I am not sure whether in the new 27001:2013 SOA really required status of each control instead of just yes or no in 2005; Where is the cause in standard state that we need to add "status of implementation" in 27001:2013 SOA? Thank you
ISO 27001:2013 defines Statement of Applicability in clause 6.1.3 d), and it requires that SoA should state for each control "whether they are implemented or not" - therefore, you need to document their status in SoA.
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.