Prototype — for demo purposes only

Statement of Applicability

Applicability decisions, justifications and evidence links for every Annex A control.

Entries

6

6

Applicable

5

5

Implemented

3

3

Excluded

1

1
All soa entrys
Annex AControlApplicableJustificationStatusEvidenceActions
A.5.1Policies for information security
Yes
Baseline requirement
Implemented
ISP-v3.pdf
A.5.7Threat intelligence
Yes
Cloud SaaS threat surface
In progress
TI-plan-2026.md
A.7.9Security of assets off-premises
Yes
Remote-first workforce
Implemented
MDM-report-Q3.pdf
A.7.11Supporting utilities
No
Fully cloud-hosted, no on-prem data centers
N/A
A.8.24Use of cryptography
Yes
Handles regulated data
In progress
Crypto-standard-draft.md
A.8.31Separation of development, test and production
Yes
Multi-env SaaS
Implemented
Env-topology.pdf