STATEMENT OF APPLICABILITY
Legal name of the entity
Effective Date
ISMS Owner Name or role (for example CISO)
Themes applicable 4 of 4 Basis
ISO/IEC 27001 cl.6.1.3 ISO/IEC 27002:2022 The Statement of Applicability is a mandatory ISMS document. It records which Annex A controls apply, the justification, and any exclusions with reasons.
1. ISMS scope
Legal name of the entity operates an ISMS owned by Name or role (for example CISO) . Scope: ISMS scope .
2. Control themes
Applicability of the ISO/IEC 27002:2022 control themes:
Theme Controls Applicability A.5 Organizational 37 Applicable A.6 People 8 Applicable A.7 Physical 14 Applicable A.8 Technological 34 Applicable
3. Exclusions
The following controls are excluded with justification:
Control Reason for exclusion __GAP[exclusions Excluded controls]__
4. Approval
Approved by Name and designation on [date].
Approved by
Name and designation
______________________
ISMS Owner
Name or role (for example CISO)
______________________