OSCAL
ISO/IEC 27001:2022 SoA profile
Projection of profile.json. How to read it: `USER-MANUAL`. Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.
- Imports
./catalog.jsonwith **include-all**. N/A rows are not excluded (excludes-not-applicable=false). - Clauses: **25**. Annex A applicable: **89**. Annex A N/A: **4**.
- Source:
SOA_Statement_of_Applicability_SoA_Example.json.
| ISO ID | Title | Applicability | Implementation | Justification |
|---|---|---|---|---|
| 4.1 | Understanding the organization and its context | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 4.2 | Understanding the needs and expectations of interested parties | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 4.3 | Determining the scope of the ISMS | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 4.4 | Information security management system | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 5.1 | Leadership and commitment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 5.2 | Information security policy | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 5.3 | Organizational roles, responsibilities and authorities | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 6.1.1 | Actions to address risks and opportunities | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 6.1.2 | Information security risk assessment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 6.1.3 | Information security risk treatment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 6.2 | Information security objectives and planning to achieve them | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 6.3 | Planning of changes | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 7.1 | Resources | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 7.2 | Competence | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 7.3 | Awareness | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 7.4 | Communication | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 7.5 | Documented information | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 8.1 | Operational planning and control | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 8.2 | Information security risk assessment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 8.3 | Information security risk treatment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 9.1 | Monitoring, measurement, analysis and evaluation | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 9.2 | Internal audit | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 9.3 | Management review | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 10.1 | Continual improvement | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| 10.2 | Nonconformity and corrective action | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| A.5.1 | Policies for information security | applicable | Implemented | Required for ISMS governance and policy direction. |
| A.5.2 | Information security roles and responsibilities | applicable | Implemented | Required for assigning ISMS accountability. |
| A.5.3 | Segregation of duties | applicable | In progress | Relevant to privileged administration and approval workflows. |
| A.5.4 | Management responsibilities | applicable | Implemented | Required for management commitment and oversight. |
| A.5.5 | Contact with authorities | applicable | Implemented | Required for incident and regulatory escalation. |
| A.5.6 | Contact with special interest groups | applicable | Implemented | Relevant for threat intelligence and software security updates. |
| A.5.7 | Threat intelligence | applicable | In progress | Required for software and cloud threat awareness. |
| A.5.8 | Information security in project management | applicable | Implemented | Required for product and ISMS implementation projects. |
| A.5.9 | Inventory of information and other associated assets | applicable | Implemented | Required because in-scope assets support customer, HR, code, identity and evidence processes. |
| A.5.10 | Acceptable use of information and other associated assets | applicable | Implemented | Required for user obligations on company assets and services. |
| A.5.11 | Return of assets | applicable | Implemented | Required during offboarding and role changes. |
| A.5.12 | Classification of information | applicable | Implemented | Required for handling and protection decisions. |
| A.5.13 | Labelling of information | applicable | Implemented | Required to communicate classification handling. |
| A.5.14 | Information transfer | applicable | Implemented | Required for customer, supplier and audit information transfer. |
| A.5.15 | Access control | applicable | Implemented | Required to protect production, identity, HR and evidence systems. |
| A.5.16 | Identity management | applicable | Implemented | Required for lifecycle management of user identities. |
| A.5.17 | Authentication information | applicable | Implemented | Required for authentication secrets and recovery. |
| A.5.18 | Access rights | applicable | Implemented | Required to grant, review and revoke access rights. |
| A.5.19 | Information security in supplier relationships | applicable | In progress | Required for cloud and SaaS supplier dependencies. |
| A.5.20 | Addressing information security within supplier agreements | applicable | In progress | Required for supplier security terms. |
| A.5.21 | Managing information security in the ICT supply chain | applicable | Planned | Required for SaaS, repository, identity and hosting chain. |
| A.5.22 | Monitoring, review and change management of supplier services | applicable | In progress | Required for supplier performance and changes. |
| A.5.23 | Information security for use of cloud services | applicable | In progress | Required because core services are cloud and SaaS based. |
| A.5.24 | Information security incident management planning and preparation | applicable | Implemented | Required for incident readiness. |
| A.5.25 | Assessment and decision on information security events | applicable | Implemented | Required for event triage. |
| A.5.26 | Response to information security incidents | applicable | Implemented | Required for incident handling. |
| A.5.27 | Learning from information security incidents | applicable | Planned | Required for improvement after incidents. |
| A.5.28 | Collection of evidence | applicable | Implemented | Required for audit and incident evidence. |
| A.5.29 | Information security during disruption | applicable | Implemented | Required for continuity of critical services. |
| A.5.30 | ICT readiness for business continuity | applicable | In progress | Required for ICT continuity readiness. |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | applicable | Implemented | Required for legal and contractual obligations. |
| A.5.32 | Intellectual property rights | applicable | Planned | Required for software, content and third-party licenses. |
| A.5.33 | Protection of records | applicable | Implemented | Required to protect ISMS and operational records. |
| A.5.34 | Privacy and protection of PII | applicable | Implemented | Required because HR and customer personal data are processed. |
| A.5.35 | Independent review of information security | applicable | Implemented | Required to review ISMS effectiveness independently. |
| A.5.36 | Compliance with policies, rules and standards for information security | applicable | Implemented | Required to verify compliance with ISMS requirements. |
| A.5.37 | Documented operating procedures | applicable | In progress | Required for repeatable ISMS and IT operations. |
| A.6.1 | Screening | applicable | Implemented | Required for relevant roles before employment. |
| A.6.2 | Terms and conditions of employment | applicable | Implemented | Required for contractual security obligations. |
| A.6.3 | Information security awareness, education and training | applicable | Implemented | Required for staff and contractors. |
| A.6.4 | Disciplinary process | applicable | Planned | Required for security policy violations. |
| A.6.5 | Responsibilities after termination or change of employment | applicable | Implemented | Required for offboarding and role changes. |
| A.6.6 | Confidentiality or non-disclosure agreements | applicable | Implemented | Required for personnel, contractors and suppliers. |
| A.6.7 | Remote working | applicable | Implemented | Required because staff work remotely. |
| A.6.8 | Information security event reporting | applicable | Implemented | Required so personnel report security events. |
| A.7.1 | Physical security perimeters | applicable | Implemented | Relevant for office and equipment storage. |
| A.7.2 | Physical entry | applicable | Implemented | Relevant for controlled office access. |
| A.7.3 | Securing offices, rooms and facilities | applicable | Implemented | Relevant for office workspaces and records. |
| A.7.4 | Physical security monitoring | applicable | In progress | Relevant to office and equipment monitoring. |
| A.7.5 | Protecting against physical and environmental threats | applicable | Planned | Relevant to equipment and office availability. |
| A.7.6 | Working in secure areas | not-applicable | Not applicable | Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield. |
| A.7.7 | Clear desk and clear screen | applicable | Implemented | Relevant for office and remote working. |
| A.7.8 | Equipment siting and protection | applicable | Implemented | Relevant for endpoint and office equipment. |
| A.7.9 | Security of assets off-premises | applicable | Implemented | Required for laptops and remote work. |
| A.7.10 | Storage media | applicable | Implemented | Relevant to endpoint media and backups. |
| A.7.11 | Supporting utilities | not-applicable | Not applicable | Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance. |
| A.7.12 | Cabling security | not-applicable | Not applicable | Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services. |
| A.7.13 | Equipment maintenance | applicable | Implemented | Relevant to managed endpoint fleet. |
| A.7.14 | Secure disposal or re-use of equipment | applicable | Implemented | Required for endpoint disposal and reuse. |
| A.8.1 | User endpoint devices | applicable | Implemented | Required for managed laptop fleet. |
| A.8.2 | Privileged access rights | applicable | In progress | Required for production and identity administration. |
| A.8.3 | Information access restriction | applicable | Implemented | Required for restricted repositories and production data. |
| A.8.4 | Access to source code | applicable | Implemented | Required for source repositories. |
| A.8.5 | Secure authentication | applicable | Implemented | Required for cloud, SaaS and repository access. |
| A.8.6 | Capacity management | applicable | Planned | Required for service availability. |
| A.8.7 | Protection against malware | applicable | Implemented | Required for endpoints and repositories. |
| A.8.8 | Management of technical vulnerabilities | applicable | In progress | Required for software and cloud services. |
| A.8.9 | Configuration management | applicable | In progress | Required for identity, cloud, endpoint and application configuration. |
| A.8.10 | Information deletion | applicable | In progress | Required for retention and offboarding. |
| A.8.11 | Data masking | applicable | Planned | Relevant to test data and support access. |
| A.8.12 | Data leakage prevention | applicable | Planned | Relevant to customer and HR data transfer. |
| A.8.13 | Information backup | applicable | Implemented | Required for availability and evidence integrity. |
| A.8.14 | Redundancy of information processing facilities | applicable | Implemented | Required where supplier redundancy is relied on. |
| A.8.15 | Logging | applicable | Implemented | Required for security monitoring and investigation. |
| A.8.16 | Monitoring activities | applicable | In progress | Required for detecting security events. |
| A.8.17 | Clock synchronization | applicable | Implemented | Required for reliable logging and investigations. |
| A.8.18 | Use of privileged utility programs | applicable | In progress | Relevant to administrative tooling. |
| A.8.19 | Installation of software on operational systems | applicable | Implemented | Required for production and endpoint change control. |
| A.8.20 | Networks security | applicable | Implemented | Required for cloud and office connectivity. |
| A.8.21 | Security of network services | applicable | Implemented | Relevant to supplier and cloud network services. |
| A.8.22 | Segregation of networks | applicable | In progress | Required for production and management separation. |
| A.8.23 | Web filtering | applicable | Planned | Relevant to endpoint protection and acceptable use. |
| A.8.24 | Use of cryptography | applicable | Implemented | Required for confidentiality and integrity. |
| A.8.25 | Secure development life cycle | applicable | Implemented | Required for customer portal software development. |
| A.8.26 | Application security requirements | applicable | In progress | Required for customer portal requirements. |
| A.8.27 | Secure system architecture and engineering principles | applicable | Planned | Required for architecture of in-scope systems. |
| A.8.28 | Secure coding | applicable | Implemented | Required for developed software. |
| A.8.29 | Security testing in development and acceptance | applicable | In progress | Required before software release. |
| A.8.30 | Outsourced development | not-applicable | Not applicable | Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff. |
| A.8.31 | Separation of development, test and production environments | applicable | Implemented | Required for safe software delivery. |
| A.8.32 | Change management | applicable | Implemented | Required for changes to systems and services. |
| A.8.33 | Test information | applicable | Planned | Required to protect production data in testing. |
| A.8.34 | Protection of information systems during audit testing | applicable | Implemented | Required to protect systems during internal and external audit testing. |
Not applicable (stay visible)
| ISO ID | Title | Applicability | Implementation | Justification |
|---|---|---|---|---|
| A.7.6 | Working in secure areas | not-applicable | Not applicable | Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield. |
| A.7.11 | Supporting utilities | not-applicable | Not applicable | Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance. |
| A.7.12 | Cabling security | not-applicable | Not applicable | Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services. |
| A.8.30 | Outsourced development | not-applicable | Not applicable | Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff. |
