Agile (8)](https://blog.intertecintl.com/tag/agile)
- [MDM (8)](https://blog.intertecintl.com/tag/mdm)
- [DevOps (7)](https://blog.intertecintl.com/tag/devops)
- [GRC (7)](https://blog.intertecintl.com/tag/grc)
- [Governance, Risk, and Compliance (7)](https://blog.intertecintl.com/tag/governance-risk-and-compliance)
- [DaaS (6)](https://blog.intertecintl.com/tag/daas)
- [Product Development (6)](https://blog.intertecintl.com/tag/product-development)
- [Test Engineering (5)](https://blog.intertecintl.com/tag/test-engineering)
- [KPIs (3)](https://blog.intertecintl.com/tag/kpis)
- [SAP Hybris (3)](https://blog.intertecintl.com/tag/sap-hybris)
- [Cloud Security (2)](https://blog.intertecintl.com/tag/cloud-security)
- [20th Anniversary (1)](https://blog.intertecintl.com/tag/20th-anniversary)
- [E-commerce (1)](https://blog.intertecintl.com/tag/e-commerce)

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Filter Date

- [March 2023 (6)](https://blog.intertecintl.com/archive/2023/03)
- [February 2023 (11)](https://blog.intertecintl.com/archive/2023/02)
- [January 2023 (5)](https://blog.intertecintl.com/archive/2023/01)
- [December 2022 (3)](https://blog.intertecintl.com/archive/2022/12)
- [November 2022 (1)](https://blog.intertecintl.com/archive/2022/11)
- [September 2022 (2)](https://blog.intertecintl.com/archive/2022/09)
- [August 2022 (5)](https://blog.intertecintl.com/archive/2022/08)
- [June 2022 (5)](https://blog.intertecintl.com/archive/2022/06)
- [May 2022 (12)](https://blog.intertecintl.com/archive/2022/05)
- [April 2022 (2)](https://blog.intertecintl.com/archive/2022/04)
- [March 2022 (2)](https://blog.intertecintl.com/archive/2022/03)
- [February 2022 (3)](https://blog.intertecintl.com/archive/2022/02)
- [January 2022 (9)](https://blog.intertecintl.com/archive/2022/01)
- [December 2021 (6)](https://blog.intertecintl.com/archive/2021/12)
- [November 2021 (11)](https://blog.intertecintl.com/archive/2021/11)
- [September 2021 (8)](https://blog.intertecintl.com/archive/2021/09)
- [August 2021 (9)](https://blog.intertecintl.com/archive/2021/08)
- [July 2021 (7)](https://blog.intertecintl.com/archive/2021/07)
- [June 2021 (10)](https://blog.intertecintl.com/archive/2021/06)
- [May 2021 (7)](https://blog.intertecintl.com/archive/2021/05)
- [April 2021 (9)](https://blog.intertecintl.com/archive/2021/04)
- [March 2021 (8)](https://blog.intertecintl.com/archive/2021/03)
- [February 2021 (8)](https://blog.intertecintl.com/archive/2021/02)
- [January 2021 (8)](https://blog.intertecintl.com/archive/2021/01)
- [December 2020 (10)](https://blog.intertecintl.com/archive/2020/12)
- [November 2020 (8)](https://blog.intertecintl.com/archive/2020/11)
- [October 2020 (5)](https://blog.intertecintl.com/archive/2020/10)
- [September 2020 (3)](https://blog.intertecintl.com/archive/2020/09)
- [August 2020 (6)](https://blog.intertecintl.com/archive/2020/08)
- [July 2020 (8)](https://blog.intertecintl.com/archive/2020/07)
- [June 2020 (9)](https://blog.intertecintl.com/archive/2020/06)
- [May 2020 (8)](https://blog.intertecintl.com/archive/2020/05)
- [April 2020 (9)](https://blog.intertecintl.com/archive/2020/04)

[![Contact Us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/7230565/504e5f3a-2b20-4d06-91fd-df5c2b06c682.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/7230565/504e5f3a-2b20-4d06-91fd-df5c2b06c682)

## Subscribe to Our Blog

Get the latest on industry news and Intertec updates!

### Subscribe Here!

[![Logo_Full name_white](https://blog.intertecintl.com/hs-fs/hubfs/Logo_Full%20name_white.png?width=1920&height=1080&name=Logo_Full%20name_white.png "Logo_Full name_white")](http://Intertec%20International)

![SAP Silver Partner](https://blog.intertecintl.com/hubfs/Footer/sap-partner.png "SAP Silver Partner")

![Microsoft Partner](https://blog.intertecintl.com/hubfs/Footer/logo-micro-footer.png "Microsoft Partner")

Company

[About Us](https://www.intertecintl.com/about)

[Why Nearshore?](https://www.intertecintl.com/why-nearshore) [Locations & Contact](https://www.intertecintl.com/contact) [Privacy Policy](https://www.intertecintl.com/privacy-policy)

Services & Solutions

[IT Services](https://www.intertecintl.com/it-services) <https://www.intertecintl.com/tech-services>[Information Security Management System Policy](https://www.intertecintl.com/information-security-management-system-policy)

Resources

[Blog](https://blog.intertecintl.com/) [Careers](https://www.intertecintl.com/careers) [Resources](https://info.intertecintl.com/remote-office-worker)

Copyright ©  Intertec International. All Rights Reserved.<https://www.aspiration.marketing>

<https://www.facebook.com/IntertecInternational> <https://www.youtube.com/user/IntertecIntl> <https://www.linkedin.com/company/intertec-international>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Frederid Palacios",
    "url" : "https://blog.intertecintl.com/author/frederid-palacios"
  },
  "dateModified" : "2021-04-01T16:00:00.968Z",
  "datePublished" : "2021-04-01T16:00:00.000Z",
  "headline" : "Nothing is More Critical Than an ISO 27001 Statement of Applicability",
  "image" : [ "https://blog.intertecintl.com/hubfs/Risk%20Assessment.%20Business%20Concept%20on%20Blurred%20Background.%20Office%20Folder%20with%20Inscription%20Risk%20Assessment%20on%20Working%20Desktop.%20Risk%20Assessment%20-%20Concept.%203D..jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.intertecintl.com/nothing-is-more-important-to-your-iso-27001-than-your-statement-of-applicability",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.intertecintl.com/hubfs/Logo_web.png"
    },
    "name" : "Intertec International"
  }
}
```