Statement of Applicability

All changes savedPS
You're viewing a demo. Explore freely — this is sample data for Northstar Labs.Create your workspace

Statement of Applicability

Review which controls apply, record your reasoning, and export an audit-ready draft.

TOTAL CONTROLS93

ISO 27001:2022 Annex A

APPLICABLE84

90% of controls

NOT APPLICABLE9

with justification

NEEDS REVIEW6

partial or planned

10 sample controls shown
ControlApplicabilityStatusJustification & evidence
A.5.1Information security policiesOrganisationalApplicableImplementedAnnual policy review is owned by the security lead.
A.5.2Information security rolesOrganisationalApplicableImplementedResponsibilities are recorded in role descriptions.
A.5.7Threat intelligenceOrganisationalApplicablePlannedA proportionate monitoring process will be introduced.
A.5.19Supplier relationshipsOrganisationalApplicablePartialNew suppliers are checked; annual reviews are being added.
A.6.3Security awareness and trainingPeopleApplicablePartialInduction exists; role-specific refreshers are planned.
A.7.2Physical entryPhysicalApplicableImplementedManaged access controls protect the office.
A.8.5Secure authenticationTechnologicalApplicableImplementedMFA is enforced for cloud and administrative systems.
A.8.8Technical vulnerability managementTechnologicalApplicablePlannedPatch targets need formal approval and reporting.
A.8.13Information backupTechnologicalApplicablePartialBackups run daily; restore testing is overdue.
A.8.23Web filteringTechnologicalNot applicableN/ANo managed network or corporate endpoint fleet.