Annex A control selector
A Statement of Applicability records a decision on all 93 Annex A controls. This works out which of them your scope makes arguable to exclude, and gives you the justification wording an auditor will accept.
Exclusion is legitimate and expected. What gets written up is an exclusion that follows from the budget rather than from the scope statement or the risk assessment. Six questions decide almost all of the arguable ones, because almost every defensible exclusion comes down to premises, software development, non-production data, or an availability commitment.
The answer appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
What the six questions are doing
Almost every arguable exclusion in Annex A comes from one of four facts about an organization, and the questions above establish all four. Everything else in the annex is written broadly enough that it applies to any company with staff, suppliers and software.
| Fact about you | Controls it puts in play | How the argument is won or lost |
|---|---|---|
| No premises in scope | Physical perimeter, entry control, securing offices, physical monitoring, working in secure areas, utilities, cabling | Won if the scope statement names no facility. Lost if a customer visits an office where in-scope work happens. |
| No software development | The secure development set, including secure coding, development life cycle, application security requirements, security testing, separation of environments | Lost the moment somebody mentions Terraform, a deployment script or a low-code app. |
| All development in-house | Outsourced development | One of the cleanest exclusions available. Lost if contract developers are used. |
| Production data never leaves production | Data masking | Won only if something technical enforces it. A policy nobody checks is not evidence. |
| No availability commitment | Redundancy of information processing facilities | Lost by any signed uptime or recovery objective, which most software contracts now carry. |
This is a first pass, not a Statement of Applicability
The output is a shortlist of controls your scope makes arguable to exclude and the wording that argument needs. It is not the document, because the document has to be written from your own risk assessment and no tool has seen that. Use it to skip the two days most projects spend arguing about the physical controls, then write the real thing in the order set out on the Statement of Applicability page.
Common questions
Do I have to give an email address to see the result?
No. The split, the reasoning and the control groups render on this page as soon as you finish the questions. The field underneath sends a written version with the justification wording set out control by control, which is useful for pasting into a document, and skipping it costs you nothing.
How many Annex A controls do most companies exclude?
Between zero and about a dozen of the 93. A cloud-hosted software company with no office in scope and no outsourced development is at the high end. A company with premises, contractors and an uptime commitment usually finds nothing it can defend excluding. There is no target, and a low exclusion count is not a worse answer.
Can we exclude a control because it is expensive?
No. Exclusion means the control is not necessary to treat your risks, and cost is not part of that test. The right move is to mark it applicable and not yet implemented, with an owner and a target date. That is a normal state for a management system and it survives an audit, which a cost-based exclusion does not.
Does this replace a gap assessment?
No. This decides which controls are in play. A gap assessment measures how far you are from operating the ones that are, across both Annex A and the clause requirements. Run this first, because scoping the control set is what makes the gap assessment cheaper.
Get the Statement of Applicability reviewed
Tell us your scope and where you are, and we will match you with Canadian firms that do ISO 27001 readiness work.
Get matched