ISO 27001
Security

Statement of Applicability Template

Annex A control selection and justification.

What This Policy Covers

Introduction-Purpose and scope.
Organizational Controls-A.5 controls.
People Controls-A.6 controls.
Physical Controls-A.7 controls.
Technological Controls-A.8 controls.

Required Sections

A compliant Statement of Applicability for ISO 27001 must include the following5 sections. Each section addresses a specific control requirement that auditors will review.

1

Introduction

Purpose and scope.

2

Organizational Controls

A.5 controls.

3

People Controls

A.6 controls.

4

Physical Controls

A.7 controls.

5

Technological Controls

A.8 controls.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Statement of Applicability that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.