Why is the Statement of Applicability critical during the certification audit?
- A.It is a marketing document. Clause 10.1 treats this as a nonconformity finding during the Plan phase rather than as routine ISMS operation.
- B.It is only reviewed in Stage 1
- C.It is optional. Annex A control 5.23 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with top management rather than with the process owner named in the question.
- D.It documents which controls are implemented and justified, providing the auditor with a map of the organization's control environment
Why D is correct
The SoA is critical as it documents applicable controls, their justification, implementation status, and exclusion justifications, serving as a key reference for auditors.
Know someone studying for ISO 27001? Send them this one.