Auditen
Home / Glossary / Statement of Applicability

Statement of Applicability

Also known as: SoA, Control Selection Document, Applicability Matrix

A Statement of Applicability is a document that identifies which security controls from a specific framework, such as ISO 27001, an organization has chosen to implement. It provides a clear justification for why certain controls are included and explains why others were excluded based on the organization's risk assessment.

In practice

An auditor uses this document as a checklist or roadmap to verify compliance; if a control is marked "applicable" in the SoA, the auditor will require evidence that it is functioning effectively. For example, if the SoA lists physical entry controls as applicable, the auditor will inspect badge logs and security cameras.

More terms