Case study #2 – selection of controls and the Statement of Applicability
The SoA is an essential document that defines which controls from Annex A of ISO 27001 are being implemented in the organization and how, which controls will not be implemented, and the reason for their elimination (this reflects the risk appetite of the organization). When preparing an SoA, it is important to note that not all controls are mandatory for implementation. The selection of controls should be based on the organization’s risk assessment, business requirements, and the specific context of the ISMS. This allows organizations to tailor the controls to their specific needs, ensuring a more efficient and effective implementation of the ISMS.
Tables 7.1, 7.2, 7.3, and 7.4 list the organizational, people, physical, and technological controls, respectively. Together, they form the SoA for the ISMS implemented at Titan Security Inc.
Organizational controls
ISO 27001:2022 incorporates...