The Statement of Applicability (SoA) in ISO 18788: Defining, Justifying, and Demonstrating Security Controls

Introduction

The Statement of Applicability (SoA) is one of the most critical documents in a Security Operations Management System (SOMS) under ISO 18788:2015. It demonstrates how an organization identifies, selects, implements, and justifies security controls to manage risks effectively. The concept of the SoA is adapted from ISO/IEC 27001:2022 (Information Security Management Systems) and further explained in ISO/IEC 27003:2020, where it forms the backbone of transparency, accountability, and international certification.

The SoA provides stakeholders—clients, regulators, auditors, and employees—with documented assurance that the organization has systematically addressed applicable risks, and has justified any controls it excludes.

Purpose of the Statement of Applicability

The SoA serves four primary functions:

  1. Reference to Controls - It lists all controls from applicable frameworks (Annex A of ISO/IEC 27001 and the operational/contractual controls from ISO 18788).
  2. Justification of Inclusion - It explains why specific controls are applicable and necessary.
  3. Justification of Exclusion - It provides clear reasons why certain controls are not relevant to the organization's scope or context.
  4. Implementation Status - It documents whether controls are in place, partially implemented, or planned, ensuring transparency for certification and audits.

Justification of Inclusions

The inclusion of controls must be based on:

  • Risk Treatment Results: Controls directly linked to unacceptable risks identified in the risk assessment.
  • Legal and Regulatory Obligations: Controls required by law, contracts, or licensing requirements.
  • Human Rights and Ethical Commitments: Controls that uphold accountability, proportionality, and respect for rights (core to ISO 18788).
  • Stakeholder Expectations: Clients, partners, and regulators may demand specific controls.
  • Operational Requirements: Controls necessary to ensure efficiency, resilience, and continuity.

Inclusions must be justified with a direct linkage between risks, obligations, and business objectives.

Justification of Exclusions

The exclusion of controls is equally important. A control may be excluded only if:

  • Irrelevant to the Scope: The activity or risk does not exist within the defined SOMS scope (e.g., excluding physical datacentre security if no datacentres are owned).
  • Covered by Other Measures: Equivalent or alternative controls exist and provide equal or stronger protection.
  • Not Applicable to Operational Model: Certain Annex controls may not apply to the industry, geography, or type of service delivered.

Each exclusion must be explicitly documented and supported by reasoned justification. Auditors and certification bodies require this to avoid perceptions of negligence or selective compliance.

Alignment with ISO 27001 and ISO 27003

#BBD0E0 »