Statement of Applicability
Review which controls apply, record your reasoning, and export an audit-ready draft.
TOTAL CONTROLS93
ISO 27001:2022 Annex A
APPLICABLE84
90% of controls
NOT APPLICABLE9
with justification
NEEDS REVIEW6
partial or planned
10 sample controls shown
| Control | Applicability | Status | Justification & evidence |
|---|---|---|---|
A.5.1Information security policiesOrganisational | Applicable | Implemented | Annual policy review is owned by the security lead. |
A.5.2Information security rolesOrganisational | Applicable | Implemented | Responsibilities are recorded in role descriptions. |
A.5.7Threat intelligenceOrganisational | Applicable | Planned | A proportionate monitoring process will be introduced. |
A.5.19Supplier relationshipsOrganisational | Applicable | Partial | New suppliers are checked; annual reviews are being added. |
A.6.3Security awareness and trainingPeople | Applicable | Partial | Induction exists; role-specific refreshers are planned. |
A.7.2Physical entryPhysical | Applicable | Implemented | Managed access controls protect the office. |
A.8.5Secure authenticationTechnological | Applicable | Implemented | MFA is enforced for cloud and administrative systems. |
A.8.8Technical vulnerability managementTechnological | Applicable | Planned | Patch targets need formal approval and reporting. |
A.8.13Information backupTechnological | Applicable | Partial | Backups run daily; restore testing is overdue. |
A.8.23Web filteringTechnological | Not applicable | N/A | No managed network or corporate endpoint fleet. |