Statement of Applicability (SoA)
The ISO/IEC 27001 SoA ISO/IEC 27001:2022 — for every control in the library, declare whether it is Applicable, record its implementation status, and give a justification for including it (or excluding it as Not applicable). It is the auditor's index into your control set. Set a control's status and notes on its control page; an applicable control with no justification is flagged on the POA&M.
188
Controls
188
Applicable
0
Excluded
188
Unjustified
Export — ⇩ soa.csv
| Control | Title | Applicability | Implementation | Justification |
|---|---|---|---|---|
| AC-1 | Policy and Procedures (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-2 | Account Management (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-3 | Access Enforcement (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-4 | Information Flow Enforcement (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-5 | Separation of Duties (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-6 | Least Privilege (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-7 | Unsuccessful Logon Attempts (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-8 | System Use Notification (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-10 | Concurrent Session Control (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-11 | Device Lock (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-12 | Session Termination (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-14 | Permitted Actions Without Identification or Authentication (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-17 | Remote Access (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-18 | Wireless Access (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-19 | Access Control for Mobile Devices (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-20 | Use of External Systems (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-21 | Information Sharing (AC) | Applicable | Not implemented | ⚠ add a justification |
| AC-22 | Publicly Accessible Content (AC) | Applicable | Not implemented | ⚠ add a justification |
| AT-1 | Policy and Procedures (AT) | Applicable | Not implemented | ⚠ add a justification |
| AT-2 | Literacy Training and Awareness (AT) | Applicable | Not implemented | ⚠ add a justification |
| AT-3 | Role-based Training (AT) | Applicable | Not implemented | ⚠ add a justification |
| AT-4 | Training Records (AT) | Applicable | Not implemented | ⚠ add a justification |
| AU-1 | Policy and Procedures (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-2 | Event Logging (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-3 | Content of Audit Records (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-4 | Audit Log Storage Capacity (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-5 | Response to Audit Logging Process Failures (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-6 | Audit Record Review, Analysis, and Reporting (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-7 | Audit Record Reduction and Report Generation (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-8 | Time Stamps (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-9 | Protection of Audit Information (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-10 | Non-repudiation (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-11 | Audit Record Retention (AU) | Applicable | Not implemented | ⚠ add a justification |
| AU-12 | Audit Record Generation (AU) | Applicable | Not implemented | ⚠ add a justification |
| CA-1 | Policy and Procedures (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-2 | Control Assessments (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-3 | Information Exchange (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-5 | Plan of Action and Milestones (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-6 | Authorization (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-7 | Continuous Monitoring (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-8 | Penetration Testing (CA) | Applicable | Not implemented | ⚠ add a justification |
| CA-9 | Internal System Connections (CA) | Applicable | Not implemented | ⚠ add a justification |
| CM-1 | Policy and Procedures (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-2 | Baseline Configuration (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-3 | Configuration Change Control (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-4 | Impact Analyses (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-5 | Access Restrictions for Change (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-6 | Configuration Settings (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-7 | Least Functionality (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-8 | System Component Inventory (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-9 | Configuration Management Plan (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-10 | Software Usage Restrictions (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-11 | User-installed Software (CM) | Applicable | Not implemented | ⚠ add a justification |
| CM-12 | Information Location (CM) | Applicable | Not implemented | ⚠ add a justification |
| CP-1 | Policy and Procedures (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-2 | Contingency Plan (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-3 | Contingency Training (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-4 | Contingency Plan Testing (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-6 | Alternate Storage Site (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-7 | Alternate Processing Site (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-8 | Telecommunications Services (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-9 | System Backup (CP) | Applicable | Not implemented | ⚠ add a justification |
| CP-10 | System Recovery and Reconstitution (CP) | Applicable | Not implemented | ⚠ add a justification |
| IA-1 | Policy and Procedures (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-2 | Identification and Authentication (Organizational Users) (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-3 | Device Identification and Authentication (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-4 | Identifier Management (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-5 | Authenticator Management (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-6 | Authentication Feedback (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-7 | Cryptographic Module Authentication (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-8 | Identification and Authentication (Non-organizational Users) (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-11 | Re-authentication (IA) | Applicable | Not implemented | ⚠ add a justification |
| IA-12 | Identity Proofing (IA) | Applicable | Not implemented | ⚠ add a justification |
| IR-1 | Policy and Procedures (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-2 | Incident Response Training (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-3 | Incident Response Testing (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-4 | Incident Handling (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-5 | Incident Monitoring (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-6 | Incident Reporting (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-7 | Incident Response Assistance (IR) | Applicable | Not implemented | ⚠ add a justification |
| IR-8 | Incident Response Plan (IR) | Applicable | Not implemented | ⚠ add a justification |
| MA-1 | Policy and Procedures (MA) | Applicable | Not implemented | ⚠ add a justification |
| MA-2 | Controlled Maintenance (MA) | Applicable | Not implemented | ⚠ add a justification |
| MA-3 | Maintenance Tools (MA) | Applicable | Not implemented | ⚠ add a justification |
| MA-4 | Nonlocal Maintenance (MA) | Applicable | Not implemented | ⚠ add a justification |
| MA-5 | Maintenance Personnel (MA) | Applicable | Not implemented | ⚠ add a justification |
| MA-6 | Timely Maintenance (MA) | Applicable | Not implemented | ⚠ add a justification |
| MP-1 | Policy and Procedures (MP) | Applicable | Not implemented | ⚠ add a justification |
| MP-2 | Media Access (MP) | Applicable | Not implemented | ⚠ add a justification |
| MP-3 | Media Marking (MP) | Applicable | Not implemented | ⚠ add a justification |
| MP-4 | Media Storage (MP) | Applicable | Not implemented | ⚠ add a justification |
| MP-5 | Media Transport (MP) | Applicable | Not implemented | ⚠ add a justification |
| MP-6 | Media Sanitization (MP) | Applicable | Not implemented | ⚠ add a justification |
| MP-7 | Media Use (MP) | Applicable | Not implemented | ⚠ add a justification |
| PE-1 | Policy and Procedures (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-2 | Physical Access Authorizations (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-3 | Physical Access Control (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-4 | Access Control for Transmission (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-5 | Access Control for Output Devices (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-6 | Monitoring Physical Access (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-8 | Visitor Access Records (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-9 | Power Equipment and Cabling (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-10 | Emergency Shutoff (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-11 | Emergency Power (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-12 | Emergency Lighting (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-13 | Fire Protection (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-14 | Environmental Controls (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-15 | Water Damage Protection (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-16 | Delivery and Removal (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-17 | Alternate Work Site (PE) | Applicable | Not implemented | ⚠ add a justification |
| PE-18 | Location of System Components (PE) | Applicable | Not implemented | ⚠ add a justification |
| PL-1 | Policy and Procedures (PL) | Applicable | Not implemented | ⚠ add a justification |
| PL-2 | System Security and Privacy Plans (PL) | Applicable | Not implemented | ⚠ add a justification |
| PL-4 | Rules of Behavior (PL) | Applicable | Not implemented | ⚠ add a justification |
| PL-8 | Security and Privacy Architectures (PL) | Applicable | Not implemented | ⚠ add a justification |
| PL-10 | Baseline Selection (PL) | Applicable | Not implemented | ⚠ add a justification |
| PL-11 | Baseline Tailoring (PL) | Applicable | Not implemented | ⚠ add a justification |
| PS-1 | Policy and Procedures (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-2 | Position Risk Designation (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-3 | Personnel Screening (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-4 | Personnel Termination (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-5 | Personnel Transfer (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-6 | Access Agreements (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-7 | External Personnel Security (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-8 | Personnel Sanctions (PS) | Applicable | Not implemented | ⚠ add a justification |
| PS-9 | Position Descriptions (PS) | Applicable | Not implemented | ⚠ add a justification |
| RA-1 | Policy and Procedures (RA) | Applicable | Not implemented | ⚠ add a justification |
| RA-2 | Security Categorization (RA) | Applicable | Not implemented | ⚠ add a justification |
| RA-3 | Risk Assessment (RA) | Applicable | Not implemented | ⚠ add a justification |
| RA-5 | Vulnerability Monitoring and Scanning (RA) | Applicable | Not implemented | ⚠ add a justification |
| RA-7 | Risk Response (RA) | Applicable | Not implemented | ⚠ add a justification |
| RA-9 | Criticality Analysis (RA) | Applicable | Not implemented | ⚠ add a justification |
| SA-1 | Policy and Procedures (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-2 | Allocation of Resources (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-3 | System Development Life Cycle (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-4 | Acquisition Process (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-5 | System Documentation (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-8 | Security and Privacy Engineering Principles (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-9 | External System Services (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-10 | Developer Configuration Management (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-11 | Developer Testing and Evaluation (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-15 | Development Process, Standards, and Tools (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-16 | Developer-Provided Training (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-17 | Developer Security and Privacy Architecture and Design (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-21 | Developer Screening (SA) | Applicable | Not implemented | ⚠ add a justification |
| SA-22 | Unsupported System Components (SA) | Applicable | Not implemented | ⚠ add a justification |
| SC-1 | Policy and Procedures (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-2 | Separation of System and User Functionality (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-3 | Security Function Isolation (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-4 | Information in Shared System Resources (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-5 | Denial-of-service Protection (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-7 | Boundary Protection (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-8 | Transmission Confidentiality and Integrity (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-10 | Network Disconnect (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-12 | Cryptographic Key Establishment and Management (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-13 | Cryptographic Protection (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-15 | Collaborative Computing Devices and Applications (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-17 | Public Key Infrastructure Certificates (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-18 | Mobile Code (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-20 | Secure Name/Address Resolution Service (Authoritative Source) (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-22 | Architecture and Provisioning for Name/Address Resolution Service (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-23 | Session Authenticity (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-24 | Fail in Known State (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-28 | Protection of Information at Rest (SC) | Applicable | Not implemented | ⚠ add a justification |
| SC-39 | Process Isolation (SC) | Applicable | Not implemented | ⚠ add a justification |
| SI-1 | Policy and Procedures (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-2 | Flaw Remediation (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-3 | Malicious Code Protection (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-4 | System Monitoring (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-5 | Security Alerts, Advisories, and Directives (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-6 | Security and Privacy Function Verification (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-7 | Software, Firmware, and Information Integrity (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-8 | Spam Protection (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-10 | Information Input Validation (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-11 | Error Handling (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-12 | Information Management and Retention (SI) | Applicable | Not implemented | ⚠ add a justification |
| SI-16 | Memory Protection (SI) | Applicable | Not implemented | ⚠ add a justification |
| SR-1 | Policy and Procedures (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-2 | Supply Chain Risk Management Plan (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-3 | Supply Chain Controls and Processes (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-5 | Acquisition Strategies, Tools, and Methods (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-6 | Supplier Assessments and Reviews (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-8 | Notification Agreements (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-9 | Tamper Resistance and Detection (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-10 | Inspection of Systems or Components (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-11 | Component Authenticity (SR) | Applicable | Not implemented | ⚠ add a justification |
| SR-12 | Component Disposal (SR) | Applicable | Not implemented | ⚠ add a justification |