From books

Controls come out of risk treatment, and Annex A is only the check that nothing was forgotten; the Statement of Applicability records both decisions.

ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, clauza 6.1.3 litera d) — conținutul obligatoriu al Declarației de aplicabilitate2 minutes read
produce a Statement of Applicability that contains: the necessary controls (see 6.1.3 b) and c)); justification for their inclusion; whether the necessary controls are implemented or not; and the justification for excluding any of the Annex A controls.ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, clauza 6.1.3 litera d) — conținutul obligatoriu al Declarației de aplicabilitate

Annex A is the safety net under your list of controls, not its source.

Almost every beginner reads the order of 6.1.3 backwards. It does not start from Annex A. First the treatment options are chosen, taking account of the assessment results; then all controls necessary to implement the chosen options are determined — the standard says plainly that they may be designed by the organization or identified from any source; only then is the resulting list compared with Annex A, as a cross-check that nothing necessary has been omitted. The outcome is recorded in the Statement of Applicability, the one document that ties risks to controls. It says four things about each control: that it is necessary, why it was included, whether it is implemented or not, and why any Annex A control was excluded. A necessary control that is not yet implemented is allowed to appear there; what is not allowed is silence. Finally, the treatment plan and the acceptance of residual risk are approved by the risk owners.

Why it mattersThe Statement of Applicability is the first document asked for at stage 1 and the only one that shows whether the system really started from risk.

TreatmentoptionsThenecessaryCross-checkagainstStatementof
Annex A enters at step three, not at step one.

Back to the feed