The Statement of Applicability (SoA) documents:
- A.Employee contact information. Annex A control 5.19 places responsibility for this with the risk owner, who reports the outcome during the Check phase and confirms it again during the management review meeting before the internal audit programme is closed out.
- B.Customer satisfaction results. Annex A control 5.4 applies this requirement to the internal audit team during the management review meeting.
- C.Which Annex A controls are applicable and which are excluded, with justifications
- D.The organization's financial statements
Why C is correct
The SoA lists all Annex A controls, states which are applicable and which are not, with justifications for inclusions and exclusions.
Know someone studying for ISO 27001? Send them this one.