Statement of Applicability
Applicability decisions, justifications and evidence links for every Annex A control.
Entries
6
6
Applicable
5
5
Implemented
3
3
Excluded
1
1
All soa entrys
| Annex A | Control | Applicable | Justification | Status | Evidence | Actions |
|---|---|---|---|---|---|---|
| A.5.1 | Policies for information security | Yes | Baseline requirement | Implemented | ISP-v3.pdf | |
| A.5.7 | Threat intelligence | Yes | Cloud SaaS threat surface | In progress | TI-plan-2026.md | |
| A.7.9 | Security of assets off-premises | Yes | Remote-first workforce | Implemented | MDM-report-Q3.pdf | |
| A.7.11 | Supporting utilities | No | Fully cloud-hosted, no on-prem data centers | N/A | — | |
| A.8.24 | Use of cryptography | Yes | Handles regulated data | In progress | Crypto-standard-draft.md | |
| A.8.31 | Separation of development, test and production | Yes | Multi-env SaaS | Implemented | Env-topology.pdf |