A Statement of Applicability, also known as an SoA, is a document that assesses an organization's security risks and outlines the specific controls that have been put in place to mitigate those risks. An SoA is typically required as part of a compliance audit, such as ISO 27001 or SOC 2.
An SoA is divided into three sections:
 

1. The first section lists all security risks that have been identified for the organization in question.
2. The second section describes the specific controls that have been implemented to mitigate those risks.
3. The third section outlines the planned future measures the organization will take to further reduce its risk profile.

The content of a Statement of Applicability depends on the specific compliance requirements an organization is trying to meet. However, all Statements of Applicability should be clear, concise, and easy to understand.

Why Are Statements of Applicability Important?

Organizations use Statements of Applicability to demonstrate their commitment to security and to show that they have taken steps to address their specific security risks. For example, a Statement of Applicability may be requested by a potential customer or business partner as part of due diligence. In any case, an SoA is an important document that can help build trust in a company's security posture.

How Do I Create a Statement of Applicability?

The process for creating a Statement of Applicability depends on the specific compliance requirements you are trying to meet. However, there are some general best practices you should follow when creating an SoA:
 

1. Make sure your Statement of Applicability is clear, concise, and easy to understand. Keep in mind that your audience may not be familiar with technical jargon or industry-specific terminology.
2. Use plain language and avoid abbreviations or acronyms where possible.
3. Be honest and transparent in your risk assessment, and don't try to downplay the significance of any particular control.
4. Provide a contact name and email address so readers can obtain further information if needed.
5. Review your SoA regularly and update it whenever your security posture changes (e.g., after implementing new controls or when an incident occurs).

Conclusion

Companies use Statements of Applicability to demonstrate their commitment to security and to outline the steps they have taken to address their specific security risks. Creating a well-crafted Statement of Applicability requires taking some time upfront to assess your organization's risks and determine which controls are appropriate to mitigate them.