How should teams justify Statement of Applicability exclusions under ISO/IEC 27001?
Start with the risk-treatment process, not the Annex A table. Clause 6.1.3 requires the organization to determine every control necessary for its chosen treatments, compare those controls with Annex A to verify that none were overlooked, and then explain any Annex A exclusions in the .
An is defensible when the organization can show why that reference control is not necessary in the scoped ISMS. The reason may follow from scope, technology, locations, information handled, interfaces, dependencies, assessed risks, or applicable requirements. Another control may contribute to the explanation, but naming an alternative alone does not show that the Annex A control is unnecessary.
- State the Annex A control identifier, exclusion rationale, scope facts, risks considered, and any alternative control or dependency relevant to the decision.
- Check the exclusion against applicable legal, regulatory, contractual, and interested-party requirements before approval.
- Do not use exclusion to hide a that is planned but not yet implemented; the SoA can record a necessary control as not implemented.
- Decision sequence: define scope and applicable requirements; assess risk; select treatment options; determine necessary controls from any source; compare them with Annex A; record inclusion, implementation, and exclusion rationales; obtain the required risk-owner approvals; then review the SoA when its basis changes.
ISO/IEC 27001:2022 clause 6.1.3 requires necessary-control determination, comparison with Annex A, and an SoA containing implementation status and justification for excluded Annex A controls.
ISO/IEC 27002:2022 provides guidance for the Annex A reference controls and can help assess their purpose and implementation context.