# ISO/IEC 27001:2022 SoA profile

Projection of `profile.json`. How to read it: [`USER-MANUAL`](./oscal-guide.md). Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.

- Imports `./catalog.json` with **include-all**. N/A rows are not excluded (`excludes-not-applicable` = `false`).
- Clauses: **25**. Annex A applicable: **89**. Annex A N/A: **4**.
- Source: `SOA_Statement_of_Applicability_SoA_Example.json`.

| ISO ID | Title | Applicability | Implementation | Justification |
| --- | --- | --- | --- | --- |
| [4.1](control.html#4.1) | Understanding the organization and its context | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [4.2](control.html#4.2) | Understanding the needs and expectations of interested parties | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [4.3](control.html#4.3) | Determining the scope of the ISMS | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [4.4](control.html#4.4) | Information security management system | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [5.1](control.html#5.1) | Leadership and commitment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [5.2](control.html#5.2) | Information security policy | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [5.3](control.html#5.3) | Organizational roles, responsibilities and authorities | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [6.1.1](control.html#6.1.1) | Actions to address risks and opportunities | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [6.1.2](control.html#6.1.2) | Information security risk assessment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [6.1.3](control.html#6.1.3) | Information security risk treatment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [6.2](control.html#6.2) | Information security objectives and planning to achieve them | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [6.3](control.html#6.3) | Planning of changes | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [7.1](control.html#7.1) | Resources | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [7.2](control.html#7.2) | Competence | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [7.3](control.html#7.3) | Awareness | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [7.4](control.html#7.4) | Communication | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [7.5](control.html#7.5) | Documented information | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [8.1](control.html#8.1) | Operational planning and control | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [8.2](control.html#8.2) | Information security risk assessment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [8.3](control.html#8.3) | Information security risk treatment | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [9.1](control.html#9.1) | Monitoring, measurement, analysis and evaluation | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [9.2](control.html#9.2) | Internal audit | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [9.3](control.html#9.3) | Management review | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [10.1](control.html#10.1) | Continual improvement | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [10.2](control.html#10.2) | Nonconformity and corrective action | applicable | always-in-scope | ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion. |
| [A.5.1](control.html#A.5.1) | Policies for information security | applicable | Implemented | Required for ISMS governance and policy direction. |
| [A.5.2](control.html#A.5.2) | Information security roles and responsibilities | applicable | Implemented | Required for assigning ISMS accountability. |
| [A.5.3](control.html#A.5.3) | Segregation of duties | applicable | In progress | Relevant to privileged administration and approval workflows. |
| [A.5.4](control.html#A.5.4) | Management responsibilities | applicable | Implemented | Required for management commitment and oversight. |
| [A.5.5](control.html#A.5.5) | Contact with authorities | applicable | Implemented | Required for incident and regulatory escalation. |
| [A.5.6](control.html#A.5.6) | Contact with special interest groups | applicable | Implemented | Relevant for threat intelligence and software security updates. |
| [A.5.7](control.html#A.5.7) | Threat intelligence | applicable | In progress | Required for software and cloud threat awareness. |
| [A.5.8](control.html#A.5.8) | Information security in project management | applicable | Implemented | Required for product and ISMS implementation projects. |
| [A.5.9](control.html#A.5.9) | Inventory of information and other associated assets | applicable | Implemented | Required because in-scope assets support customer, HR, code, identity and evidence processes. |
| [A.5.10](control.html#A.5.10) | Acceptable use of information and other associated assets | applicable | Implemented | Required for user obligations on company assets and services. |
| [A.5.11](control.html#A.5.11) | Return of assets | applicable | Implemented | Required during offboarding and role changes. |
| [A.5.12](control.html#A.5.12) | Classification of information | applicable | Implemented | Required for handling and protection decisions. |
| [A.5.13](control.html#A.5.13) | Labelling of information | applicable | Implemented | Required to communicate classification handling. |
| [A.5.14](control.html#A.5.14) | Information transfer | applicable | Implemented | Required for customer, supplier and audit information transfer. |
| [A.5.15](control.html#A.5.15) | Access control | applicable | Implemented | Required to protect production, identity, HR and evidence systems. |
| [A.5.16](control.html#A.5.16) | Identity management | applicable | Implemented | Required for lifecycle management of user identities. |
| [A.5.17](control.html#A.5.17) | Authentication information | applicable | Implemented | Required for authentication secrets and recovery. |
| [A.5.18](control.html#A.5.18) | Access rights | applicable | Implemented | Required to grant, review and revoke access rights. |
| [A.5.19](control.html#A.5.19) | Information security in supplier relationships | applicable | In progress | Required for cloud and SaaS supplier dependencies. |
| [A.5.20](control.html#A.5.20) | Addressing information security within supplier agreements | applicable | In progress | Required for supplier security terms. |
| [A.5.21](control.html#A.5.21) | Managing information security in the ICT supply chain | applicable | Planned | Required for SaaS, repository, identity and hosting chain. |
| [A.5.22](control.html#A.5.22) | Monitoring, review and change management of supplier services | applicable | In progress | Required for supplier performance and changes. |
| [A.5.23](control.html#A.5.23) | Information security for use of cloud services | applicable | In progress | Required because core services are cloud and SaaS based. |
| [A.5.24](control.html#A.5.24) | Information security incident management planning and preparation | applicable | Implemented | Required for incident readiness. |
| [A.5.25](control.html#A.5.25) | Assessment and decision on information security events | applicable | Implemented | Required for event triage. |
| [A.5.26](control.html#A.5.26) | Response to information security incidents | applicable | Implemented | Required for incident handling. |
| [A.5.27](control.html#A.5.27) | Learning from information security incidents | applicable | Planned | Required for improvement after incidents. |
| [A.5.28](control.html#A.5.28) | Collection of evidence | applicable | Implemented | Required for audit and incident evidence. |
| [A.5.29](control.html#A.5.29) | Information security during disruption | applicable | Implemented | Required for continuity of critical services. |
| [A.5.30](control.html#A.5.30) | ICT readiness for business continuity | applicable | In progress | Required for ICT continuity readiness. |
| [A.5.31](control.html#A.5.31) | Legal, statutory, regulatory and contractual requirements | applicable | Implemented | Required for legal and contractual obligations. |
| [A.5.32](control.html#A.5.32) | Intellectual property rights | applicable | Planned | Required for software, content and third-party licenses. |
| [A.5.33](control.html#A.5.33) | Protection of records | applicable | Implemented | Required to protect ISMS and operational records. |
| [A.5.34](control.html#A.5.34) | Privacy and protection of PII | applicable | Implemented | Required because HR and customer personal data are processed. |
| [A.5.35](control.html#A.5.35) | Independent review of information security | applicable | Implemented | Required to review ISMS effectiveness independently. |
| [A.5.36](control.html#A.5.36) | Compliance with policies, rules and standards for information security | applicable | Implemented | Required to verify compliance with ISMS requirements. |
| [A.5.37](control.html#A.5.37) | Documented operating procedures | applicable | In progress | Required for repeatable ISMS and IT operations. |
| [A.6.1](control.html#A.6.1) | Screening | applicable | Implemented | Required for relevant roles before employment. |
| [A.6.2](control.html#A.6.2) | Terms and conditions of employment | applicable | Implemented | Required for contractual security obligations. |
| [A.6.3](control.html#A.6.3) | Information security awareness, education and training | applicable | Implemented | Required for staff and contractors. |
| [A.6.4](control.html#A.6.4) | Disciplinary process | applicable | Planned | Required for security policy violations. |
| [A.6.5](control.html#A.6.5) | Responsibilities after termination or change of employment | applicable | Implemented | Required for offboarding and role changes. |
| [A.6.6](control.html#A.6.6) | Confidentiality or non-disclosure agreements | applicable | Implemented | Required for personnel, contractors and suppliers. |
| [A.6.7](control.html#A.6.7) | Remote working | applicable | Implemented | Required because staff work remotely. |
| [A.6.8](control.html#A.6.8) | Information security event reporting | applicable | Implemented | Required so personnel report security events. |
| [A.7.1](control.html#A.7.1) | Physical security perimeters | applicable | Implemented | Relevant for office and equipment storage. |
| [A.7.2](control.html#A.7.2) | Physical entry | applicable | Implemented | Relevant for controlled office access. |
| [A.7.3](control.html#A.7.3) | Securing offices, rooms and facilities | applicable | Implemented | Relevant for office workspaces and records. |
| [A.7.4](control.html#A.7.4) | Physical security monitoring | applicable | In progress | Relevant to office and equipment monitoring. |
| [A.7.5](control.html#A.7.5) | Protecting against physical and environmental threats | applicable | Planned | Relevant to equipment and office availability. |
| [A.7.6](control.html#A.7.6) | Working in secure areas | not-applicable | Not applicable | Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield. |
| [A.7.7](control.html#A.7.7) | Clear desk and clear screen | applicable | Implemented | Relevant for office and remote working. |
| [A.7.8](control.html#A.7.8) | Equipment siting and protection | applicable | Implemented | Relevant for endpoint and office equipment. |
| [A.7.9](control.html#A.7.9) | Security of assets off-premises | applicable | Implemented | Required for laptops and remote work. |
| [A.7.10](control.html#A.7.10) | Storage media | applicable | Implemented | Relevant to endpoint media and backups. |
| [A.7.11](control.html#A.7.11) | Supporting utilities | not-applicable | Not applicable | Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance. |
| [A.7.12](control.html#A.7.12) | Cabling security | not-applicable | Not applicable | Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services. |
| [A.7.13](control.html#A.7.13) | Equipment maintenance | applicable | Implemented | Relevant to managed endpoint fleet. |
| [A.7.14](control.html#A.7.14) | Secure disposal or re-use of equipment | applicable | Implemented | Required for endpoint disposal and reuse. |
| [A.8.1](control.html#A.8.1) | User endpoint devices | applicable | Implemented | Required for managed laptop fleet. |
| [A.8.2](control.html#A.8.2) | Privileged access rights | applicable | In progress | Required for production and identity administration. |
| [A.8.3](control.html#A.8.3) | Information access restriction | applicable | Implemented | Required for restricted repositories and production data. |
| [A.8.4](control.html#A.8.4) | Access to source code | applicable | Implemented | Required for source repositories. |
| [A.8.5](control.html#A.8.5) | Secure authentication | applicable | Implemented | Required for cloud, SaaS and repository access. |
| [A.8.6](control.html#A.8.6) | Capacity management | applicable | Planned | Required for service availability. |
| [A.8.7](control.html#A.8.7) | Protection against malware | applicable | Implemented | Required for endpoints and repositories. |
| [A.8.8](control.html#A.8.8) | Management of technical vulnerabilities | applicable | In progress | Required for software and cloud services. |
| [A.8.9](control.html#A.8.9) | Configuration management | applicable | In progress | Required for identity, cloud, endpoint and application configuration. |
| [A.8.10](control.html#A.8.10) | Information deletion | applicable | In progress | Required for retention and offboarding. |
| [A.8.11](control.html#A.8.11) | Data masking | applicable | Planned | Relevant to test data and support access. |
| [A.8.12](control.html#A.8.12) | Data leakage prevention | applicable | Planned | Relevant to customer and HR data transfer. |
| [A.8.13](control.html#A.8.13) | Information backup | applicable | Implemented | Required for availability and evidence integrity. |
| [A.8.14](control.html#A.8.14) | Redundancy of information processing facilities | applicable | Implemented | Required where supplier redundancy is relied on. |
| [A.8.15](control.html#A.8.15) | Logging | applicable | Implemented | Required for security monitoring and investigation. |
| [A.8.16](control.html#A.8.16) | Monitoring activities | applicable | In progress | Required for detecting security events. |
| [A.8.17](control.html#A.8.17) | Clock synchronization | applicable | Implemented | Required for reliable logging and investigations. |
| [A.8.18](control.html#A.8.18) | Use of privileged utility programs | applicable | In progress | Relevant to administrative tooling. |
| [A.8.19](control.html#A.8.19) | Installation of software on operational systems | applicable | Implemented | Required for production and endpoint change control. |
| [A.8.20](control.html#A.8.20) | Networks security | applicable | Implemented | Required for cloud and office connectivity. |
| [A.8.21](control.html#A.8.21) | Security of network services | applicable | Implemented | Relevant to supplier and cloud network services. |
| [A.8.22](control.html#A.8.22) | Segregation of networks | applicable | In progress | Required for production and management separation. |
| [A.8.23](control.html#A.8.23) | Web filtering | applicable | Planned | Relevant to endpoint protection and acceptable use. |
| [A.8.24](control.html#A.8.24) | Use of cryptography | applicable | Implemented | Required for confidentiality and integrity. |
| [A.8.25](control.html#A.8.25) | Secure development life cycle | applicable | Implemented | Required for customer portal software development. |
| [A.8.26](control.html#A.8.26) | Application security requirements | applicable | In progress | Required for customer portal requirements. |
| [A.8.27](control.html#A.8.27) | Secure system architecture and engineering principles | applicable | Planned | Required for architecture of in-scope systems. |
| [A.8.28](control.html#A.8.28) | Secure coding | applicable | Implemented | Required for developed software. |
| [A.8.29](control.html#A.8.29) | Security testing in development and acceptance | applicable | In progress | Required before software release. |
| [A.8.30](control.html#A.8.30) | Outsourced development | not-applicable | Not applicable | Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff. |
| [A.8.31](control.html#A.8.31) | Separation of development, test and production environments | applicable | Implemented | Required for safe software delivery. |
| [A.8.32](control.html#A.8.32) | Change management | applicable | Implemented | Required for changes to systems and services. |
| [A.8.33](control.html#A.8.33) | Test information | applicable | Planned | Required to protect production data in testing. |
| [A.8.34](control.html#A.8.34) | Protection of information systems during audit testing | applicable | Implemented | Required to protect systems during internal and external audit testing. |

## Not applicable (stay visible)

| ISO ID | Title | Applicability | Implementation | Justification |
| --- | --- | --- | --- | --- |
| [A.7.6](control.html#A.7.6) | Working in secure areas | not-applicable | Not applicable | Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield. |
| [A.7.11](control.html#A.7.11) | Supporting utilities | not-applicable | Not applicable | Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance. |
| [A.7.12](control.html#A.7.12) | Cabling security | not-applicable | Not applicable | Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services. |
| [A.8.30](control.html#A.8.30) | Outsourced development | not-applicable | Not applicable | Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff. |
